chore(deps): combine Dependabot updates (#1250)

### Significant changes / EOS impact

The dependency bumps are mostly patch/tooling updates, but a few are worth explicit review:

- **`pydantic-settings` 2.14.2 → 2.15.0 — highest runtime impact.** EOS directly subclasses `pydantic_settings.BaseSettings` for `SettingsEOS` / `ConfigEOS`, with `case_sensitive` left at its default. In 2.15.0, `case_sensitive` now also applies to init kwargs and config-file sources, so top-level setting keys are now matched case-insensitively by default where those sources previously did not behave that way. This can change how differently-cased config keys are accepted/resolved. The release also adds warnings for unresolved forward references and changes strict non-JSON env-value failures to `ValidationError`. **Recommended:** exercise JSON config loading, init/update paths, env overrides, and config round-trips.

- **`tzfpy` 1.3.2 → 1.3.3 — runtime correctness change.** EOS uses `tzfpy.get_tz()` in `to_timezone()` and exposes the result through `GeneralSettings.timezone`. Queries exactly on timezone polygon borders now resolve instead of returning an empty result, and the `America/Argentina/Ushuaia` boundary is corrected. This can intentionally change timezone output for users on/near affected boundaries.

- **`cachebox` 6.2.2 → 6.2.5 — runtime cache correctness/safety.** EOS uses `cachebox.LRUCache` and `cachebox.cached` for the energy-management cache. The update fixes iterator lifetime safety, LRU iterator invalidation when reads promote entries, and a potential `setdefault_with` locking issue. EOS does not appear to rely on those edge cases directly, so this is expected to be low-risk and mostly corrective; existing cache tests are the relevant regression coverage.

- **`GitPython` 3.1.58 → 3.1.59 — dev/tooling security hardening.** This release blocks file-reading Git options, separate git-directory use during clone, and hardens config parsing. It appears to be a dev/docs dependency rather than EOS runtime code, but CI/tooling that intentionally passes unusual Git options could be affected.

- **`pre-commit` 4.6.1 → 4.6.2 — dev-only bug fix.** Fixes a regression in Node-language hooks using npm 11.x build scripts.

- **`mypy` 2.3.1, `commitizen` 4.17.1, and `types-PyYaml` stub update** are tooling/type-checking changes with no expected EOS runtime behavior change.

Overall, the main compatibility focus should be **configuration handling (`pydantic-settings`)**, followed by **timezone edge cases (`tzfpy`)**. The remaining updates are primarily correctness, security, or developer-tooling fixes.
This commit is contained in:
Normann
2026-08-22 00:11:08 +02:00
committed by GitHub
parent 9b3f37e172
commit 6849b731b0
3 changed files with 209 additions and 201 deletions
+8 -8
View File
@@ -16,7 +16,7 @@ classifiers = [
dependencies = [
"babel==2.18.0",
"beautifulsoup4==4.15.0",
"cachebox==6.2.2",
"cachebox==6.2.5",
"numpy==2.4.6",
"numpydantic==1.10.0",
"matplotlib==3.11.1",
@@ -31,7 +31,7 @@ dependencies = [
"bokeh==3.9.2",
"uvicorn==0.52.4",
"scipy==1.17.1",
"tzfpy==1.3.2",
"tzfpy==1.3.3",
"deap==1.4.4",
"requests==2.34.2",
"pandas==3.0.5",
@@ -42,7 +42,7 @@ dependencies = [
"pydantic==2.13.4",
"pydantic_extra_types==2.11.2",
"statsmodels==0.14.6",
"pydantic-settings==2.14.2",
"pydantic-settings==2.15.0",
"linkify-it-py==2.1.0",
"loguru==0.7.3",
"lmdb==2.3.0",
@@ -59,21 +59,21 @@ dev = [
# - commitizen - sync with requirements-dev.txt (if on pypi)
#
# !!! Sync .pre-commit-config.yaml with these dependencies !!!
"pre-commit==4.6.1",
"mypy==2.3.0",
"pre-commit==4.6.2",
"mypy==2.3.1",
"types-requests==2.33.0.20260712", # for mypy
"pandas-stubs==3.0.5.260730", # for mypy
"tokenize-rt==6.2.0", # for mypy
"types-docutils==0.22.3.20260712", # for mypy
"types-PyYaml==6.0.12.20260724", # for mypy
"commitizen==4.16.5",
"types-PyYaml==6.0.12.20260815", # for mypy
"commitizen==4.17.1",
"deprecated==1.3.1", # for commitizen
# Sphinx
"sphinx==9.0.4",
"sphinx_rtd_theme==3.1.0",
"sphinx-tabs==3.5.0",
"GitPython==3.1.58",
"GitPython==3.1.59",
"myst-parser==5.1.0",
"docutils==0.21.2",
"sphinxcontrib-mermaid==2.1.0 ",