Skip to content

Bump coverage from 7.15.3 to 7.15.4 - #140

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/coverage-7.15.4
Aug 27, 2026
Merged

Bump coverage from 7.15.3 to 7.15.4#140
github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/coverage-7.15.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 27, 2026

Copy link
Copy Markdown
Contributor

Bumps coverage from 7.15.3 to 7.15.4.

Release notes

Sourced from coverage's releases.

7.15.4

Version 7.15.4 — 2026-08-06

  • Fix: in the HTML report, a source file name containing a double quote (legal on POSIX) wasn’t escaped where it’s dropped into the href of the index and prev/next links, so it could close the attribute early and inject markup. Page URLs are now escaped. Thanks, Rajath Mohare.
  • Fix: the LCOV report wrote file names and other fields into its line-oriented records without neutralizing control characters. A measured file whose name contained a newline (legal on POSIX) could forge extra records, inflating the coverage seen by tools that read the report. Control characters in a field are now replaced. Thanks, Rajath Mohare.
  • Wheels are now provided for Python 3.15.

➡️  PyPI page: coverage 7.15.4. :arrow_right:  To install: python3 -m pip install coverage==7.15.4

Changelog

Sourced from coverage's changelog.

Version 7.15.4 — 2026-08-06

  • Fix: in the HTML report, a source file name containing a double quote (legal on POSIX) wasn't escaped where it's dropped into the href of the index and prev/next links, so it could close the attribute early and inject markup. Page URLs are now escaped. Thanks, Rajath Mohare <pull 2227_>_.

  • Fix: the LCOV report wrote file names and other fields into its line-oriented records without neutralizing control characters. A measured file whose name contained a newline (legal on POSIX) could forge extra records, inflating the coverage seen by tools that read the report. Control characters in a field are now replaced. Thanks, Rajath Mohare <pull 2226_>_.

  • Wheels are now provided for Python 3.15.

.. _pull 2226: coveragepy/coveragepy#2226 .. _pull 2227: coveragepy/coveragepy#2227

.. _changes_7-15-3:

Commits
  • 4c0e7ff docs: sample HTML for 7.15.4
  • db4cc32 docs: prep for 7.15.4
  • c33085c style: start gradual move to ruff 0.16
  • 53a0fd5 fix: neutralize control characters in lcov report fields (#2226)
  • b64d53d build: make 3.15 wheels
  • 53792ab build: show the python version for kits
  • f6b03c7 chore: make upgrade_one package=cibuildwheel
  • d9b660a chore: make upgrade
  • b128a31 docs: oops, move this entry to the correct place
  • a7a2c15 fix: escape filename urls in html report href attributes (#2227)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [coverage](https://github.com/coveragepy/coveragepy) from 7.15.3 to 7.15.4.
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.15.3...7.15.4)

---
updated-dependencies:
- dependency-name: coverage
  dependency-version: 7.15.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner August 27, 2026 15:32
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 27, 2026

@senzingdevops senzingdevops left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated: approving this pull request because it includes a patch update

@github-actions
github-actions Bot enabled auto-merge (squash) August 27, 2026 15:33
@github-actions

Copy link
Copy Markdown

🤖 Claude Code Review

PR Code Review

Summary: This PR bumps the coverage package pin from 7.15.3 to 7.15.4 for Python > 3.11, in two locations in pyproject.toml (the development and test optional-dependency groups).

Code Quality

  • Style conventions — Change is a version string bump, consistent with existing formatting (pyproject.toml:38, pyproject.toml:87).
  • No commented-out code
  • Meaningful variable names — N/A, no code changed.
  • DRY principle — Both occurrences of the pin were updated consistently, so the development and test groups stay in sync (this repo doesn't centralize the version, but both call sites were kept in agreement).
  • Defects — No logic changes; a pure dependency version bump. No bugs, edge cases, or security issues introduced.
  • CLAUDE.md considerations — Nothing in the diff conflicts with .claude/CLAUDE.md. The file itself remains general-purpose (no local-machine-specific content was added).

Testing

  • ✅ N/A — No functional code changed; nothing new to unit/integration test. Existing CI will validate the pin resolves and installs correctly across Python 3.10–3.13.
  • ⚠️ Not verifiable in this review without network access: whether coverage==7.15.4 is actually a published, valid version on PyPI. Recommend confirming CI passes (dependency install + test run) before merge.

Documentation

  • ✅ README — Not applicable to a dependency bump.
  • ✅ API docs — Not applicable.
  • ✅ Inline comments — Not applicable.
  • ⚠️ CHANGELOG.md — Not updated. Check repo convention: many projects treat routine dependency bumps (especially bot-generated ones, per the recent commit history showing Bump coverage from 7.15.2 to 7.15.3 (#139)) as exempt from CHANGELOG entries. Given this appears to be an automated dependency-bump PR (consistent with prior commits like 1357899, 58036b9, 49e097b), this is likely fine and expected.

Security

  • ✅ No hardcoded credentials
  • ✅ No input validation concerns — N/A for this change
  • ✅ No error handling concerns — N/A
  • ✅ No sensitive data in logs
  • ✅ No .lic files or AQAAAD-prefixed strings present in the diff

Overall

Approve. This is a minimal, low-risk, single-purpose dependency version bump consistent with the repo's existing automated update pattern. No blocking issues found.

Automated code review analyzing defects and coding standards

@github-actions
github-actions Bot merged commit 8964bce into main Aug 27, 2026
12 checks passed
@github-actions
github-actions Bot deleted the dependabot/pip/coverage-7.15.4 branch August 27, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants