Skip to content

chore(deps-dev): bump pytest-cov from 4.1.0 to 7.0.0 - #19

Merged
moshehbenavraham merged 1 commit into
mainfrom
dependabot/pip/pytest-cov-7.0.0
Nov 12, 2025
Merged

chore(deps-dev): bump pytest-cov from 4.1.0 to 7.0.0#19
moshehbenavraham merged 1 commit into
mainfrom
dependabot/pip/pytest-cov-7.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Nov 10, 2025

Copy link
Copy Markdown
Contributor

Bumps pytest-cov from 4.1.0 to 7.0.0.

Changelog

Sourced from pytest-cov's changelog.

7.0.0 (2025-09-09)

  • Dropped support for subprocesses measurement.

    It was a feature added long time ago when coverage lacked a nice way to measure subprocesses created in tests. It relied on a .pth file, there was no way to opt-out and it created bad interations with coverage's new patch system <https://coverage.readthedocs.io/en/latest/config.html#run-patch>_ added in 7.10 <https://coverage.readthedocs.io/en/7.10.6/changes.html#version-7-10-0-2025-07-24>_.

    To migrate to this release you might need to enable the suprocess patch, example for .coveragerc:

    .. code-block:: ini

    [run] patch = subprocess

    This release also requires at least coverage 7.10.6.

  • Switched packaging to have metadata completely in pyproject.toml and use hatchling <https://pypi.org/project/hatchling/>_ for building. Contributed by Ofek Lev in [#551](https://github.com/pytest-dev/pytest-cov/issues/551) <https://github.com/pytest-dev/pytest-cov/pull/551>_ with some extras in [#716](https://github.com/pytest-dev/pytest-cov/issues/716) <https://github.com/pytest-dev/pytest-cov/pull/716>_.

  • Removed some not really necessary testing deps like six.

6.3.0 (2025-09-06)

  • Added support for markdown reports. Contributed by Marcos Boger in [#712](https://github.com/pytest-dev/pytest-cov/issues/712) <https://github.com/pytest-dev/pytest-cov/pull/712>_ and [#714](https://github.com/pytest-dev/pytest-cov/issues/714) <https://github.com/pytest-dev/pytest-cov/pull/714>_.
  • Fixed some formatting issues in docs. Anonymous contribution in [#706](https://github.com/pytest-dev/pytest-cov/issues/706) <https://github.com/pytest-dev/pytest-cov/pull/706>_.

6.2.1 (2025-06-12)

  • Added a version requirement for pytest's pluggy dependency (1.2.0, released 2023-06-21) that has the required new-style hookwrapper API.

  • Removed deprecated license classifier (packaging).

  • Disabled coverage warnings in two more situations where they have no value:

    • "module-not-measured" in workers
    • "already-imported" in subprocesses

6.2.0 (2025-06-11)

  • The plugin now adds 3 rules in the filter warnings configuration to prevent common coverage warnings being raised as obscure errors::

    default:unclosed database in <sqlite3.Connection object at:ResourceWarning once::PytestCovWarning

... (truncated)

Commits
  • 224d896 Bump version: 6.3.0 → 7.0.0
  • 73424e3 Cleanup the docs a bit.
  • 36f1cc2 Bump pins in template.
  • f299c59 Bump the github-actions group with 2 updates
  • 25f0b2e Update docs/config.rst
  • bb23eac Improve configuration docs
  • a19531e Switch from build/pre-commit to uv/prek - this should make this faster.
  • 82f9993 Update changelog.
  • 211b5cd Fix links.
  • 97aadd7 Update some ci config, reformat and apply some lint fixes.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Updates pytest-cov to 7.0.0 with required dependency adjustments and aligns several runtime/dev package versions in pyproject.toml and poetry.lock.

  • Dev/Test tooling:
    • pytest-cov7.0.0 with new deps: coverage >=7.10.6, pytest >=7, pluggy >=1.2.
    • coverage7.11.3 (python >=3.10).
    • ruff pinned to 0.14.2 and pre-commit to 4.3.0.
  • Runtime deps:
    • streamlit pinned to ^1.50.0 (lock reflects 1.50.0; relaxes pyarrow to ">=7.0" and tightens pillow <12).
    • rich pinned to ^13 (lock to 13.9.4), with typing-extensions added for Python <3.11.
  • Project config:
    • pyproject.toml and poetry.lock updated to reflect the above version and constraint changes (metadata content-hash updated).

Written by Cursor Bugbot for commit f142401. This will update automatically on new commits. Configure here.

@dependabot @github

dependabot Bot commented on behalf of github Nov 10, 2025

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@moshehbenavraham

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Nov 12, 2025

Copy link
Copy Markdown
Contributor Author

Dependabot attempted to update this pull request, but because the branch dependabot/pip/pytest-cov-7.0.0 is protected it was unable to do so.

Bumps [pytest-cov](https://github.com/pytest-dev/pytest-cov) from 4.1.0 to 7.0.0.
- [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-cov@v4.1.0...v7.0.0)

---
updated-dependencies:
- dependency-name: pytest-cov
  dependency-version: 7.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@moshehbenavraham
moshehbenavraham force-pushed the dependabot/pip/pytest-cov-7.0.0 branch from cfcd4d6 to f142401 Compare November 12, 2025 09:20
@moshehbenavraham
moshehbenavraham merged commit 59dd478 into main Nov 12, 2025
6 checks passed
@moshehbenavraham
moshehbenavraham deleted the dependabot/pip/pytest-cov-7.0.0 branch November 12, 2025 09:21

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is being reviewed by Cursor Bugbot

Details

You are on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle.

To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.

Comment thread pyproject.toml
pydantic-settings = "^2.11"
typer = {extras = ["all"], version = "^0.20.0"}
rich = "^14.2"
rich = "^13.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Unintended Dependency Downgrade Introduced

The rich dependency constraint was changed from ^14.2 to ^13.0, causing a downgrade from version 14.2.0 to 13.9.4 in the lock file. This unintended downgrade contradicts the PR's stated purpose of only bumping pytest-cov and may introduce compatibility issues or remove features from the newer version.

Fix in Cursor Fix in Web

Comment thread pyproject.toml
tenacity = "^9.1"
aiofiles = "^24.1"
streamlit = "^1.51.0"
streamlit = "^1.50.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Unintended Downgrade: Version Constraint Mismatch

The streamlit dependency constraint was changed from ^1.51.0 to ^1.50.0, causing a downgrade from version 1.51.0 to 1.50.0 in the lock file. This unintended downgrade contradicts the PR's stated purpose of only bumping pytest-cov and may introduce compatibility issues or remove features from the newer version.

Fix in Cursor Fix in Web

Comment thread pyproject.toml
pytest-cov = "^4.1"
ruff = "^0.14.4"
pytest-cov = "^7.0"
ruff = "^0.14.2"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Unintended Ruff Dependency Regression

The ruff dependency constraint was changed from ^0.14.4 to ^0.14.2, causing a downgrade from version 0.14.4 to 0.14.2 in the lock file. This unintended downgrade contradicts the PR's stated purpose of only bumping pytest-cov and may introduce compatibility issues or remove linting rules from the newer version.

Fix in Cursor Fix in Web

Comment thread pyproject.toml
ruff = "^0.14.2"
mypy = "^1.18"
pre-commit = "^4.4"
pre-commit = "^4.3"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Accidental pre-commit Dependency Downgrade

The pre-commit dependency constraint was changed from ^4.4 to ^4.3, causing a downgrade from version 4.4.0 to 4.3.0 in the lock file. This unintended downgrade contradicts the PR's stated purpose of only bumping pytest-cov and may introduce compatibility issues or remove features from the newer version.

Fix in Cursor Fix in Web

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant