Bump setuptools from 82.0.1 to 83.0.0#62
Conversation
Bumps [setuptools](https://github.com/pypa/setuptools) from 82.0.1 to 83.0.0. - [Release notes](https://github.com/pypa/setuptools/releases) - [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst) - [Commits](pypa/setuptools@v82.0.1...v83.0.0) --- updated-dependencies: - dependency-name: setuptools dependency-version: 83.0.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM — routine dependency bump.
Extended reasoning...
Overview
This PR is an automated Dependabot update to uv.lock only, bumping setuptools from 82.0.1 to 83.0.0. No application source files, tests, or configuration are touched.
Security risks
None identified. setuptools is a build-time packaging dependency, not part of the runtime request path, and does not touch tenant isolation, PHI handling, auth, or any application logic. The changelog for 83.0.0 shows a bugfix (Unicode-normalization handling in MANIFEST.in exclude patterns, GHSA-h35f-9h28-mq5c) and a minimum Python version bump to 3.10+, which this repo already requires.
Level of scrutiny
Minimal scrutiny is appropriate: this is a single-file lockfile diff generated by Dependabot with no hand-written code changes, matching the criteria for mechanical/low-risk changes that do not need human review.
Other factors
No prior reviews or comments exist on this PR. The change is additive/version-only and reversible by reverting the lockfile if it causes issues.
Bumps setuptools from 82.0.1 to 83.0.0.
Changelog
Sourced from setuptools's changelog.
Commits
6519f72Bump version: 82.0.1 → 83.0.0d1151b1Merge pull request #5250 from pypa/feature/distutils-d7633fbeda2df31eCapture removal of dry_run parameter in changelog.00144dcMoved newsfragment to the release where it occurred.a4a5a2bAdd news fragment.77470c2Merge https://github.com/pypa/distutils into feature/distutils-d7633fbed3c43897Merge pull request #5247 from pypa/copilot/fix-pypy-version-issuebb6ea66Bump PyPy from 3.10 to 3.11 in CI workflowa2bc3acFix broken intersphinx reference to build's installation docs2d6a739Use stacked parametrize decorators instead of itertools.productDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.