Skip to content

chore(deps-dev)(deps-dev): bump the python-dependencies group with 3 updates - #566

Merged
tschm merged 1 commit into
mainfrom
dependabot/uv/python-dependencies-321e093ee4
Oct 6, 2026
Merged

tschm merged 1 commit into
mainfrom
dependabot/uv/python-dependencies-321e093ee4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 3 updates: jquantstats, marimo and hypothesis.

Updates jquantstats from 0.11.0 to 0.12.0

Release notes

Sourced from jquantstats's releases.

v0.12.0

Changelog

All notable changes to this project are documented in this file.

The format is based on Keep a Changelog, and entries are generated from Conventional Commits.

[0.12.0] - 2026-09-28

New Features

  • Add investment_ratio property to Portfolio (#1001)

Bug Fixes

  • Escape user-supplied title and asset names in the Data HTML report (#996) (#998)

Documentation

  • Source the landing page from README (#977)
  • Write example reports under output/ so they stay untracked (#981)
  • Correct CLAUDE.md's account of the rhiza make layer (#986) (#990)
  • Record the builtin-validation exemption and enforce its scope (#989) (#993)

Maintenance

  • Chore(deps)(deps): bump the python-dependencies group with 2 updates (#975)
  • Update rhiza to v1.7.2 (#976)
  • Update rhiza to v1.8.0 (#978)
  • Derive the version from the git tag (#979)
  • Chore(deps)(deps): bump the python-dependencies group with 2 updates (#980)
  • Chore(deps)(deps): bump the python-dependencies group with 5 updates (#982)
  • Chore(deps)(deps): bump anyio from 4.13.0 to 4.14.2 (#983)
  • Chore(deps)(deps): bump soupsieve from 2.8.4 to 2.9 (#984)
  • Chore(deps)(deps): bump the python-dependencies group with 2 updates (#985)
  • Extract mark, grid, norm and label helpers in the mpl renderer (#988) (#992)
  • Run the src/ docstring examples as part of the suite (#987) (#991)
  • Add httpx2 so starlette's TestClient stops warning (#994) (#995)
  • Render the Data report through the Jinja2 templates (#997) (#999)

PyPI Package

jquantstats

PyPI Package

jquantstats

Changelog

Sourced from jquantstats's changelog.

[0.12.0] - 2026-09-28

New Features

  • Add investment_ratio property to Portfolio (#1001)

Bug Fixes

  • Escape user-supplied title and asset names in the Data HTML report (#996) (#998)

Documentation

  • Source the landing page from README (#977)
  • Write example reports under output/ so they stay untracked (#981)
  • Correct CLAUDE.md's account of the rhiza make layer (#986) (#990)
  • Record the builtin-validation exemption and enforce its scope (#989) (#993)

Maintenance

  • Chore(deps)(deps): bump the python-dependencies group with 2 updates (#975)
  • Update rhiza to v1.7.2 (#976)
  • Update rhiza to v1.8.0 (#978)
  • Derive the version from the git tag (#979)
  • Chore(deps)(deps): bump the python-dependencies group with 2 updates (#980)
  • Chore(deps)(deps): bump the python-dependencies group with 5 updates (#982)
  • Chore(deps)(deps): bump anyio from 4.13.0 to 4.14.2 (#983)
  • Chore(deps)(deps): bump soupsieve from 2.8.4 to 2.9 (#984)
  • Chore(deps)(deps): bump the python-dependencies group with 2 updates (#985)
  • Extract mark, grid, norm and label helpers in the mpl renderer (#988) (#992)
  • Run the src/ docstring examples as part of the suite (#987) (#991)
  • Add httpx2 so starlette's TestClient stops warning (#994) (#995)
  • Render the Data report through the Jinja2 templates (#997) (#999)
Commits
  • 569eda4 chore: release v0.12.0 (#1002)
  • ffdae72 feat: add investment_ratio property to Portfolio (#1001)
  • 1e9fb52 refactor: render the Data report through the Jinja2 templates (#997) (#999)
  • 68ccda0 fix: escape user-supplied title and asset names in the Data HTML report (#996...
  • 8cb9a6e build: add httpx2 so starlette's TestClient stops warning (#994) (#995)
  • bdb9bd3 docs: record the builtin-validation exemption and enforce its scope (#989) (#...
  • 7e33d76 test: run the src/ docstring examples as part of the suite (#987) (#991)
  • 5f01e29 docs: correct CLAUDE.md's account of the rhiza make layer (#986) (#990)
  • 32f0a50 refactor: extract mark, grid, norm and label helpers in the mpl renderer (#98...
  • d1a8ca0 chore(deps)(deps): bump the python-dependencies group with 2 updates (#985)
  • Additional commits viewable in compare view

Updates marimo from 0.25.0 to 0.25.1

Release notes

Sourced from marimo's releases.

0.25.1

✨ Enhancements

  • Make local agent pairing easier to discover (#10946)
  • Update LLM model catalog (#11002)
  • Add expand_outputs as an argument to ctx.edit_cell and ctx.create_cell (#10974)
  • Record cache entries in a per-notebook manifest (#10838)
  • Marimo cache size (#10837)
  • Marimo cache dir (#10836)

🐛 Bug fixes

  • Keep getpass responses out of saved console output (#11043)
  • Reject invalid code mode cell names (#11032)
  • Align and unshrink mo.ui.radio button when option label wraps (#11031)
  • Harden sandbox environment selection (#11026)
  • Send origin referrer on cross-origin requests from notebook pages (#11015)
  • Keep sandbox package managers fixed in install alerts (#10983)
  • Render dotted chart columns when data falls back to CSV (#10856)
  • Fix plotly hover text rendering issue (#10988)
  • Avoid repeated Docker prompt for sandboxed URL edits (#10984)
  • Make the kernel SIGINT handler reentrancy-safe (#10975)
  • Secure language server websocket listeners (#10979)
  • Change tokenization to allow trailing comments (#10981)
  • UI fix for SFTP (and a fsspec plugin for ssh) (#10977)
  • Ensure partial cell config update preserves existing values (#10971)

📚 Documentation

  • Add huggingface/drive to remote storage (#10959)
  • Normalize styles from katex bump (#10995)
  • Add Whisper sandbox example (#10994)
  • Fix quickstart anchors in Spanish and Chinese READMEs (#10989)
  • Security clarification on pyproject.toml (#10986)
  • Add ffmpeg pixi example for blog post (#10993)

📝 Other changes

  • Fix suboptimal assignment in cell-matching Hungarian algorithm (#10654) (f15c5ff)

Contributors

Thanks to all our community and contributors who made this release possible: @​dmadisetti, @​kirangadhave, @​koaning, @​Light2Dark, @​manzt, @​marthacryan, @​mscolnick, @​peter-gy, @​sadov, @​ZainnQureshii

Full Changelog: marimo-team/marimo@0.25.0...0.25.1

Commits

Updates hypothesis from 6.168.1 to 6.168.3

Commits
  • 44b82b2 Bump hypothesis version to 6.168.3 and update changelog
  • aeaafb5 Merge pull request #4888 from gpacix/fix-quadratic-statistics
  • f3f4a29 wording, remove hardcoded test
  • 7fabb94 Add RELEASE.rst and AUTHORS.rst changes
  • 0ab4e38 Summarize statistics events in linear time
  • 32ebeb2 Bump hypothesis version to 6.168.2 and update changelog
  • ff7e800 Merge pull request #4886 from pschanely/atomic-constants-cache
  • e57fd12 Isolate the constants cache test from existing cache files
  • c8981a0 Write the local constants cache atomically
  • 9c55f97 Merge pull request #4877 from HypothesisWorks/create-pull-request/patch
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the python-dependencies group with 3 updates: [jquantstats](https://github.com/jebel-quant/jquantstats), [marimo](https://github.com/marimo-team/marimo) and [hypothesis](https://github.com/HypothesisWorks/hypothesis).


Updates `jquantstats` from 0.11.0 to 0.12.0
- [Release notes](https://github.com/jebel-quant/jquantstats/releases)
- [Changelog](https://github.com/Jebel-Quant/jquantstats/blob/main/CHANGELOG.md)
- [Commits](Jebel-Quant/jquantstats@v0.11.0...v0.12.0)

Updates `marimo` from 0.25.0 to 0.25.1
- [Release notes](https://github.com/marimo-team/marimo/releases)
- [Commits](marimo-team/marimo@0.25.0...0.25.1)

Updates `hypothesis` from 6.168.1 to 6.168.3
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.1...v6.168.3)

---
updated-dependencies:
- dependency-name: jquantstats
  dependency-version: 0.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: marimo
  dependency-version: 0.25.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: hypothesis
  dependency-version: 6.168.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 6, 2026
@tschm
tschm merged commit 4141fcb into main Oct 6, 2026
45 checks passed
@tschm
tschm deleted the dependabot/uv/python-dependencies-321e093ee4 branch October 6, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant