Skip to content

Build(deps): Bump https://github.com/codespell-project/codespell from v2.4.2 to 2.4.3 - #844

Merged
pankajastro merged 1 commit into
mainfrom
dependabot/pre_commit/https-/github.com/codespell-project/codespell-2.4.3
Jul 27, 2026
Merged

Build(deps): Bump https://github.com/codespell-project/codespell from v2.4.2 to 2.4.3#844
pankajastro merged 1 commit into
mainfrom
dependabot/pre_commit/https-/github.com/codespell-project/codespell-2.4.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor

Bumps https://github.com/codespell-project/codespell from v2.4.2 to 2.4.3.

Release notes

Sourced from https://github.com/codespell-project/codespell's releases.

v2.4.3

What's Changed

... (truncated)

Commits
  • 57b2140 Read only [tool.codespell] from TOML config (#3975)
  • 23b8d94 [pre-commit.ci] pre-commit autoupdate
  • 926c4d6 [pre-commit.ci] pre-commit autoupdate
  • 820a301 Merge pull request #3967 from codespell-project/peternewman-patch-1
  • 9fe42c9 Add common misspellings for reseeve->reserve to dictionary
  • 725173c [pre-commit.ci] pre-commit autoupdate
  • 86c13ee [pre-commit.ci] pre-commit autoupdate
  • 7b9f36c Bump actions/checkout from 6 to 7
  • bcc1b80 Add spelling corrections for simpe and variants.
  • 89584cc [pre-commit.ci] pre-commit autoupdate
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [https://github.com/codespell-project/codespell](https://github.com/codespell-project/codespell) from v2.4.2 to 2.4.3.
- [Release notes](https://github.com/codespell-project/codespell/releases)
- [Commits](codespell-project/codespell@v2.4.2...v2.4.3)

---
updated-dependencies:
- dependency-name: https://github.com/codespell-project/codespell
  dependency-version: 2.4.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 22, 2026
@dependabot
dependabot Bot requested review from a team and gyli as code owners July 22, 2026 13:44
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 22, 2026
@dependabot
dependabot Bot requested review from pankajkoti and tatiana and removed request for a team July 22, 2026 13:44
@github-actions

Copy link
Copy Markdown

⏸️ Hold — Bot PR Safety Review

codespell v2.4.2 → 2.4.3 (pre-commit ecosystem, patch bump)

Axis Result Detail
Cooldown ❌ Violated PR opened 2026-07-22 (today, 0 days old). The 7-day cooldown requires waiting until 2026-07-29. No security advisory claimed in the PR body.
Security ✅ No advisory No CVE/GHSA referenced in the PR body. v2.4.3 release notes show only routine fixes and dictionary updates — no published security advisories.
Risk / blast radius ✅ Low Dev/CI-only change — codespell is a pre-commit spell-checker hook, not a runtime or shipped dependency. Patch-level bump. The Static-Check CI job runs pre-commit run --files dagfactory/*, which exercises codespell directly — green CI confirms the new version is compatible with the codebase.
CI gate ✅ Green All 54 check runs completed successfully: full unit-test and integration-test matrix, Static-Check (exercises codespell), zizmor, CodeQL, Code-Coverage all pass. No checks pending or awaiting maintainer authorization.
Tag integrity N/A Not a github-actions bump.

Recommendation: Wait until 2026-07-29 for the 7-day cooldown to elapse, then merge. No other concerns.


This review comment was generated by an agent. It is advisory only and does not approve or merge the PR. Reviewed on 2026-07-22 16:42 UTC.

@tatiana

tatiana commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

Bot PR review — codespell 2.4.2 → 2.4.3

Recommendation: ✅ Merge — trivial dev-tool patch, cooldown honored, CI green.

Cooldown: honored. v2.4.3 released 2026-07-15, PR opened 07-22 = 7 days.

Security: dev-only spell-checker, not shipped. No known advisories.

Risk: Low. Rev-only patch; codespell runs in pre-commit CI.

CI: all green.


This review comment was generated by Claude (Claude Code). It is advisory only and does not approve or merge the PR. Reviewed on 2026-07-27 10:27 UTC.

@pankajastro
pankajastro merged commit aa79415 into main Jul 27, 2026
54 checks passed
@pankajastro
pankajastro deleted the dependabot/pre_commit/https-/github.com/codespell-project/codespell-2.4.3 branch July 27, 2026 11:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file origin:bot review:easy

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants