build: bump ruff from 0.15.22 to 0.16.0 - #175
Open
dependabot[bot] wants to merge 49 commits into
Open
Conversation
…152) Generic release-gating scripts (release_readiness, ci_status, version_free, deployed_digest) + tests for data-olympus's own release process. No internal orchestration data. Reviewed: Opus whole-branch + codex companion (all blockers resolved, incl. fail-closed hardening). Admin-merged past required-review per operator authorization.
/ KNA-143) Rewrite the kb_record_event docstring to cover all three Glama dimensions that scored below A: - Behavior: discloses that the tool appends a durable, non-destructive entry to the audit log and requires write capability. - Completeness: documents both event_type values (gate_bypass, gate_degraded), all required params, and that reason is optional but recommended for gate_bypass entries. - Usage Guidelines: when to call (enforce hook bypassed or degraded the gate and the fallback must be recorded) vs. when not to (use kb_gate_check to check, kb_consult to consult, kb_audit or kb_compliance to read back events).
Add a 'Use when / use X instead when Y' guidance sentence to each of kb_outline, kb_get, kb_list, kb_onboarding_status, kb_cleanup_plan, kb_gate_check, and kb_compliance. Also discloses kb_gate_check's audit-log side effect: each check is recorded non-destructively (readOnlyHint=false is intentional). Target: Usage Guidelines avg >= 4.3 and Behavior avg >= 4.2 on next Glama re-score; Conciseness avg must not regress below 4.50.
Reviewed security dependency update required for the 0.6.0 release gate.
Reviewed dependency update for Dependabot alert 19 and the 0.6.0 release security gate.
Bumps [fastmcp](https://github.com/PrefectHQ/fastmcp) from 3.4.3 to 3.4.4. - [Release notes](https://github.com/PrefectHQ/fastmcp/releases) - [Changelog](https://github.com/PrefectHQ/fastmcp/blob/main/docs/changelog.mdx) - [Commits](PrefectHQ/fastmcp@v3.4.3...v3.4.4) --- updated-dependencies: - dependency-name: fastmcp dependency-version: 3.4.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [regex](https://github.com/mrabarnett/mrab-regex) from 2026.5.9 to 2026.7.10. - [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt) - [Commits](mrabarnett/mrab-regex@2026.5.9...2026.7.10) --- updated-dependencies: - dependency-name: regex dependency-version: 2026.7.10 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [types-regex](https://github.com/python/typeshed) from 2026.6.28.20260630 to 2026.7.10.20260711. - [Commits](https://github.com/python/typeshed/commits) --- updated-dependencies: - dependency-name: types-regex dependency-version: 2026.7.10.20260711 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [mypy](https://github.com/python/mypy) from 2.2.0 to 2.3.0. - [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md) - [Commits](python/mypy@v2.2.0...v2.3.0) --- updated-dependencies: - dependency-name: mypy dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.15.20 to 0.15.22. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.15.20...0.15.22) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.15.21 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
## Summary Fix RC and release image provenance so the reusable image workflow builds the explicit requested ref instead of the caller workflow SHA. ## Verification * `uv run --python 3.13 --extra dev pytest -q tests/test_publish_workflows.py`: 12 passed * `actionlint`: passed * Independent Claude high risk review: APPROVE at `33b05a208c60e89b17db825242b0041dc47f4f57` The operator supplied release ref is consumed by `actions/checkout`, not interpolated into shell. The resolved commit is obtained with `git rev-parse HEAD` after checkout and reused immutably by image and prerelease jobs. RC.1 exposed this defect and was not deployed. A new RC will be cut only after this correction lands on the trusted `main` workflow definition.
feat: prepare data-olympus 0.6.0 Glama catalog readiness
This PR adds a badge linking to the BundleDex directory (https://bundledex.net), the curated registry of OKF knowledge bundles. BundleDex indexes over 400 OKF-conformant bundles from 333+ authors. [](https://bundledex.net) Co-authored-by: dbt-bot <dbt-bot@mcclawddigital.com>
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.15.22 to 0.16.0. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.15.22...0.16.0) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps ruff from 0.15.22 to 0.16.0.
Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
a2635fdBump 0.16.0 (#27136)3433449[ty] Reuse full call diagnostics for implicit setter calls (#27115)2240070Reflectruff: ignoreand--add-ignorestabilization in documentation (#27...17ef711Stabilize--add-ignore(#27125)ef912bbAdd newly stabilized rules to defaults (#27055)b30f040Stabilize new default rules (#27035)bcd70c5Exclude Markdown files fromformat-devruns (#27052)87e51e2Fixformat --checkspans for syntax errors (#27045)afe2723[flake8-gettext] Stabilize qualified-name and built-in binding resolution (...a9702d8[flake8-bandit] Stabilize string literal binding resolution (S310) (#26944)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)