Skip to content

Bump pip from 26.1.1 to 26.1.2 - #120

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/pip-26.1.2
Closed

Bump pip from 26.1.1 to 26.1.2#120
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/pip-26.1.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 10, 2026

Copy link
Copy Markdown
Contributor

Bumps pip from 26.1.1 to 26.1.2.

Changelog

Sourced from pip's changelog.

26.1.2 (2026-05-31)

Bug Fixes

  • Reject console_scripts and gui_scripts entry points whose name would install a script outside the scripts directory. ([#14000](https://github.com/pypa/pip/issues/14000) <https://github.com/pypa/pip/issues/14000>_)
  • Fix installation incorrectly failing when the target path contains a doubled slash, such as with pip install --root //.... ([#14001](https://github.com/pypa/pip/issues/14001) <https://github.com/pypa/pip/issues/14001>_)
  • Send a consistent Accept-Encoding header to avoid a spurious Cache entry deserialization failed warning. ([#14012](https://github.com/pypa/pip/issues/14012) <https://github.com/pypa/pip/issues/14012>_)
Commits
  • 31d7d16 Bump for release
  • 79f348c Update AUTHORS.txt
  • 237a925 Merge pull request #14001 from notatallshaw/fix-is-within-directory
  • 34d0285 Merge pull request #14006 from laymonage/fix-requirements_from_scripts-space-...
  • 09d3e07 Merge pull request #14012 from notatallshaw/stable-accept-encoding
  • fa7854f Use is_within_directory for entry point check
  • d01b46c NEWS ENTRY
  • 7ff8bdd Fix is_within_directory for doubled-slash roots
  • 7ea3466 NEWS ENTRY
  • 85673ea Fix Accept-Encoding to gzip, deflate
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [pip](https://github.com/pypa/pip) from 26.1.1 to 26.1.2.
- [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst)
- [Commits](pypa/pip@26.1.1...26.1.2)

---
updated-dependencies:
- dependency-name: pip
  dependency-version: 26.1.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 10, 2026
@dependabot
dependabot Bot requested a review from cognitivegears as a code owner July 10, 2026 15:17
cognitivegears added a commit that referenced this pull request Jul 17, 2026
- pytest-homeassistant-custom-component 0.13.333 -> 0.13.339 (HA 2026.6.3)
- serialx 1.7.3 -> 1.8.0, dbus-fast 4.0.4 -> 5.0.16 (dev pins follow HA
  2026.6.3 package_constraints; manifest.json ranges unchanged, so the
  end-user HA floor stays 2026.5.0)
- wcwidth 0.8.1 -> 0.8.2 (runtime; IndexError bugfix)
- ruff 0.15.18 -> 0.15.22; mypy stays 2.1.0 (2.2+ needs
  ast-serialize>=0.6, harness pins 0.3.0 — mypy added to the dependabot
  ignore list like pytest/respx)
- security.yml pip-audit ignore list rebuilt against the new stack
  (fixes the scan that has been failing on main since the Pillow 12.2.0
  advisories landed)
- README requirements corrected: minimum HA is 2026.5, not 2026.3
  (floor was raised when serial support landed)

Supersedes dependabot PRs #94, #119, #120, #121.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@cognitivegears

Copy link
Copy Markdown
Owner

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

The dependabot.yml entry that created this PR has been deleted so this PR can't be recreated. Please close the PR so Dependabot can create a new one with the current dependabot.yml.

cognitivegears added a commit that referenced this pull request Aug 11, 2026
)

* chore(deps): refresh dev toolchain and HA test harness to 2026.8.1

- pytest-homeassistant-custom-component 0.13.348 -> 0.13.355 (HA 2026.7.4 -> 2026.8.1, dev/CI only; supported HA floor unchanged)
- Pillow 12.2.0 -> 12.3.0 (matches HA 2026.8.1 package_constraints)
- ruff 0.15.22 -> 0.16.2; ignore PLR0917 (companion to already-ignored PLR0913)
- pre-commit 4.6.0 -> 4.6.1, diff-cover 10.3.0 -> 10.4.2
- uv lock --upgrade: picks up msgpack 1.2.1, pip 26.2.1, and other transitives

Supersedes dependabot PRs #94, #110, #120, #128, #129, #130.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014hjUZ6aEMCJwQjyuFuTW3h

* docs: update dependency-pins skill for harness 0.13.355 / HA 2026.8.1

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014hjUZ6aEMCJwQjyuFuTW3h

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@cognitivegears

Copy link
Copy Markdown
Owner

Superseded by #137 (main now carries a newer version).

@dependabot @github

dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/uv/pip-26.1.2 branch August 11, 2026 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant