mirror of
https://github.com/Akkudoktor-EOS/EOS.git
synced 2026-08-30 04:06:37 +00:00
Consolidates the currently applicable dependency updates into one PR, including the closed Dependabot backlog such as #1241, plus dependency surfaces that were not covered by the repository's previous pip-only Dependabot configuration. Cleanup of test warnings. Most importent: * GitPython + pypdf security hardening. * Uvicorn WebSocket close/backpressure/header fixes for server/dashboard reliability. * FastAPI dependency-memory/OpenAPI improvements for the API process. * Bokeh WebSocket/resource-leak/prefix fixes for EOSdash and proxied deployments. * cachebox cancellation/lock cleanup fixes for long-running/concurrent work. * pandas 3.0.5 avoiding the yanked 3.0.4 datetime/segfault build. * Ruff security-lint and pydocstyle correctness fixes, plus faster release builds via PGO. * platformdirs malformed-XDG and duplicate-directory fixes for deployment portability. * CI action modernization, regenerated uv.lock, and expanded Dependabot coverage. Runtime dependencies cachebox: 6.1.2 → 6.2.2 fastapi: 0.139.2 → 0.141.1 python-fasthtml: 0.14.9 → 0.14.11 MonsterUI: 1.0.46 → 1.0.47 bokeh: 3.9.1 → 3.9.2 uvicorn: 0.51.0 → 0.52.4 (build(deps): bump uvicorn from 0.51.0 to 0.52.3 #1241, refreshed to latest patch) pandas: 3.0.3 → 3.0.5 platformdirs: 4.11.0 → 4.11.3 Development/test dependencies pandas-stubs: 3.0.3.260530 → 3.0.5.260730 types-PyYAML: 6.0.12.20260518 → 6.0.12.20260724 GitPython: 3.1.53 → 3.1.58 (security/fix releases) coverage: 7.15.2 → 7.15.4 pypdf: 6.14.2 → 6.16.1 (includes security fixes) Pre-commit/tooling ruff-pre-commit: v0.15.21 → v0.16.3 synchronize pandas-stubs, types-docutils, and types-PyYAML pins with pyproject.toml CI / repository dependencies Python 3.13.9 → 3.13.15 in CI, Docker, .env, and local Docker Make targets actions/checkout → v7 in pytest, pre-commit, CodeQL, and release workflows actions/setup-python → v7 in pytest, pre-commit, and release workflows actions/upload-artifact → v7 in pytest workflow actions/stale: v9.1.0 → v11.0.0 (SHA-pinned) regenerate uv.lock from the final dependency pins so locked/frozen installs match pyproject.toml Future update coverage Expand Dependabot from pip-only to also monitor: GitHub Actions Docker The existing open docutils 0.23 update (#1085) is intentionally excluded because it has separate compatibility/ignore handling and should remain isolated. docker-build.yml was audited and is already using the newer action generations, so no changes were needed there. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
88 lines
2.4 KiB
YAML
88 lines
2.4 KiB
YAML
# Exclude some file types from automatic code style
|
|
exclude: \.(json|csv)$
|
|
repos:
|
|
# --- Basic sanity checks ---
|
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
|
rev: v6.0.0
|
|
hooks:
|
|
- id: check-merge-conflict
|
|
- id: check-toml
|
|
- id: check-yaml
|
|
- id: end-of-file-fixer
|
|
- id: trailing-whitespace
|
|
- id: check-merge-conflict
|
|
exclude: '\.rst$' # Exclude .rst files from whitespace cleanup
|
|
|
|
# --- Import sorting ---
|
|
- repo: https://github.com/PyCQA/isort
|
|
rev: 8.0.1
|
|
hooks:
|
|
- id: isort
|
|
|
|
# --- Linting + Formatting via Ruff ---
|
|
- repo: https://github.com/astral-sh/ruff-pre-commit
|
|
rev: v0.16.3
|
|
hooks:
|
|
# Run the linter and fix simple isssues automatically
|
|
- id: ruff
|
|
args: [--fix]
|
|
# Run the formatter
|
|
- id: ruff-format
|
|
|
|
# --- Static type checking ---
|
|
- repo: https://github.com/pre-commit/mirrors-mypy
|
|
rev: v2.3.0
|
|
hooks:
|
|
- id: mypy
|
|
additional_dependencies:
|
|
- types-requests==2.33.0.20260712
|
|
- pandas-stubs==3.0.5.260730
|
|
- tokenize-rt==6.2.0
|
|
- types-docutils==0.22.3.20260712
|
|
- types-PyYaml==6.0.12.20260724
|
|
pass_filenames: false
|
|
|
|
# --- Markdown linter ---
|
|
- repo: https://github.com/jackdewinter/pymarkdown
|
|
rev: v0.9.39
|
|
hooks:
|
|
- id: pymarkdown
|
|
files: ^docs/
|
|
args:
|
|
- --config=docs/pymarkdown.json
|
|
- scan
|
|
|
|
# --- Commit message linting ---
|
|
# - Local cross-platform hooks
|
|
- repo: local
|
|
hooks:
|
|
# Validate commit messages (using Python wrapper)
|
|
- id: commitizen-commit
|
|
name: Commitizen (venv-aware)
|
|
entry: scripts/cz_check_commit_message.py
|
|
language: python
|
|
additional_dependencies:
|
|
- .
|
|
stages: [commit-msg]
|
|
pass_filenames: false
|
|
|
|
# Branch name check on push (using Python wrapper)
|
|
- id: commitizen-branch
|
|
name: Commitizen branch check
|
|
entry: scripts/cz_check_branch.py
|
|
language: python
|
|
additional_dependencies:
|
|
- .
|
|
stages: [pre-push]
|
|
pass_filenames: false
|
|
|
|
# Validate new commit messages before push (using Python wrapper)
|
|
- id: commitizen-new-commits
|
|
name: Commitizen (check new commits only, .venv aware)
|
|
entry: scripts/cz_check_new_commits.py
|
|
language: python
|
|
additional_dependencies:
|
|
- .
|
|
stages: [pre-push]
|
|
pass_filenames: false
|