Skip to content

Update all non-major dependencies - #397

Merged
renovate[bot] merged 1 commit into
developfrom
renovate/all-minor-patch
Oct 5, 2026
Merged

renovate[bot] merged 1 commit into
developfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
astral-sh/setup-uv action minor v10.1.0 → v10.2.0 age confidence
jupytext project.dependencies patch 1.19.5 → 1.19.6 age confidence

Release Notes

astral-sh/setup-uv (astral-sh/setup-uv)

v10.2.0

Compare Source

jupytext/jupytext (jupytext)

v1.19.6

Compare Source

Security

  • The Quarto conversions now run in a private temporary directory, so that the output file that quarto convert names after its input can no longer be pre-created as a symlink by another user of the machine. Thanks to Naveed for the PR (#​1615).
  • Paired paths from notebook formats metadata are now prevented from escaping the working tree, including when an absolute notebook path is used. Thanks to Naveed for addressing the issue (#​1588).
  • The CLI now ignores trusted cell metadata when the notebook signature is invalid, so a trusted=true option in a
    paired text file cannot make untrusted notebook outputs trusted during --sync. Thanks to
    Naveed for the fix (#​1617).
  • Custom cell_markers and endofcell values in the light format are now matched literally, preventing regular-expression
    injection, parsing errors, and excessive processing time on crafted notebooks. This also fixes writing OCaml notebooks
    with custom cell markers. Thanks to Naveed again for the PR
    (#​1618).
  • We have merged Dependabot security updates for the JupyterLab extension and the documentation website
    (#​1614, #​1620,
    #​1622, #​1624,
    #​1634, #​1639,
    #​1642, #​1643,
    #​1647, #​1653,
    #​1654).

Fixed

  • Menu entries such as "Rename Notebook…" name the file type again, instead of saying "default". Thanks to
    Michał Krassowski for this PR (#​1632).
  • Mermaid %% comments inside a markdown cell are no longer mistaken for py:percent cell markers (#​1533). Thanks to Sanjay Santhanam for his PR (#​1609)
  • A whitespace-only final line in a percent-format cell is now preserved when reading and round-tripping the notebook
    (#​1599). Thanks to lowbyteguy
    for the PR (#​1610).
  • The JupyterLab extension's development install script now uses the correct jupyter-builder import
    (#​1632). Thanks again to Michał Krassowski
    for this fix.
  • Fixed JupyterLab extension build issues related to Yarn package checksums. Thanks to
    Mahendra Paipuri for his contributions to
    #​1614, #​1620,
    and #​1621.
  • Fixed pairing on Windows when a prefix root contains subdirectories, such as notebooks/tutorials///ipynb.

Changed

Added

  • We have added a development container that can be opened with VS Code’s Dev Containers extension
    (#​1655).
  • Added support for the Jenner language. Thanks to Lawrence Sinclair for this contribution (#​1493).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from f994ae9 to 52f1048 Compare October 5, 2026 00:46
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 52f1048 to 815d563 Compare October 5, 2026 00:48
@renovate
renovate Bot merged commit c3e4142 into develop Oct 5, 2026
4 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch October 5, 2026 06:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants