-
Notifications
You must be signed in to change notification settings - Fork 9
Comparing changes
Open a pull request
base repository: DiamondLightSource/python-copier-template
base: 5.3.0
head repository: DiamondLightSource/python-copier-template
compare: 5.4.0
- 7 commits
- 10 files changed
- 3 contributors
Commits on Jul 22, 2026
-
chore(deps): update astral-sh/setup-uv action to v9 (#363)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) | action | major | `v8.3.2` → `v9.0.0` | --- ### Release Notes <details> <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary> ### [`v9.0.0`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.2...v9.0.0) [Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.2...v9.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/DiamondLightSource/python-copier-template). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for a0cac98 - Browse repository at this point
Copy the full SHA a0cac98View commit details
Commits on Jul 27, 2026
-
chore(deps): lock file maintenance (#366)
This PR contains the following updates: | Update | Change | |---|---| | lockFileMaintenance | All locks refreshed | 🔧 This Pull Request updates lock files to use the latest dependency versions. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/DiamondLightSource/python-copier-template). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b8caef5 - Browse repository at this point
Copy the full SHA b8caef5View commit details
Commits on Jul 29, 2026
-
fix: copier should not be a dev dependency (#364)
## Summary `copier` should not be installed as a dev dependency of *generated* projects — it should be invoked via `uvx copier` instead. This PR removes it from the template's dev dependency group and updates the docs to recommend `uvx copier update`. - `template/pyproject.toml.jinja`: removed `"copier"` from the `dev` dependency-group list. - `docs/how-to/update-template.md`: changed the two bare `copier update` invocations to `uvx copier update`. - `.github/CONTRIBUTING.md`: changed `copier update --vcs-ref=<branch_name>` to `uvx copier update --vcs-ref=<branch_name>`. ## Deliberately left untouched - Root `pyproject.toml` — this template repo's own test suite imports `copier` (`from copier import run_copy`), so it legitimately needs `copier` as a dev dependency here. - `tests/test_example.py` — its bare `copier update` call runs in this repo's own dev environment, not inside a generated project. - Tutorial docs (`docs/tutorials/adopt-existing.md`, `docs/tutorials/create-new.md`) and prose/comment mentions of "copier" — already correct or out of scope. ## Testing - `uv run --locked tox -e pre-commit` — passed. - `uv run --locked tox -e tests` — 5 pre-existing failures unrelated to this change (sandbox network proxy blocks a docs-build version-switcher request to `diamondlightsource.github.io`, and one test has a version-string mismatch from running off an untagged commit rather than a release tag). No failures caused by this change; `test_example_repo_updates`'s actual file-content diff was clean aside from that unrelated version string. Closes #343 --- _Generated by [Claude Code](https://claude.ai/code/session_01VuHBQ1iEZogr1q7VBjA2iL)_ Co-authored-by: Claude <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for 718a485 - Browse repository at this point
Copy the full SHA 718a485View commit details
Commits on Aug 3, 2026
-
chore(deps): lock file maintenance (#367)
This PR contains the following updates: | Update | Change | |---|---| | lockFileMaintenance | All locks refreshed | 🔧 This Pull Request updates lock files to use the latest dependency versions. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/DiamondLightSource/python-copier-template). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 4ee6984 - Browse repository at this point
Copy the full SHA 4ee6984View commit details
Commits on Aug 10, 2026
-
chore(deps): lock file maintenance (#368)
This PR contains the following updates: | Update | Change | |---|---| | lockFileMaintenance | All locks refreshed | 🔧 This Pull Request updates lock files to use the latest dependency versions. --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 4am on monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/DiamondLightSource/python-copier-template). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for f39321a - Browse repository at this point
Copy the full SHA f39321aView commit details
Commits on Aug 14, 2026
-
fix: disable Renovate Dockerfile base-image updates in downstream rep…
…os (#365) ## Summary Downstream repos generated from this template were receiving Renovate PRs (e.g. "Update ubuntu Docker tag") for Docker base images that are only ever meant to be bumped centrally, in `template/Dockerfile.jinja`. This PR adds a `packageRule` to `template/renovate.json.jinja` — the config shipped to downstream projects — that disables Renovate's `dockerfile` manager for the two template-managed base images (`ubuntu` and `ghcr.io/diamondlightsource/ubuntu-devcontainer`), mirroring the existing rules that already disable `pyenv` and template-managed GitHub Actions. The rule is appended to the **end** of the `packageRules` array (not inserted before the existing github-actions rule), since `tests/test_example.py::test_renovate_actions_match_what_is_shipped` hard-indexes `packageRules[1]` as the github-actions rule. ## Originating request From a maintainer comment on [bluesky/scanspec#211](bluesky/scanspec#211): Renovate was opening Docker base-image bump PRs in downstream repos, but those base images are managed centrally by this template — the update should only ever happen here, not downstream. ## Deliberately left alone - **Root `renovate.json`** (this template repo's own Renovate config) was **not** changed — this repo should keep receiving Docker base-image updates itself, since it's the one place those bumps are supposed to land. - `template/Dockerfile.jinja`, the root `Dockerfile`, workflows, and `uv.lock` were not touched. ## Verification Ran locally from the repo root, as CI does: - `uv run --locked tox -e pre-commit` — passed. - `uv run --locked tox -e tests` — `test_renovate_actions_match_what_is_shipped` passes for all 5 parametrized scenarios (no-docker, docker, docker+debug, pypi, sphinx docs). Two pre-existing, unrelated failures were confirmed to reproduce identically on unmodified `main` (a docs-build test blocked by network/proxy restrictions in this sandbox, and a template-version-hash mismatch in a generated doc link) — left untouched as instructed. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --- _Generated by [Claude Code](https://claude.ai/code/session_01J29WGmqiaFAwfavJrqwon7)_
Configuration menu - View commit details
-
Copy full SHA for 909a4b5 - Browse repository at this point
Copy the full SHA 909a4b5View commit details -
chore(deps): update astral-sh/setup-uv action to v10 (#369)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) | action | major | `v9.0.0` → `v10.0.0` | --- ### Release Notes <details> <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary> ### [`v10.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.0): 🌈 Disable automatic caching for sensitive events and new QOL features [Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0) ##### Changes Another breaking release, directly after v9.0.0 but we think the added security justifies that. ##### Extra security by default If you use the default `enable-cache: auto` this will now **DISABLE THE CACHE** to protect against cache poisoning for the following events: - `pull_request_target` - `workflow_run` - `release` You can read the full reasoning in [#​984](https://redirect.github.com/astral-sh/setup-uv/issues/984) ##### `version: latest-known` ```yaml - name: Install the latest version of uv known to setup-uv uses: astral-sh/setup-uv@v10.0.0 with: version: "latest-known" ``` This will now install the latest version with a checksum that is known by this action. The [known `uv` checksums](https://redirect.github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts) are automatically updated but will take a release of this action to take effect. You won't be always using the latest & greatest but you will have an extra level of security. ##### Read python version from `.tool-versions` ```yaml - name: Install uv based on the version defined in .tool-versions and also set python uses: astral-sh/setup-uv@v10.0.0 with: version-file: "pyproject.toml" ``` Will now also set the python version if it is defined in `.tool-versions`. You can read the details [in the docs](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file) ##### 🚨 Breaking changes - Disable automatic caching for sensitive events [@​eifinger](https://redirect.github.com/eifinger) ([#​992](https://redirect.github.com/astral-sh/setup-uv/issues/992)) ##### 🐛 Bug fixes - Reject paths in .tool-versions [@​eifinger](https://redirect.github.com/eifinger) ([#​1007](https://redirect.github.com/astral-sh/setup-uv/issues/1007)) ##### 🚀 Enhancements - Read Python version from .tool-versions [@​eifinger](https://redirect.github.com/eifinger) ([#​996](https://redirect.github.com/astral-sh/setup-uv/issues/996)) - Add latest-known version selector [@​eifinger](https://redirect.github.com/eifinger) ([#​993](https://redirect.github.com/astral-sh/setup-uv/issues/993)) ##### 🧰 Maintenance - Require pull requests for Dependabot rollups [@​eifinger](https://redirect.github.com/eifinger) ([#​1005](https://redirect.github.com/astral-sh/setup-uv/issues/1005)) - ci: pin Alpine container image [@​eifinger](https://redirect.github.com/eifinger) ([#​995](https://redirect.github.com/astral-sh/setup-uv/issues/995)) - chore: update known checksums for 0.12.3 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​991](https://redirect.github.com/astral-sh/setup-uv/issues/991)) - chore: update known checksums for 0.12.2 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​985](https://redirect.github.com/astral-sh/setup-uv/issues/985)) - chore: update known checksums for 0.12.1 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​982](https://redirect.github.com/astral-sh/setup-uv/issues/982)) - chore: update known checksums for 0.12.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​981](https://redirect.github.com/astral-sh/setup-uv/issues/981)) - chore: update known checksums for 0.11.31/0.11.32 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​972](https://redirect.github.com/astral-sh/setup-uv/issues/972)) ##### 📚 Documentation - docs: update version references to v9.0.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​971](https://redirect.github.com/astral-sh/setup-uv/issues/971)) ##### ⬆️ Dependency updates - chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​1013](https://redirect.github.com/astral-sh/setup-uv/issues/1013)) - chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​1004](https://redirect.github.com/astral-sh/setup-uv/issues/1004)) - chore(deps): roll up Dependabot updates [@​eifinger](https://redirect.github.com/eifinger) ([#​994](https://redirect.github.com/astral-sh/setup-uv/issues/994)) - chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#​976](https://redirect.github.com/astral-sh/setup-uv/issues/976)) - chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#​980](https://redirect.github.com/astral-sh/setup-uv/issues/980)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/DiamondLightSource/python-copier-template). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 72fb4e1 - Browse repository at this point
Copy the full SHA 72fb4e1View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff 5.3.0...5.4.0