Skip to content

Bump pre-commit from 4.6.1 to 4.6.2 - #2257

Merged
JSv4 merged 4 commits into
mainfrom
dependabot/pip/pre-commit-4.6.2
Aug 30, 2026
Merged

JSv4 merged 4 commits into
mainfrom
dependabot/pip/pre-commit-4.6.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps pre-commit from 4.6.1 to 4.6.2.

Release notes

Sourced from pre-commit's releases.

pre-commit v4.6.2

Fixes

Changelog

Sourced from pre-commit's changelog.

4.6.2 - 2026-08-10

Fixes

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 4.6.1 to 4.6.2.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v4.6.1...v4.6.2)

---
updated-dependencies:
- dependency-name: pre-commit
  dependency-version: 4.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Aug 17, 2026
@claude

claude Bot commented Aug 17, 2026

Copy link
Copy Markdown

Review

This is a routine Dependabot dependency bump: pre-commit 4.6.1 → 4.6.2 in requirements/local.txt (+1/-1, dev-only tooling dependency).

  • Code quality / bugs / security: N/A — no application code, config, or logic changes. pre-commit is a dev/CI tool, not a runtime dependency, so there's no production security surface here.
  • Change content: The 4.6.2 release is a bugfix-only patch (fixes language: node hooks with "scripts": {"build": ...} under npm 11.x, per the linked changelog) — a strict improvement over 4.6.1 with low regression risk.
  • Test coverage: No tests needed for a lockfile-style version bump; CI running pre-commit itself is sufficient verification.

LGTM — safe to merge.

@claude

claude Bot commented Aug 30, 2026

Copy link
Copy Markdown

Review

Straightforward Dependabot patch bump: pre-commit 4.6.1 → 4.6.2 in requirements/local.txt.

  • Scope: pre-commit is a dev-only tool (pre-commit hook runner), not part of the application runtime — no production code paths are affected.
  • Change content: The 4.6.2 release is a narrow bugfix (fixes language: node hooks with npm 11.x "scripts": {"build": ...}, regressed in 4.6.1). No breaking changes noted in the release notes.
  • Risk: Minimal — patch version, single line diff, no lockfile/transitive dependency changes visible in the diff.
  • Tests: No test coverage needed for a tooling version bump; nothing in the app's behavior changes.

No concerns. Safe to merge.

claude added 2 commits August 30, 2026 03:34
The linter job on this PR fails with 10 I001/I005 findings in
opencontractserver/llms/agents/pydantic_ai_agents.py and
opencontractserver/utils/compact_pawls.py — files this PR does not touch. The
failure reproduces identically on a clean origin/main checkout: the flake8
hook's unpinned flake8-isort floated to isort 9.0.1 while the standalone isort
hook stayed rev-pinned to 6.0.1, and the two disagree about repeated
`from X import (...)` statements.

Cherry-picking the pin here so this PR can reach green without waiting on
#2281 to merge. It no-ops once main carries the same change.
The linter job on this PR fails with 10 I001/I005 findings in
opencontractserver/llms/agents/pydantic_ai_agents.py and
opencontractserver/utils/compact_pawls.py — files this PR does not touch. The
failure reproduces identically on a clean origin/main checkout: the flake8
hook's unpinned flake8-isort floated to isort 9.0.1 while the standalone isort
hook stayed rev-pinned to 6.0.1, and the two disagree about repeated
`from X import (...)` statements.

Only the flake8 pin is ported. #2281 also bumps this hook file's mypy stub
pins, but that half needs the type fixes that ship with it, so it stays there.

Cherry-picking so this PR can reach green without waiting on #2281 to merge.
It no-ops once main carries the same change.
@claude

claude Bot commented Aug 30, 2026

Copy link
Copy Markdown

Review

Routine Dependabot bump (pre-commit 4.6.1 → 4.6.2, a patch release fixing language: node hooks with npm 11.x) plus two follow-up commits pinning flake8-isort/isort versions in .pre-commit-config.yaml. No production code is touched.

Code quality / correctness

  • The added additional_dependencies pins (flake8-isort==7.0.0, isort==6.0.1) are internally consistent: flake8-isort==7.0.0 matches requirements/local.txt:32, and isort==6.0.1 matches the standalone isort hook's rev (.pre-commit-config.yaml:49). The comment block explaining why (unpinned additional_dependencies float independently of rev on rebuild, so the two isort resolutions silently diverged and produced conflicting I001/I005 verdicts) is exactly the kind of load-bearing rationale that's easy to lose — good call documenting it inline rather than just fixing it silently.
  • Minor, pre-existing and unrelated to this PR: the flake8 hook is still pinned to rev: 7.2.0 (.pre-commit-config.yaml:54) while requirements/local.txt:31 specifies flake8==7.3.0. Not something to fix here, but worth a follow-up so local flake8 runs and the pre-commit hook stay on the same version.

Scope note

Tests / security / performance

  • Config-only change (.pre-commit-config.yaml, requirements/local.txt); no test coverage needed and no security or performance implications.

Overall: low risk, well-justified. LGTM.

@codecov

codecov Bot commented Aug 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

JSv4 commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator

Picked this up as part of a batch pass over the open PRs. The review above had no open items ("LGTM — safe to merge"), and nothing about the bump itself needed changing. Two things happened to the branch:

main merged in to bring it up to date (it was based on 5ca0a1f).

One cherry-picked fix. linter was failing here for a reason unrelated to this bump: 10 I001/I005 findings in opencontractserver/llms/agents/pydantic_ai_agents.py and opencontractserver/utils/compact_pawls.py, neither of which this PR touches. It reproduces identically on a clean main — the flake8 hook's additional_dependencies: [flake8-isort] carried no version, and pre-commit re-resolves those on every hook-env rebuild, so flake8-isort floated to isort 9.0.1 while the standalone isort hook stayed rev-pinned to 6.0.1. The two disagree about repeated from X import (...) statements, so isort kept writing a layout flake8 rejected.

Fix is in #2281 and cherry-picked here so this PR can go green without waiting on it; it no-ops once #2281 merges.

Also confirmed the CLA check now passes — dependabot[bot] is on the cla.yml allowlist, so the earlier CLAAssistant failure was just a stale run from before that landed.

Current state: all checks green — linter, pytest, redis-integration, CodeQL, CLAAssistant, backend-ci-gate, and all three codecov/patch statuses.


Generated by Claude Code

@JSv4
JSv4 merged commit 67671c2 into main Aug 30, 2026
16 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 30, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/pre-commit-4.6.2 branch August 30, 2026 11:39
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants