chore(deps): update dependency jsonschema to v4.18.3 - autoclosed
Metadata
Current evaluation
Dependency update for jsonschema to v4.18.3 was held pending snap file verification for new rust dependencies. The pull request was automatically closed due to inactivity without being merged.
Suggested action: —
No scores available.
Issue body
[](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [jsonschema](https://togithub.com/python-jsonschema/jsonschema) ([changelog](https://togithub.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst)) | `==4.17.3` -> `==4.18.3` | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) | [](https://docs.renovatebot.com/merge-confidence/) |
---
### Release Notes
<details>
<summary>python-jsonschema/jsonschema (jsonschema)</summary>
### [`v4.18.3`](https://togithub.com/python-jsonschema/jsonschema/blob/HEAD/CHANGELOG.rst#v4183)
[Compare Source](https://togithub.com/python-jsonschema/jsonschema/compare/v4.18.2...v4.18.3)
\=======
- Properly preserve `applicable_validators` in extended validators.
Specifically, validators extending early drafts where siblings of `$ref` were ignored will properly ignore siblings in the extended validator.
### [`v4.18.2`](https://togithub.com/python-jsonschema/jsonschema/blob/HEAD/CHANGELOG.rst#v4182)
[Compare Source](https://togithub.com/python-jsonschema/jsonschema/compare/v4.18.1...v4.18.2)
\=======
- Fix an additional regression with the deprecated `jsonschema.RefResolver` and pointer resolution.
### [`v4.18.1`](https://togithub.com/python-jsonschema/jsonschema/blob/HEAD/CHANGELOG.rst#v4181)
[Compare Source](https://togithub.com/python-jsonschema/jsonschema/compare/v4.18.0...v4.18.1)
\=======
- Fix a regression with `jsonschema.RefResolver` based resolution when used in combination with a custom validation dialect (via `jsonschema.validators.create`).
### [`v4.18.0`](https://togithub.com/python-jsonschema/jsonschema/blob/HEAD/CHANGELOG.rst#v4180)
[Compare Source](https://togithub.com/python-jsonschema/jsonschema/compare/v4.17.3...v4.18.0)
\=======
This release majorly rehauls the way in which JSON Schema reference resolution is configured.
It does so in a way that *should* be backwards compatible, preserving old behavior whilst emitting deprecation warnings.
- `jsonschema.RefResolver` is now deprecated in favor of the new `referencing library <https://github.com/python-jsonschema/referencing/>`\_.
`referencing` will begin in beta, but already is more compliant than the existing `$ref` support.
This change is a culmination of a meaningful chunk of work to make `$ref` resolution more flexible and more correct.
Backwards compatibility *should* be preserved for existing code which uses `RefResolver`, though doing so is again now deprecated, and all such use cases should be doable using the new APIs.
Please file issues on the `referencing` tracker if there is functionality missing from it, or here on the `jsonschema` issue tracker if you have issues with existing code not functioning the same, or with figuring out how to change it to use `referencing`.
In particular, this referencing change includes a change concerning *automatic* retrieval of remote references (retrieving `http://foo/bar` automatically within a schema).
This behavior has always been a potential security risk and counter to the recommendations of the JSON Schema specifications; it has survived this long essentially only for backwards compatibility reasons, and now explicitly produces warnings.
The `referencing` library itself will *not* automatically retrieve references if you interact directly with it, so the deprecated behavior is only triggered if you fully rely on the default `$ref` resolution behavior and also include remote references in your schema, which will still be retrieved during the deprecation period (after which they will become an error).
- Support for Python 3.7 has been dropped, as it is nearing end-of-life.
This should not be a "visible" change in the sense that `requires-python` has been updated, so users using 3.7 should still receive `v4.17.3` when installing the library.
- On draft 2019-09, `unevaluatedItems` now properly does *not* consider items to be evaluated by an `additionalItems` schema if `items` is missing from the schema, as the specification says in this case that `additionalItems` must be completely ignored.
- Fix the `date` format checker on Python 3.11 (when format assertion behavior is enabled), where it was too liberal ([#​1076](https://togithub.com/python-jsonschema/jsonschema/issues/1076)).
- Speed up validation of `unevaluatedProperties` ([#​1075](https://togithub.com/python-jsonschema/jsonschema/issues/1075)).
## Deprecations
- `jsonschema.RefResolver` -- see above for details on the replacement
- `jsonschema.RefResolutionError` -- see above for details on the replacement
- relying on automatic resolution of remote references -- see above for details on the replacement
- importing `jsonschema.ErrorTree` -- instead import it via `jsonschema.exceptions.ErrorTree`
- importing `jsonschema.FormatError` -- instead import it via `jsonschema.exceptions.FormatError`
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "every weekend" in timezone Etc/UTC, Automerge - "before 07:00" in timezone Etc/UTC.
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://developer.mend.io/github/canonical/charmcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNi44LjExIiwidXBkYXRlZEluVmVyIjoiMzYuOC4xMSIsInRhcmdldEJyYW5jaCI6Im1haW4ifQ==-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Dependency update for jsonschema to v4.18.3 was held pending snap file verification for new rust dependencies. The pull request was automatically closed due to inactivity without being merged. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Dependency update for jsonschema to v4.18.3 was held for snap file verification due to new rust dependencies and subsequently autoclosed without merging. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Dependency update for jsonschema to v4.18.3 was held pending snap file verification due to new rust dependencies. Renovate subsequently autoclosed the PR, abandoning the update. |
Update history
No update history recorded yet.
Related issues
| Issue | Project | State | Summary | Similarity |
|---|---|---|---|---|
| #1255 chore(deps): update dependency jsonschema to v4.19.0 | charmcraft | merged | Merged automated dependency update upgrading jsonschema from v4.18.4 to v4.19.0. Approved by two reviewers, passed CI checks, and merged with a minimal two-line change. An unrelated failing snap test mentioned in comments did not block the merge. | |
| #1187 chore(deps): update dependency jsonschema-specifications to v2023.7.1 | charmcraft | merged | Merged automated dependency update from Renovate bot. Updated jsonschema-specifications from v2023.6.1 to v2023.7.1. Approved by reviewer, passed CI checks, and merged with minimal changes across two files. | |
| #252 chore(deps): update dependency lint/ruff to ~=0.4.1 - autoclosed | craft-cli | closed | Renovate autoclosed this dependency update for lint/ruff to 0.4.1 without merging. The branch was superseded or became stale, resulting in an automatic closure with no reviewer activity or CI checks. | |
| #5702 build(deps): update dependency jsonschema to v4 (main) | snapcraft | closed | Closed without merging and superseded by PRs #5653 and #5655. The jsonschema v4 update was abandoned, causing Renovate to ignore future 4.x releases for this repository. | |
| #1170 chore(deps): update dependency humanize to v4.7.0 - autoclosed | charmcraft | closed | Automated dependency update to humanize v4.7.0 was autoclosed without merging. Renovate bot automatically closed the pull request, indicating it was superseded or outdated, leaving the change unapplied. | |
| #69 chore(deps): update pnpm/action-setup action to v4.4.0 - autoclosed | craft-actions | closed | Dependency update to pnpm/action-setup v4.4.0 was autoclosed without merging. All CI checks passed, but the bot automatically closed the request, likely due to staleness or disabled automerge configuration. | |
| #5506 build(deps): update dependency jsonschema (main) | snapcraft | closed | Closed and superseded by PRs #5653 and #5655. Following CI failures and rust/cargo compatibility discussions, the maintainer closed the jsonschema update to consolidate changes into the referenced PRs. | |
| #1174 chore(deps): update dependency pytest-cov to v4.1.0 - autoclosed | charmcraft | closed | Automated dependency update for pytest-cov to v4.1.0 was autoclosed by Renovate due to inactivity. No reviews or CI checks ran, and the change was abandoned without merging. | |
| #235 chore(deps): update dependency lint/ruff to v0.2.2 - autoclosed | craft-cli | closed | Automatically closed without merging. The Renovate bot dependency update for lint/ruff to v0.2.2 was autoclosed. No changes were applied to the repository. | |
| #64 chore(deps): update dependency canonical/snapcraft to v8.9.1 (core24-8) - abandoned | snapcraft-rocks | closed | Dependency update for canonical/snapcraft to v8.9.1 was abandoned and superseded by pull request #66. Branch modifications triggered Renovate autoclose, and a maintainer replaced it with a new PR. |