Skip to content

deps(deps): Bump the python-patch group with 2 updates#1

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-patch-831fe84a11
Closed

deps(deps): Bump the python-patch group with 2 updates#1
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-patch-831fe84a11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown

Bumps the python-patch group with 2 updates: striprtf and rapidfuzz.

Updates striprtf from 0.0.29 to 0.0.32

Release notes

Sourced from striprtf's releases.

new release v0.0.32

No release notes provided.

new release

Fixes #66

new release

Fixed joshy/striprtf#63

Changelog

Sourced from striprtf's changelog.

v0.0.32 - 27.04.206

  • Wrong _version file

v0.0.31 - 23.04.206

  • Accidently added twine as runtime dependency

v0.0.30 - 23.04.206

Commits

Updates rapidfuzz from 3.14.3 to 3.14.5

Release notes

Sourced from rapidfuzz's releases.

Release 3.14.5

Fixed

  • fix release ci attempting to upload a pyodide wheel

Release 3.14.4

Added

  • add risc64 wheels
  • add support for taskflow 4.0.0

Changed

  • upgrade to Cython==3.2.4.

Fixed

  • fix type hints for extractOne when no score_cutoff is provided
Changelog

Sourced from rapidfuzz's changelog.

Changelog

[3.14.5] - 2026-08-07 ^^^^^^^^^^^^^^^^^^^^^ Fixed

* fix release ci attempting to upload a pyodide wheel

[3.14.4] - 2026-04-06 ^^^^^^^^^^^^^^^^^^^^^ Added

  • add risc64 wheels
  • add support for taskflow 4.0.0

Changed

* upgrade to ``Cython==3.2.4``.

Fixed

* fix type hints for extractOne when no score_cutoff is provided

[3.14.3] - 2025-11-01
^^^^^^^^^^^^^^^^^^^^^
Fixed

  • add missing pypy and freethreaded linux wheels

Removed

  • drop s390x and ppc64le wheels since they are virtually unused and require extremly long to build under emulation

[3.14.2] - 2025-10-30 ^^^^^^^^^^^^^^^^^^^^^ Changed

* upgrade to ``Cython==3.1.6``
* enable free threading

[3.14.1] - 2025-09-08 ^^^^^^^^^^^^^^^^^^^^^ Fixed

* Fully disable line tracing in release builds

[3.14.0] - 2025-08-27
^^^^^^^^^^^^^^^^^^^^^
Changed
</tr></table>
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/edf9f3c2d016c878dae1511301f8b4a501bba871&quot;&gt;&lt;code&gt;edf9f3c&lt;/code&gt;&lt;/a> fix release ci</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/3d8470bf60062dda5c200517f61a8ff43e3e9ef2&quot;&gt;&lt;code&gt;3d8470b&lt;/code&gt;&lt;/a> enable verbose publish</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/7fd4ee202b5e3cc9f158f505a33d934a68c14148&quot;&gt;&lt;code&gt;7fd4ee2&lt;/code&gt;&lt;/a> Bump the github-actions group across 1 directory with 3 updates</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/9691cf1bf985eaf59f6c968f3d7cd8e59054ebaa&quot;&gt;&lt;code&gt;9691cf1&lt;/code&gt;&lt;/a> tag release</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/fd16748843be7d1a4842604fa3429e3943e80e5c&quot;&gt;&lt;code&gt;fd16748&lt;/code&gt;&lt;/a> ci: switch riscv64 from QEMU to native RISE runner</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/7f7d58b91a2716eaaec939a72b476ab1bf1ead1b&quot;&gt;&lt;code&gt;7f7d58b&lt;/code&gt;&lt;/a> ci: add riscv64 wheel builds via QEMU</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/f4b56942bdbbb99bba556656ea8a0aef1e8c12f0&quot;&gt;&lt;code&gt;f4b5694&lt;/code&gt;&lt;/a> Bump pypa/cibuildwheel from 3.3.1 to 3.4.0 in the github-actions group</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/f2873ce9868285eca1d05d8645791d76a2b545fe&quot;&gt;&lt;code&gt;f2873ce&lt;/code&gt;&lt;/a> Bump the github-actions group across 1 directory with 3 updates</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/4e48509d858454ea994521f90ae8c5d66eb15073&quot;&gt;&lt;code&gt;4e48509&lt;/code&gt;&lt;/a> support Taskflow 4.0.0</li>
<li><a href="https://github.com/rapidfuzz/RapidFuzz/commit/70480396a66fadabd897407ce289978dec2c13c0&quot;&gt;&lt;code&gt;7048039&lt;/code&gt;&lt;/a> Bump the github-actions group across 1 directory with 4 updates</li>
<li>Additional commits viewable in <a href="https://github.com/rapidfuzz/RapidFuzz/compare/v3.14.3...v3.14.5&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-patch group with 2 updates: [striprtf](https://github.com/joshy/striprtf) and [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz).


Updates `striprtf` from 0.0.29 to 0.0.32
- [Release notes](https://github.com/joshy/striprtf/releases)
- [Changelog](https://github.com/joshy/striprtf/blob/master/CHANGELOG.md)
- [Commits](joshy/striprtf@v0.0.29...v0.0.32)

Updates `rapidfuzz` from 3.14.3 to 3.14.5
- [Release notes](https://github.com/rapidfuzz/RapidFuzz/releases)
- [Changelog](https://github.com/rapidfuzz/RapidFuzz/blob/main/CHANGELOG.rst)
- [Commits](rapidfuzz/RapidFuzz@v3.14.3...v3.14.5)

---
updated-dependencies:
- dependency-name: striprtf
  dependency-version: 0.0.32
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-patch
- dependency-name: rapidfuzz
  dependency-version: 3.14.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 1, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/python-patch-831fe84a11 branch July 1, 2026 23:28
exbuf added a commit that referenced this pull request Jul 2, 2026
inaccurate --on-match claim on --watch composition

Two things in one commit — the second was uncovered while writing
the first, so they need to land together for the README to stay
factually correct.

1. **--on-match accuracy fix (README).** The "How these compose"
   section added in e8d10fd claimed --watch could pair with
   --on-match ("--on-match CMD for a live pattern sentinel").
   Verified against the code: --watch returns from run_watch()
   at cli.py:1586, BEFORE the on-match hook code around line 871.
   peekdocs/watcher.py has zero on_match references. --on-match
   is a batch-search hook (one hook per invocation); --watch's
   notification channel is the stdout NDJSON stream. Rewrites
   composition #1 to reflect that, with an explicit note calling
   out the difference so future readers don't fall into the
   same trap.

2. **Worked examples cross-linked from all three README
   compositions.** Compositions #2 (provenance audit) and #3
   (scheduled pattern scan) already had worked examples in
   USER_GUIDE.md (audit engagement provenance, line 1496; nightly
   source-tree watch, line 1419). Added cross-links in the
   README so readers don't have to hunt for them.

3. **New worked example: real-time pattern monitoring with
   --watch.** Composition #1 had no worked example — the
   "nightly source-tree watch" one uses cron, not the --watch
   flag. Added a full walkthrough in USER_GUIDE.md right after
   the audit engagement one:

     - Domain-neutral scenario (docs team hygiene watch — TODO
       markers, deprecated feature names, internal-only URLs).
       Deliberately not a compliance / credential scanning
       framing.
     - Setup: build regex collection in GUI.
     - Command: --watch --regex-collection piped to a shell
       loop that fires osascript display notifications.
     - Accurate NDJSON output shape (7 fields, verified against
       peekdocs/watcher.py's docstring).
     - Variations: Slack webhook, log-to-disk, jq prefilter.
     - Six gotchas: --on-match doesn't fire in --watch, Ctrl-C
       clean shutdown, refuse-to-run-as-root, --allow-system-paths
       warning, no delete events, noisy folders.
     - What this is not: pre-commit hook substitute.

4. USER_GUIDE TOC entry added for the new worked example.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
exbuf added a commit that referenced this pull request Jul 6, 2026
Reviewer's #1 code-health weakness after the mixin split was 149
`except Exception: pass` sites across the GUI mixins mixing real
defensive Tk guards with silent bug swallowers. When something
broke, the user saw "nothing happened" and the maintainer got no
signal.

Ships the infrastructure fix:

  peekdocs/gui/_error_guard.py

    gui_guard(operation)       — swallow exception AND log to
                                 peekdocs_errors.log with the
                                 operation name + traceback tail.
                                 For persistence writes, best-effort
                                 widget updates, and other cases
                                 where a persistent problem matters
                                 but a single occurrence shouldn't
                                 crash the UI.

    gui_race_guard()           — swallow silently. For Tk timing
                                 races (grab_set on not-yet-viewable
                                 window, focus_set on destroyed
                                 widget) where the retry-with-after()
                                 pattern handles correctness and
                                 logging would be pure noise.

Converts 4 persistence sites in _mixin_data.py as a pattern
demonstration:

  - factory reset: remove ~/.peekdocsrc
  - save text_size preference (config write)
  - clear search history: remove ~/.peekdocs_history.json
  - save bookmarks to disk

These are exactly the sites where a persistent disk-write problem
(read-only home, out of inodes, permissions issue) would matter to
the maintainer; the old bare `except Exception: pass` swallowed them
identically to a one-off race. Now they leave a log line.

7 new tests in tests/test_error_guard.py cover: swallow-and-log,
happy-path no-log, log-write-failure survival (the guard's own log
attempt must not cascade), and nested-guard stacking.

mypy scope extended to _error_guard.py (9 files typed now).

ARCHITECTURE.md known-weaknesses list gets a new entry documenting
the partial fix and pointing at the remaining conversion work (one-
at-a-time across ~145 remaining sites).

Full suite: 710 passed (703 + 7 new), 8 skipped, 0 failing. mypy
clean on 9 typed files.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
exbuf added a commit that referenced this pull request Jul 6, 2026
User reported on 1.2.80: About → View License in the standalone
GUI shows "LICENSE file not found in this build" on both macOS and
Windows.

Diagnosis on macOS. I downloaded the released
peekdocs-gui-macos.zip and inspected the .app bundle:

  peekdocs-gui.app/Contents/Resources/LICENSE          <- actually here
  peekdocs-gui.app/Contents/Resources/NOTICE
  peekdocs-gui.app/Contents/Resources/THIRD_PARTY_NOTICES.md

But sys._MEIPASS on a PyInstaller --onedir --windowed .app bundle
points at Contents/Frameworks/ (runtime + libraries), NOT
Contents/Resources/. resource_path("LICENSE") returned
Contents/Frameworks/LICENSE, which doesn't exist, so the fallback
"not found" message displayed.

This behavior is not documented anywhere in PyInstaller's docs —
--add-data payloads simply land in a different bundle directory
than the runtime under --windowed on macOS. Traditional
sys._MEIPASS-only lookups miss them.

Windows check. I parsed the peekdocs-gui-windows.exe TOC and
verified LICENSE IS present at the archive root, which _should_
extract to _MEIPASS/LICENSE at runtime. If the user still sees the
fallback on Windows, likely a cached older exe (before the file
was bundled at all) or a runtime-permission issue — the
multi-candidate fix below is defensive either way.

Fix. Extended resource_path() to search a small ordered candidate
list under sys._MEIPASS and return the first that exists on disk:

  1. sys._MEIPASS/relative_path
     (traditional --onefile / --onedir root — works on Windows,
     Linux, macOS CLI)
  2. sys._MEIPASS/../Resources/relative_path
     (macOS .app bundle — Contents/Resources/ relative to
     Contents/Frameworks/)

If no candidate exists, return the traditional #1 path so the
caller's os.path.exists() check hits False and its own
"not found" fallback logic runs. This preserves API behavior for
existing consumers.

Design note: this only affects the PyInstaller-frozen path. Source
checkouts and pip/pipx installs continue to use the repo-root and
dist-info paths respectively. The docstring gains a full
per-build-mode breakdown so a future maintainer doesn't hit the
same "why isn't _MEIPASS enough" puzzle.

4 new tests in tests/test_paths.py cover: traditional root lookup,
macOS .app Contents/Resources/ fallback, no-candidate returns
traditional path (for caller fallback), root-wins-over-resources
when both exist.

Full suite: 721 passed (up from 717, +4 new), 8 skipped, 0
failing. mypy clean on 12 typed files.

Fix ships in next release build. About → View License will show
the actual LICENSE text once the user re-downloads.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
exbuf added a commit that referenced this pull request Jul 9, 2026
"Pipeline" appears in README sentence #1 ("a single pipeline") but was
undefined for non-technical readers. Add a plain-language entry explaining
what a pipeline is and the benefit of peekdocs's single pipeline (same
steps, options, and reports across all 100+ file types).

Also reconcile the glossary term count — the doc table said 93 and the
prose said 92; the actual count is now 94. Both README references updated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
exbuf added a commit that referenced this pull request Jul 9, 2026
…d sections)

Found by a full internal-link audit across all project markdown (415 links,
now 0 broken). All pre-existing doc-rot, unrelated to MCP:

- GLOSSARY -> README#prerequisites          => #3-prerequisites (numbered heading)
- INSTALLATION -> README#option-a-...        => #1-option-a-... (numbered heading)
- WALKTHROUGHS -> README#screenshots         => #watch-peekdocs-in-action (renamed)
- TROUBLESHOOTING -> USER_GUIDE#command-examples => #complete-cli-reference (renamed)
- USER_GUIDE -> GLOSSARY#file-integrity-monitoring-fim: the term is a table cell
  (no auto anchor); added an explicit <a id> matching the existing convention.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
exbuf added a commit that referenced this pull request Jul 19, 2026
Per the clarity review — trim the most-repeated points without losing any,
keeping each stated fully once.

README (local-model privacy pitch, repeated ~6x):
- Opening MCP paragraph stated the local/privacy point twice and re-spelled the
  model list; tightened to one clean statement that defers the cloud-vs-local
  nuance to the "A note on privacy" block right below.
- The "Anyone who'd rather ask" persona bullet re-pitched local/cloud at the
  end → compressed to one clause + the existing MCP-section link.

USER_GUIDE ("by design" overlap):
- Removed the standalone "summarize what you found" sentence (said 5-6x
  elsewhere); kept a compressed parenthetical on the One-way point.
- Flow-closer re-explained the whole cloud/local split (privacy thesis #1 of 3)
  → compressed to one clause + a single pointer to "Does it keep everything on
  your machine?".
- Dropped the "unit-testable without importing mcp" implementation aside from
  the user-facing benefits sentence.

Each point is still stated fully once. Docs only; no version bump.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants