Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 30, 2026

Bumps build from 1.3.0 to 1.4.0.

Release notes

Sourced from build's releases.

1.4.0

  • Add --quiet flag (PR #947)
  • Add option to dump PEP 517 metadata with --metadata (PR #940, PR #943)
  • Support UV environment variable (PR #971)
  • Remove a workaround for 3.14b1 (PR #960)
  • In 3.14 final release, color defaults to True already (PR #962)
  • Pass sp-repo-review (PR #942)
  • In pytest configuration, log_level is better than log_cli_level (PR #950)
  • Split up typing and mypy (PR #944)
  • Use types-colorama (PR #945)
  • In docs, first argument for _has_dependency is a name (PR #970)
  • Fix test failure when flit-core is installed (PR #921)
Changelog

Sourced from build's changelog.

1.4.0 (2026-01-08)

  • Add --quiet flag (:pr:947)
  • Add option to dump PEP 517 metadata with --metadata (:pr:940, :pr:943)
  • Support UV environment variable (:pr:971)
  • Remove a workaround for 3.14b1 (:pr:960)
  • In 3.14 final release, color defaults to True already (:pr:962)
  • Pass sp-repo-review (:pr:942)
  • In pytest configuration, log_level is better than log_cli_level (:pr:950)
  • Split up typing and mypy (:pr:944)
  • Use types-colorama (:pr:945)
  • In docs, first argument for _has_dependency is a name (PR :pr:970)
  • Fix test failure when flit-core is installed (PR :pr:921)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Resolves #947
Resolves #940
Resolves #943
Resolves #971
Resolves #960
Resolves #962
Resolves #942
Resolves #950
Resolves #944
Resolves #945
Resolves #970
Resolves #921
Resolves #972
Resolves #968
Resolves #965
Resolves #961

Bumps [build](https://github.com/pypa/build) from 1.3.0 to 1.4.0.
- [Release notes](https://github.com/pypa/build/releases)
- [Changelog](https://github.com/pypa/build/blob/main/CHANGELOG.rst)
- [Commits](pypa/build@1.3.0...1.4.0)

---
updated-dependencies:
- dependency-name: build
  dependency-version: 1.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jan 30, 2026
@dependabot dependabot bot requested a review from a team as a code owner January 30, 2026 08:54
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jan 30, 2026
@github-actions
Copy link

🤖 Claude Code Review

Code Review Results

Analyzing the pull request diff against the checklist...

Summary

This PR updates the build package from version 1.3.0 to 1.4.0 in the development dependencies. This is a straightforward dependency version bump.


Detailed Review

Code Quality ✅

  • Code follows style guide: This is a simple dependency version change in TOML format. No code style issues.
  • No commented-out code: None present.
  • Meaningful variable names: N/A - dependency declaration only.
  • DRY principle followed: N/A - single dependency version update.
  • Identify Defects: No bugs, logic errors, or security vulnerabilities introduced. The build package update from 1.3.0 to 1.4.0 is a minor version bump that should be backwards compatible.
  • Project memory considerations: The change is appropriately generic and doesn't introduce environment-specific configurations.

Testing ⚠️

  • ⚠️ Unit tests for new functions: N/A - no functional code changes, but CI should verify the new build version works.
  • ⚠️ Integration tests for new endpoints: N/A - no new endpoints.
  • ⚠️ Edge cases covered: N/A - dependency update only.
  • ⚠️ Test coverage > 80%: N/A - no code coverage impact expected.

Note: For dependency updates, the existing CI pipeline should run to verify compatibility.

Documentation ✅

  • Readme updated if needed: Not required - internal development dependency change.
  • API docs updated: Not required - no API changes.
  • Inline comments for complex logic: N/A - TOML dependency declaration.
  • ⚠️ CHANGELOG.md updated: Could not verify if CHANGELOG.md was updated. For dependency bumps in development dependencies, this may not be required, but worth checking if your project tracks all dependency changes.
  • Markdown formatting: N/A - TOML file only in this diff.

Security ✅

  • No hardcoded credentials: None present.
  • Input validation implemented: N/A - dependency declaration only.
  • Proper error handling: N/A - dependency declaration only.
  • No sensitive data in logs: N/A - dependency declaration only.
  • No license files or AQAAAD strings: None present in the diff.

Overall Assessment: ✅ APPROVED

This is a clean, low-risk dependency update for a development tool. The change:

  • Updates build from 1.3.0 to 1.4.0 (minor version bump)
  • Only affects the development dependency group
  • No functional code changes
  • No security concerns

Recommendations:

  1. Verify CI passes: Ensure all CI checks (pylint, tests) pass with the new build version
  2. Consider CHANGELOG: If your project documents all dependency changes, add an entry to CHANGELOG.md (pyproject.toml:36)
  3. Check compatibility: The build 1.4.0 release notes should be reviewed to ensure no breaking changes affect your build process

No blocking issues found. This PR is safe to merge once CI passes.

Automated code review analyzing defects and coding standards

@docktermj docktermj merged commit f562bfe into main Jan 30, 2026
14 checks passed
@docktermj docktermj deleted the dependabot/pip/build-1.4.0 branch January 30, 2026 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant