Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: DiamondLightSource/python-copier-template
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 5.3.0
Choose a base ref
...
head repository: DiamondLightSource/python-copier-template
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 5.4.0
Choose a head ref
  • 7 commits
  • 10 files changed
  • 3 contributors

Commits on Jul 22, 2026

  1. chore(deps): update astral-sh/setup-uv action to v9 (#363)

    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
    action | major | `v8.3.2` → `v9.0.0` |
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>
    
    ###
    [`v9.0.0`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.2...v9.0.0)
    
    [Compare
    Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.2...v9.0.0)
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (UTC)
    
    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Disabled by config. Please merge this manually once you
    are satisfied.
    
    ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuNCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jul 22, 2026
    Configuration menu
    Copy the full SHA
    a0cac98 View commit details
    Browse the repository at this point in the history

Commits on Jul 27, 2026

  1. chore(deps): lock file maintenance (#366)

    This PR contains the following updates:
    
    | Update | Change |
    |---|---|
    | lockFileMaintenance | All locks refreshed |
    
    🔧 This Pull Request updates lock files to use the latest dependency
    versions.
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (UTC)
    
    - Branch creation
      - "before 4am on monday"
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
    rebase/retry checkbox.
    
    👻 **Immortal**: This PR will be recreated if closed unmerged. Get
    [config
    help](https://redirect.github.com/renovatebot/renovate/discussions) if
    that's undesired.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Jul 27, 2026
    Configuration menu
    Copy the full SHA
    b8caef5 View commit details
    Browse the repository at this point in the history

Commits on Jul 29, 2026

  1. fix: copier should not be a dev dependency (#364)

    ## Summary
    
    `copier` should not be installed as a dev dependency of *generated*
    projects — it should be invoked via `uvx copier` instead. This PR
    removes it from the template's dev dependency group and updates the docs
    to recommend `uvx copier update`.
    
    - `template/pyproject.toml.jinja`: removed `"copier"` from the `dev`
    dependency-group list.
    - `docs/how-to/update-template.md`: changed the two bare `copier update`
    invocations to `uvx copier update`.
    - `.github/CONTRIBUTING.md`: changed `copier update
    --vcs-ref=<branch_name>` to `uvx copier update --vcs-ref=<branch_name>`.
    
    ## Deliberately left untouched
    
    - Root `pyproject.toml` — this template repo's own test suite imports
    `copier` (`from copier import run_copy`), so it legitimately needs
    `copier` as a dev dependency here.
    - `tests/test_example.py` — its bare `copier update` call runs in this
    repo's own dev environment, not inside a generated project.
    - Tutorial docs (`docs/tutorials/adopt-existing.md`,
    `docs/tutorials/create-new.md`) and prose/comment mentions of "copier" —
    already correct or out of scope.
    
    ## Testing
    
    - `uv run --locked tox -e pre-commit` — passed.
    - `uv run --locked tox -e tests` — 5 pre-existing failures unrelated to
    this change (sandbox network proxy blocks a docs-build version-switcher
    request to `diamondlightsource.github.io`, and one test has a
    version-string mismatch from running off an untagged commit rather than
    a release tag). No failures caused by this change;
    `test_example_repo_updates`'s actual file-content diff was clean aside
    from that unrelated version string.
    
    Closes #343
    
    
    ---
    _Generated by [Claude
    Code](https://claude.ai/code/session_01VuHBQ1iEZogr1q7VBjA2iL)_
    
    Co-authored-by: Claude <noreply@anthropic.com>
    coretl and claude authored Jul 29, 2026
    Configuration menu
    Copy the full SHA
    718a485 View commit details
    Browse the repository at this point in the history

Commits on Aug 3, 2026

  1. chore(deps): lock file maintenance (#367)

    This PR contains the following updates:
    
    | Update | Change |
    |---|---|
    | lockFileMaintenance | All locks refreshed |
    
    🔧 This Pull Request updates lock files to use the latest dependency
    versions.
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (UTC)
    
    - Branch creation
      - "before 4am on monday"
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
    rebase/retry checkbox.
    
    👻 **Immortal**: This PR will be recreated if closed unmerged. Get
    [config
    help](https://redirect.github.com/renovatebot/renovate/discussions) if
    that's undesired.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Aug 3, 2026
    Configuration menu
    Copy the full SHA
    4ee6984 View commit details
    Browse the repository at this point in the history

Commits on Aug 10, 2026

  1. chore(deps): lock file maintenance (#368)

    This PR contains the following updates:
    
    | Update | Change |
    |---|---|
    | lockFileMaintenance | All locks refreshed |
    
    🔧 This Pull Request updates lock files to use the latest dependency
    versions.
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (UTC)
    
    - Branch creation
      - "before 4am on monday"
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Enabled.
    
    ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
    rebase/retry checkbox.
    
    👻 **Immortal**: This PR will be recreated if closed unmerged. Get
    [config
    help](https://redirect.github.com/renovatebot/renovate/discussions) if
    that's undesired.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMi4wIiwidXBkYXRlZEluVmVyIjoiNDQuMTIuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Aug 10, 2026
    Configuration menu
    Copy the full SHA
    f39321a View commit details
    Browse the repository at this point in the history

Commits on Aug 14, 2026

  1. fix: disable Renovate Dockerfile base-image updates in downstream rep…

    …os (#365)
    
    ## Summary
    
    Downstream repos generated from this template were receiving Renovate
    PRs (e.g. "Update ubuntu Docker tag") for Docker base images that are
    only ever meant to be bumped centrally, in `template/Dockerfile.jinja`.
    This PR adds a `packageRule` to `template/renovate.json.jinja` — the
    config shipped to downstream projects — that disables Renovate's
    `dockerfile` manager for the two template-managed base images (`ubuntu`
    and `ghcr.io/diamondlightsource/ubuntu-devcontainer`), mirroring the
    existing rules that already disable `pyenv` and template-managed GitHub
    Actions.
    
    The rule is appended to the **end** of the `packageRules` array (not
    inserted before the existing github-actions rule), since
    `tests/test_example.py::test_renovate_actions_match_what_is_shipped`
    hard-indexes `packageRules[1]` as the github-actions rule.
    
    ## Originating request
    
    From a maintainer comment on
    [bluesky/scanspec#211](bluesky/scanspec#211):
    Renovate was opening Docker base-image bump PRs in downstream repos, but
    those base images are managed centrally by this template — the update
    should only ever happen here, not downstream.
    
    ## Deliberately left alone
    
    - **Root `renovate.json`** (this template repo's own Renovate config)
    was **not** changed — this repo should keep receiving Docker base-image
    updates itself, since it's the one place those bumps are supposed to
    land.
    - `template/Dockerfile.jinja`, the root `Dockerfile`, workflows, and
    `uv.lock` were not touched.
    
    ## Verification
    
    Ran locally from the repo root, as CI does:
    - `uv run --locked tox -e pre-commit` — passed.
    - `uv run --locked tox -e tests` —
    `test_renovate_actions_match_what_is_shipped` passes for all 5
    parametrized scenarios (no-docker, docker, docker+debug, pypi, sphinx
    docs). Two pre-existing, unrelated failures were confirmed to reproduce
    identically on unmodified `main` (a docs-build test blocked by
    network/proxy restrictions in this sandbox, and a template-version-hash
    mismatch in a generated doc link) — left untouched as instructed.
    
    🤖 Generated with [Claude Code](https://claude.com/claude-code)
    
    ---
    _Generated by [Claude
    Code](https://claude.ai/code/session_01J29WGmqiaFAwfavJrqwon7)_
    coretl authored Aug 14, 2026
    Configuration menu
    Copy the full SHA
    909a4b5 View commit details
    Browse the repository at this point in the history
  2. chore(deps): update astral-sh/setup-uv action to v10 (#369)

    This PR contains the following updates:
    
    | Package | Type | Update | Change |
    |---|---|---|---|
    | [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
    action | major | `v9.0.0` → `v10.0.0` |
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>
    
    ###
    [`v10.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v10.0.0):
    🌈 Disable automatic caching for sensitive events and new QOL features
    
    [Compare
    Source](https://redirect.github.com/astral-sh/setup-uv/compare/v9.0.0...v10.0.0)
    
    ##### Changes
    
    Another breaking release, directly after v9.0.0 but we think the added
    security justifies that.
    
    ##### Extra security by default
    
    If you use the default `enable-cache: auto` this will now **DISABLE THE
    CACHE** to protect against cache poisoning for the following events:
    
    - `pull_request_target`
    - `workflow_run`
    - `release`
    
    You can read the full reasoning in
    [#&#8203;984](https://redirect.github.com/astral-sh/setup-uv/issues/984)
    
    ##### `version: latest-known`
    
    ```yaml
    - name: Install the latest version of uv known to setup-uv
      uses: astral-sh/setup-uv@v10.0.0
      with:
        version: "latest-known"
    ```
    
    This will now install the latest version with a checksum that is known
    by this action. The [known `uv`
    checksums](https://redirect.github.com/astral-sh/setup-uv/blob/4f6036f71cec78afb113b323f220c9185d983c12/src/download/checksum/known-checksums.ts)
    are automatically updated but will take a release of this action to take
    effect. You won't be always using the latest & greatest but you will
    have an extra level of security.
    
    ##### Read python version from `.tool-versions`
    
    ```yaml
    - name: Install uv based on the version defined in .tool-versions and also set python
      uses: astral-sh/setup-uv@v10.0.0
      with:
        version-file: "pyproject.toml"
    ```
    
    Will now also set the python version if it is defined in
    `.tool-versions`. You can read the details [in the
    docs](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/advanced-version-configuration.md#install-a-version-defined-in-a-requirements-or-config-file)
    
    ##### 🚨 Breaking changes
    
    - Disable automatic caching for sensitive events
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;992](https://redirect.github.com/astral-sh/setup-uv/issues/992))
    
    ##### 🐛 Bug fixes
    
    - Reject paths in .tool-versions
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;1007](https://redirect.github.com/astral-sh/setup-uv/issues/1007))
    
    ##### 🚀 Enhancements
    
    - Read Python version from .tool-versions
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;996](https://redirect.github.com/astral-sh/setup-uv/issues/996))
    - Add latest-known version selector
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;993](https://redirect.github.com/astral-sh/setup-uv/issues/993))
    
    ##### 🧰 Maintenance
    
    - Require pull requests for Dependabot rollups
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;1005](https://redirect.github.com/astral-sh/setup-uv/issues/1005))
    - ci: pin Alpine container image
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;995](https://redirect.github.com/astral-sh/setup-uv/issues/995))
    - chore: update known checksums for 0.12.3
    @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
    ([#&#8203;991](https://redirect.github.com/astral-sh/setup-uv/issues/991))
    - chore: update known checksums for 0.12.2
    @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
    ([#&#8203;985](https://redirect.github.com/astral-sh/setup-uv/issues/985))
    - chore: update known checksums for 0.12.1
    @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
    ([#&#8203;982](https://redirect.github.com/astral-sh/setup-uv/issues/982))
    - chore: update known checksums for 0.12.0
    @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
    ([#&#8203;981](https://redirect.github.com/astral-sh/setup-uv/issues/981))
    - chore: update known checksums for 0.11.31/0.11.32
    @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
    ([#&#8203;972](https://redirect.github.com/astral-sh/setup-uv/issues/972))
    
    ##### 📚 Documentation
    
    - docs: update version references to v9.0.0
    @&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
    ([#&#8203;971](https://redirect.github.com/astral-sh/setup-uv/issues/971))
    
    ##### ⬆️ Dependency updates
    
    - chore(deps): roll up Dependabot updates
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;1013](https://redirect.github.com/astral-sh/setup-uv/issues/1013))
    - chore(deps): roll up Dependabot updates
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;1004](https://redirect.github.com/astral-sh/setup-uv/issues/1004))
    - chore(deps): roll up Dependabot updates
    [@&#8203;eifinger](https://redirect.github.com/eifinger)
    ([#&#8203;994](https://redirect.github.com/astral-sh/setup-uv/issues/994))
    - chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0
    @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
    ([#&#8203;976](https://redirect.github.com/astral-sh/setup-uv/issues/976))
    - chore(deps): bump actions/checkout from 7.0.0 to 7.0.1
    @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
    ([#&#8203;980](https://redirect.github.com/astral-sh/setup-uv/issues/980))
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (UTC)
    
    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Disabled by config. Please merge this manually once you
    are satisfied.
    
    ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/DiamondLightSource/python-copier-template).
    
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuMjQuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Aug 14, 2026
    Configuration menu
    Copy the full SHA
    72fb4e1 View commit details
    Browse the repository at this point in the history
Loading