Skip to content

Update tox requirement from <4.55,>=4.16.0 to >=4.16.0,<4.56#148

Merged
colectric-auto-merge-bot[bot] merged 1 commit into
mainfrom
dependabot/pip/main/tox-gte-4.16.0-and-lt-4.56
May 28, 2026
Merged

Update tox requirement from <4.55,>=4.16.0 to >=4.16.0,<4.56#148
colectric-auto-merge-bot[bot] merged 1 commit into
mainfrom
dependabot/pip/main/tox-gte-4.16.0-and-lt-4.56

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 28, 2026

Updates the requirements on tox to permit the latest version.

Release notes

Sourced from tox's releases.

v4.55.0

What's Changed

Full Changelog: tox-dev/tox@4.54.0...4.55.0

Changelog

Sourced from tox's changelog.

Features - 4.55.0

  • Automatically pass the TERMINFO environment variable to tox subprocesses if the output is a TTY. This variable is used by Ghostty to communicate terminal capabilities to programs. (:issue:3946)

Bug fixes - 4.55.0

  • When the constraints configuration option is set, constrain_package_deps and use_frozen_constraints are now ignored. Previously, both the user-provided constraints file and the auto-generated constraints file were passed to pip during install_package_deps, which could cause resolver conflicts when the same package appeared in both files - by :user:gaborbernat. (:issue:3945) (:issue:3945)

v4.54.0 (2026-05-12)


Features - 4.54.0

  • Declare the runtime dependencies of the tox.pytest plugin (pytest, devpi-process and pytest-mock) under a new testing extra, so plugin authors can pull them in via tox[testing] - by :user:gaborbernat. (:issue:3938, :issue:3940)

Bug fixes - 4.54.0

  • Extend the generated TOML schema to cover every replace table form (env, ref, posargs, glob, if), including conditional replacements used inside commands. A guard test asserts the schema stays in sync with the loader implementation so future replace types cannot be added without a corresponding schema entry. (:issue:3939)

v4.53.1 (2026-05-02)


Bug fixes - 4.53.1

  • Hardening pass on user-facing logging and config parsing:

    • Mask secret-looking --key=value flag values in command logs (terminal warnings, .tox/<env>/log/*.log, and Outcome __repr__) using the same keyword regex previously applied to environment variable values.
    • Resolve PEP 723 script paths and reject any that escape tox_root; cap the script read at 5 MiB so a symlink to /dev/zero cannot exhaust memory.
    • Replace eval() of a constructed Literal[...] string in the CLI parser with a direct Literal[tuple(action.choices)] subscript.
    • Pass timeout=30 to urlopen when fetching a remote requirements file so a slow or unresponsive mirror cannot hang tox indefinitely. (:issue:3924)

... (truncated)

Commits
  • 928b7f0 release 4.55.0
  • a43427f 🐛 fix(pip): skip constrain_package_deps when constraints is set (#3948)
  • 27b68b3 [pre-commit.ci] pre-commit autoupdate (#3947)
  • 4e6627c feat: Also pass TERMINFO when in an interactive shell (#3946)
  • 10c431c [pre-commit.ci] pre-commit autoupdate (#3943)
  • c86e876 👷 ci(schemastore): sync fork before pushing branch (#3942)
  • 1f1fcc7 release 4.54.0
  • b35c8ee 🐛 fix(schema): cover every replace form in the TOML schema (#3941)
  • 6eb5c4f ✨ feat(packaging): declare tox.pytest deps via a testing extra (#3940)
  • 1ad47dd 🧪 test(conftest): strip broken nspkg.pth files under py3.15 (#3937)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 28, 2026
Updates the requirements on [tox](https://github.com/tox-dev/tox) to permit the latest version.
- [Release notes](https://github.com/tox-dev/tox/releases)
- [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst)
- [Commits](tox-dev/tox@4.16.0...4.55.0)

---
updated-dependencies:
- dependency-name: tox
  dependency-version: 4.55.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/pip/main/tox-gte-4.16.0-and-lt-4.56 branch from df75d3f to 391c96d Compare May 28, 2026 10:16
@colectric-auto-merge-bot colectric-auto-merge-bot Bot merged commit c901c58 into main May 28, 2026
10 checks passed
@dependabot dependabot Bot deleted the dependabot/pip/main/tox-gte-4.16.0-and-lt-4.56 branch May 28, 2026 10:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants