Skip to content

build(deps): bump actions/setup-python from 6 to 7 - #552

Merged
sumithr merged 2 commits into
mainfrom
dependabot/github_actions/actions/setup-python-7
Aug 3, 2026
Merged

sumithr merged 2 commits into
mainfrom
dependabot/github_actions/actions/setup-python-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

Bumps actions/setup-python from 6 to 7.

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

@dependabot dependabot Bot added ci Continuous integration / GitHub Actions deps Dependency updates labels Jul 20, 2026
@dependabot
dependabot Bot requested a review from sumithr as a code owner July 20, 2026 07:10
@dependabot dependabot Bot added deps Dependency updates ci Continuous integration / GitHub Actions labels Jul 20, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 2, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@sumithr

sumithr commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Parked from the current dependency batch on blast radius: this PR changes runner setup across all 10 workflow files (#463 is 17 call sites, #552 is 16), so a regression removes the whole CI signal rather than one job. Neither is driven by a security advisory.

Deliberately left open rather than closed so Dependabot keeps it rebased. Tracked in #581 for evaluation as its own piece of work.

Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-python-7 branch from 753c89c to f82076b Compare August 3, 2026 13:10
@sumithr

sumithr commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Un-parked and verified. Fresh CI against current main: 33 passed, 0 failed.

v7 has two changes that could have bitten this repo. Both checked:

1. pip-install input removed (actions/setup-python#1336). Not used anywhere:

grep -rn 'pip-install' .github/workflows/   ->  NO

The only inputs we pass are python-version, cache: pip and cache-dependency-path: pyproject.toml.

2. EOL Python versions removed (actions/setup-python#1333). Our matrix spans 3.10 to 3.14, so this was the real risk. All edge jobs pass:

pass  pytest (ubuntu-latest / macos-latest / windows-latest, py3.10)
pass  pytest (ubuntu-latest / macos-latest / windows-latest, py3.14)

3. @actions/cache upgraded to 6.2.0 (actions/setup-python#1337). We rely on cache: pip in 8 places, and a silent cache regression shows up as slow CI rather than red CI, so it was checked directly in the lint run:

Cache hit for: setup-python-Linux-x64-24.04-Ubuntu-python-3.13.14-pip-0425a2e...
Cache restored successfully
Cache hit occurred on the primary key ..., not saving cache.

16 call sites across all 10 workflow files, all green.

@sumithr
sumithr merged commit 3d04f92 into main Aug 3, 2026
33 checks passed
@sumithr
sumithr deleted the dependabot/github_actions/actions/setup-python-7 branch August 3, 2026 14:40
sumithr added a commit that referenced this pull request Aug 3, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.60.5](v0.60.4...v0.60.5)
(2026-08-03)


### Build System

* **deps:** bump actions/checkout from 5 to 7
([#463](#463))
([f2af4bc](f2af4bc))
* **deps:** bump actions/setup-python from 6 to 7
([#552](#552))
([3d04f92](3d04f92))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <release-please[bot]@users.noreply.github.com>
sumithr added a commit that referenced this pull request Sep 23, 2026
#708)

Updates the requirements on [mutmut](https://github.com/boxed/mutmut) to
permit the latest version.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/boxed/mutmut/releases">mutmut's
releases</a>.</em></p>
<blockquote>
<h2>3.8.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: mutate ternary conditions by <a
href="https://github.com/espressolee"><code>@​espressolee</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/546">boxed/mutmut#546</a></li>
<li>fix: mutate methods of decorated classes by <a
href="https://github.com/Sanjays2402"><code>@​Sanjays2402</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/539">boxed/mutmut#539</a></li>
<li>Add mutation score badge support by <a
href="https://github.com/rxdt"><code>@​rxdt</code></a> in <a
href="https://redirect.github.com/boxed/mutmut/pull/549">boxed/mutmut#549</a></li>
<li>wip: don't mutate lines excluded from coverage by <a
href="https://github.com/nedbat"><code>@​nedbat</code></a> in <a
href="https://redirect.github.com/boxed/mutmut/pull/547">boxed/mutmut#547</a></li>
<li>chore: add support python3.15 by <a
href="https://github.com/even-even"><code>@​even-even</code></a> in <a
href="https://redirect.github.com/boxed/mutmut/pull/551">boxed/mutmut#551</a></li>
<li>Fix mutants missed when tests clear os.environ by <a
href="https://github.com/DSeaStar"><code>@​DSeaStar</code></a> in <a
href="https://redirect.github.com/boxed/mutmut/pull/552">boxed/mutmut#552</a></li>
<li>chore: up mypy to 2.3.1 by <a
href="https://github.com/even-even"><code>@​even-even</code></a> in <a
href="https://redirect.github.com/boxed/mutmut/pull/553">boxed/mutmut#553</a></li>
<li>Honour 'pragma: no mutate block' on else/except/finally arms by <a
href="https://github.com/dylanpulver"><code>@​dylanpulver</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/559">boxed/mutmut#559</a></li>
<li>refac: main decomposition by <a
href="https://github.com/nicklafleur"><code>@​nicklafleur</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/561">boxed/mutmut#561</a></li>
<li>ci: pre-commit workflow by <a
href="https://github.com/nicklafleur"><code>@​nicklafleur</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/567">boxed/mutmut#567</a></li>
<li>fix: delete twice &quot;-24&quot; param and up ruff for tests it by
<a href="https://github.com/even-even"><code>@​even-even</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/565">boxed/mutmut#565</a></li>
<li>Fix &quot;pragma: no mutate&quot; on match/case headers being
silently ignored by <a
href="https://github.com/mathieu-lacage"><code>@​mathieu-lacage</code></a>
in <a
href="https://redirect.github.com/boxed/mutmut/pull/554">boxed/mutmut#554</a></li>
<li>misc: update history by <a
href="https://github.com/nicklafleur"><code>@​nicklafleur</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/576">boxed/mutmut#576</a></li>
<li>feat: process isolation and fork-safe test runners by <a
href="https://github.com/nicklafleur"><code>@​nicklafleur</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/566">boxed/mutmut#566</a></li>
<li>Fix obsolete test names never being removed from the stats file by
<a href="https://github.com/t-roi33"><code>@​t-roi33</code></a> in <a
href="https://redirect.github.com/boxed/mutmut/pull/569">boxed/mutmut#569</a></li>
<li>Release 3.8.0 by <a
href="https://github.com/nicklafleur"><code>@​nicklafleur</code></a> in
<a
href="https://redirect.github.com/boxed/mutmut/pull/581">boxed/mutmut#581</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/espressolee"><code>@​espressolee</code></a>
made their first contribution in <a
href="https://redirect.github.com/boxed/mutmut/pull/546">boxed/mutmut#546</a></li>
<li><a href="https://github.com/rxdt"><code>@​rxdt</code></a> made their
first contribution in <a
href="https://redirect.github.com/boxed/mutmut/pull/549">boxed/mutmut#549</a></li>
<li><a href="https://github.com/nedbat"><code>@​nedbat</code></a> made
their first contribution in <a
href="https://redirect.github.com/boxed/mutmut/pull/547">boxed/mutmut#547</a></li>
<li><a href="https://github.com/DSeaStar"><code>@​DSeaStar</code></a>
made their first contribution in <a
href="https://redirect.github.com/boxed/mutmut/pull/552">boxed/mutmut#552</a></li>
<li><a
href="https://github.com/dylanpulver"><code>@​dylanpulver</code></a>
made their first contribution in <a
href="https://redirect.github.com/boxed/mutmut/pull/559">boxed/mutmut#559</a></li>
<li><a
href="https://github.com/mathieu-lacage"><code>@​mathieu-lacage</code></a>
made their first contribution in <a
href="https://redirect.github.com/boxed/mutmut/pull/554">boxed/mutmut#554</a></li>
<li><a href="https://github.com/t-roi33"><code>@​t-roi33</code></a> made
their first contribution in <a
href="https://redirect.github.com/boxed/mutmut/pull/569">boxed/mutmut#569</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/boxed/mutmut/compare/3.7.0...3.8.0">https://github.com/boxed/mutmut/compare/3.7.0...3.8.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/boxed/mutmut/blob/main/HISTORY.rst">mutmut's
changelog</a>.</em></p>
<blockquote>
<p>3.8.0</p>
<pre><code>
* Fix obsolete test names never being removed from
``mutants/mutmut-stats.json``
(`[#564](https://github.com/boxed/mutmut/issues/564)`)
<ul>
<li>
<p>Fix <code># pragma: no mutate block</code> being silently ignored
when placed on an <code>else</code>, <code>except</code>,
<code>except*</code> or <code>finally</code> header, and on the
<code>try</code> line of a <code>try</code>/<code>except*</code>
(<code>[#559](https://github.com/boxed/mutmut/issues/559)</code>)</p>
</li>
<li>
<p>Fix <code># pragma: no mutate</code> being silently ignored on
<code>match</code> and <code>case</code> headers
(<code>[#554](https://github.com/boxed/mutmut/issues/554)</code>)</p>
</li>
<li>
<p>Fix mutants being reported as survived when a test uses
<code>patch.dict(os.environ, ..., clear=True)</code>
(<code>[#511](https://github.com/boxed/mutmut/issues/511)</code>,
<code>[#552](https://github.com/boxed/mutmut/issues/552)</code>)</p>
</li>
<li>
<p>Fix <code>mutate_only_covered_lines</code> mutating code that
coverage.py excludes from measurement (<code># pragma: no cover</code>,
<code>exclude_lines</code>, <code>exclude_also</code>)
(<code>[#547](https://github.com/boxed/mutmut/issues/547)</code>)</p>
</li>
<li>
<p>Fix mutations that delete ignored code. Dropping a <code>case</code>
from a <code>match</code>, or an argument from a call, is a mutation of
the enclosing node, so it used to be made even when the removed lines
were themselves ignored
(<code>[#547](https://github.com/boxed/mutmut/issues/547)</code>)</p>
</li>
<li>
<p>Fix methods of decorated classes (for example
<code>@DataClass</code>) not being mutated
(<code>[#480](https://github.com/boxed/mutmut/issues/480)</code>,
<code>[#539](https://github.com/boxed/mutmut/issues/539)</code>)</p>
</li>
<li>
<p>Fix time measurement including test setup/teardown instead of only
the main test run
(<code>[#544](https://github.com/boxed/mutmut/issues/544)</code>)</p>
</li>
<li>
<p>Fix mutants stopped by the CPU-time limit being reported as killed
instead of timed out
(<code>[#565](https://github.com/boxed/mutmut/issues/565)</code>)</p>
</li>
<li>
<p>Fix <code>mutate_only_covered_lines</code> breaking when the test
suite imports a dependency that cannot be initialized twice in one
process, which raised for numpy and libyaml, produced misleading type
errors for cryptography, and segfaulted for asyncpg. Coverage is now
gathered in a separate process, so the modules the coverage run imports
are no longer unloaded and re-imported in the main process
(<code>[#528](https://github.com/boxed/mutmut/issues/528)</code>,
<code>[#566](https://github.com/boxed/mutmut/issues/566)</code>)</p>
</li>
<li>
<p>Mutate the condition of ternary expressions
(<code>[#196](https://github.com/boxed/mutmut/issues/196)</code>,
<code>[#546](https://github.com/boxed/mutmut/issues/546)</code>)</p>
</li>
<li>
<p>Add a <code>process_isolation</code> config for choosing which
process mutant workers are forked from. The new <code>forkserver</code>
strategy keeps mutmut's main process free of pytest and your
<code>conftest.py</code>, routing every fork through a dedicated fork
server process, for test setups that are not fork-safe
(<code>gevent</code>, <code>grpc</code>, <code>torch</code>). Tune what
it preloads with <code>forkserver_warmup</code>
(<code>[#578](https://github.com/boxed/mutmut/issues/578)</code>,
<code>[#566](https://github.com/boxed/mutmut/issues/566)</code>)</p>
</li>
<li>
<p>Add a <code>badge</code> command that writes a shields.io endpoint
file, for publishing the mutation score
(<code>[#549](https://github.com/boxed/mutmut/issues/549)</code>)</p>
</li>
<li>
<p>Support python3.15
(<code>[#551](https://github.com/boxed/mutmut/issues/551)</code>)</p>
</li>
</ul>
<p>3.7.0</p>
<pre><code>
* Fix the trampoline dropping a generator's return value, so ``yield
from`` on a mutated generator no longer yields ``None`` instead of its
result

* Fix async generators, so that `aclose()`/`athrow()` are handled by the
`except`/`finally` blocks of the mutated function instead of being
swallowed by the trampoline

* Fix `max_stack_depth` when a test changes the working directory (for
example via a tmpdir fixture)

* Fix `type_check_command` reporting type errors in copied files that
have no mutants

* Per-function source hashing for incremental cache invalidation — only
re-test mutants in functions that changed

* Cross-call dependency tracking — invalidate mutants in callers when a
called function changes

* Use git to detect non-Python dependency file changes; falls back to a
curated file list when git is unavailable

* Add `cache_invalidation_exclude` config to suppress noisy files from
change detection

&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt; 
&lt;/code&gt;&lt;/pre&gt;
&lt;/blockquote&gt;
&lt;p&gt;... (truncated)&lt;/p&gt;
&lt;/details&gt;
&lt;details&gt;
&lt;summary&gt;Commits&lt;/summary&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@14a7230049a5c8abd90c2bb0f7438e30da6471f5&quot;&gt;&lt;code&gt;14a7230&lt;/code&gt;&lt;/a&gt;
Release 3.8.0 (&lt;a
href=&quot;https://redirect.github.com/boxed/mutmut/issues/581&quot;&gt;#581&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@4ff5d9e9c23c5f75404cc3696ad6fb7c1e4888e8&quot;&gt;&lt;code&gt;4ff5d9e&lt;/code&gt;&lt;/a&gt;
Fix obsolete test names never being removed from the stats file (&lt;a
href=&quot;https://redirect.github.com/boxed/mutmut/issues/569&quot;&gt;#569&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@c3a8f4b402b01873cc788774c0ce15d2a1cebb86&quot;&gt;&lt;code&gt;c3a8f4b&lt;/code&gt;&lt;/a&gt;
feat: process isolation and fork-safe test runners (&lt;a
href=&quot;https://redirect.github.com/boxed/mutmut/issues/566&quot;&gt;#566&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@7f8ba005185ac98216cbeedfcacffeb4229366fa&quot;&gt;&lt;code&gt;7f8ba00&lt;/code&gt;&lt;/a&gt;
misc: update history (&lt;a
href=&quot;https://redirect.github.com/boxed/mutmut/issues/576&quot;&gt;#576&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@301df52797ae34a1fadac176cd2afa50186050ea&quot;&gt;&lt;code&gt;301df52&lt;/code&gt;&lt;/a&gt;
Fix pragma: no mutate on match/case headers being silently
ignored&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@630e84662635eb57d35fe935365af0152d58094a&quot;&gt;&lt;code&gt;630e846&lt;/code&gt;&lt;/a&gt;
fix: delete twice &amp;quot;-24&amp;quot; param and up ruff for tests
it&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@b1d127060ad4f79d2e81f8317842263435586851&quot;&gt;&lt;code&gt;b1d1270&lt;/code&gt;&lt;/a&gt;
ci: pre-commit workflow (&lt;a
href=&quot;https://redirect.github.com/boxed/mutmut/issues/567&quot;&gt;#567&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@748bfc06bddbeb09855dda592c2156cb9ef42310&quot;&gt;&lt;code&gt;748bfc0&lt;/code&gt;&lt;/a&gt;
refac: main decomposition (&lt;a
href=&quot;https://redirect.github.com/boxed/mutmut/issues/561&quot;&gt;#561&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@2f39c84dcbf3b9fdabafe395200d090d4f47de65&quot;&gt;&lt;code&gt;2f39c84&lt;/code&gt;&lt;/a&gt;
Honour 'pragma: no mutate block' on else/except/finally arms (&lt;a
href=&quot;https://redirect.github.com/boxed/mutmut/issues/559&quot;&gt;#559&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a
href=&quot;boxed/mutmut@e450cfcf52ce5bbd89941cef9c2e988cb798231b&quot;&gt;&lt;code&gt;e450cfc&lt;/code&gt;&lt;/a&gt;
chore: up mypy to 2.3.1&lt;/li&gt;
&lt;li&gt;Additional commits viewable in &lt;a
href=&quot;boxed/mutmut@3.7.0...3.8.0&quot;&gt;compare
view&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;

&lt;br /&gt;</code></pre>

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: sumithr <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci Continuous integration / GitHub Actions deps Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant