Skip to content

chore(deps): bump the python-dependencies group across 1 directory with 4 updates - #25

Merged
ArturSepp merged 2 commits into
mainfrom
dependabot/uv/python-dependencies-e59c1747de
Oct 7, 2026
Merged

ArturSepp merged 2 commits into
mainfrom
dependabot/uv/python-dependencies-e59c1747de

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 4 updates in the / directory: numba, statsmodels, qis and ruff.

Updates numba from 0.67.0 to 0.68.0

Updates statsmodels from 0.14.6 to 0.15.0

Release notes

Sourced from statsmodels's releases.

Release 0.15.0

The statsmodels developers are happy to announce the release of 0.15.0. 358 issues were closed in this release and 655 pull requests were merged. Major new features include:

  • Standardized on rng for controlling randomness across the package (SPEC 007), replacing seed/random_state
  • Functions with variable-length tuple returns now return documented NamedTuple results instead
  • A new abstracted formula engine that supports both patsy and formulaic as the backend
  • Support for Polars DataFrames and Series as model input
  • Switched the build backend from setuptools to meson-python
  • New robust estimators: CovDetMCD, CovDetS, CovDetMM, and RLMDetSMM
  • New tests: Diebold-Mariano, Pesaran-Timmermann, Jonckheere-Terpstra, Leybourne-McCabe, and a delete-k block jackknife estimator
  • The Hamilton filter, local false discovery rate correction, and an L1-penalized GLM solver
  • HurdleCountModel gained fit_regularized, and MICEData is now iterable

This release also raises the minimum supported versions of NumPy, SciPy, and pandas, and tightens input validation for many string-valued options across the package (invalid values that previously failed silently or with a confusing error now raise a clear ValueError). A handful of long-standing bugs in seldom-exercised code paths were also corrected as part of a systematic coverage audit this cycle, some of which change numerical output for affected models. See the release notes for the complete list of enhancements, breaking changes, and bug fixes.

Commits
  • 278ff99 Merge pull request #10211 from bashtage/update-release-note
  • ab3f3bc DOC: Final release note
  • 9307ef1 Merge pull request #8712 from bdpedigo/nobs-style
  • 463e5c5 Merge pull request #10210 from Panzerkampfwagen-del/mice-data-iterable
  • cc734d8 Merge branch 'main' into mice-data-iterable
  • 2912b84 Merge pull request #10209 from Panzerkampfwagen-del/var-df-model-docstring
  • 279b9f4 ENH: make MICEData iterable, yielding successive imputed datasets
  • ce7f2c0 DOC: clarify VARResults.df_model counts parameters per equation
  • d1e1875 Merge pull request #10205 from bashtage/fix-hurdle-and-l1-cov
  • bb385fb Merge pull request #10208 from bashtage/update-release-note
  • Additional commits viewable in compare view

Updates qis from 5.12.0 to 5.33.2

Release notes

Sourced from qis's releases.

qis 5.30.3

What's Changed

New Contributors

Full Changelog: ArturSepp/QuantInvestStrats@v5.30.2...v5.30.3

qis 5.30.0

What's Changed

Full Changelog: ArturSepp/QuantInvestStrats@v5.23.0...v5.30.0

qis 5.22.0

What's Changed

... (truncated)

Changelog

Sourced from qis's changelog.

[5.33.2] - 2026-10-01

Changed

  • Make the legacy PyBloqs fallback in strategy_benchmark_factsheet_pybloqs.py delegate to the canonical implementation instead of keeping a second, identical copy (#136). The signature, report output, warnings and exceptions are unchanged.

Fixed

  • Lock tornado 6.5.10 (was 6.5.8). tornado is a transitive dependency of the Jupyter packages in the lockfile; the published package's requirements do not change. Dependabot now opens security-update pull requests for the uv lockfile, with routine version updates suppressed.

[5.33.1] - 2026-09-30

Fixed

  • Require Numba 0.64 or newer: 0.63 fails to compile the EWM array kernel with the supported NumPy 2 floor, breaking the Python 3.10 minimum-dependency test run.
  • Make compute_ewm, compute_ewm_vol, the related shared-decay estimators, and the covariance and beta EWM kernels reject non-finite spans, spans below one, and decay values outside [0, 1) before recursion. Per-column mean/volatility arrays now reject the complete request when any entry is invalid, while span precedence and the span=1 pass-through remain unchanged.
  • Make long_short_to_relative_nav compute the long and short legs by role instead of using Series names as lookup keys. Absent, duplicate, and distinct names now produce the same relative NAV values and neutral result name.
  • Make compute_turnover() and delegated PortfolioData.get_turnover() reject negative or infinite aligned unit notionals and infinite volatility inputs before calculation, while preserving nullable missing values and zero-denominator warnings.

Documentation

  • Write the annualisation factor as $\mathrm{af}$, the name of the code's af argument, instead of $\mathrm{AN}$ in every handbook chapter, packaged note, docstring, worked example and handbook figure footer. The notation chapter and the documentation standard define the new symbol; functions that name the argument annualization_factor keep that name. No signature or computed value changes.
  • Map the convexity-premium chapter to Sepp and Kastenholz (2026), accepted by the Journal of Investment Management: tables of the paper's notation, results and exhibits against qis, and the settings that reproduce its monthly analysis. Add the smart-diversifier definition, a coverage-floor section with the linear Bear-regime loss identity and an executed stacked- portfolio example that feeds qis.plot_overlay_allocation_frontier, and limitations on the diagonal residuals of the mixture covariance and on the two EWMA clocks.
  • Name the paper's result in the docstrings of qis.regimes and qis.portfolio.smart_diversification. SmartDiversificationReport and create_overlay_portfolio_curve state that levered mixes are financed at a zero rate and need excess-of-cash navs; plot_overlay_allocation_frontier states that its points are stacked portfolios; compute_overlay_blend_frontier states that its blend is funded with the benchmark on its null; compute_regime_ewm_betas states which clock its span counts. Remove two

... (truncated)

Commits
  • 2aca91e release: prepare qis 5.33.2 (#137)
  • b168044 fix: patch locked tornado and enable uv security updates
  • 7b5ed6a refactor: share PyBloqs fallback construction (#136)
  • f568c20 release: prepare qis 5.33.1 (#135)
  • f1bc5c2 fix: update locked urllib3 to 2.8.0
  • ab9399e docs: write annualisation as af and map the handbook to Sepp and Kastenholz (...
  • 34beb4e fix: validate turnover input domains (#133)
  • 93d104b fix: ignore names in long-short NAVs (#132)
  • 590dfd1 Merge remote-tracking branch 'origin/main'
  • 01d4031 feat: add sample regime covariance and allocation frontier for 5.33.0
  • Additional commits viewable in compare view

Updates ruff from 0.16.9 to 0.16.10

Release notes

Sourced from ruff's releases.

0.16.10

Release Notes

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Install ruff 0.16.10

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.ps1 | iex"

Download ruff 0.16.10

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.10

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Commits
  • 3265ed1 Bump version to 0.16.10 (#29055)
  • e786964 Authorize shared PR security-review workflow to publish findings (#29052)
  • a81291e [ty] Defer uv workspace discovery until after project configuration (#28525)
  • b6a74d2 [ty] Refresh uv project metadata when uv files change (#28529)
  • 41d30df Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)
  • 317e0a3 [ty] Bound nested callable signature display (#29049)
  • 8546752 [ty] Fix member lookup on union-bounded type variables (#29018)
  • 56180bc [ty] Specialize instance members once (#29043)
  • aa9a1ff [ty] Avoid stale I/O diagnostics when closing deleted files (#28988)
  • 2d25346 [ty] Improve unresolved-import documentation (#29039)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 4 updates

Bumps the python-dependencies group with 4 updates in the / directory: [numba](https://numba.pydata.org), [statsmodels](https://github.com/statsmodels/statsmodels), [qis](https://github.com/ArturSepp/QuantInvestStrats) and [ruff](https://github.com/astral-sh/ruff).


Updates `numba` from 0.67.0 to 0.68.0

Updates `statsmodels` from 0.14.6 to 0.15.0
- [Release notes](https://github.com/statsmodels/statsmodels/releases)
- [Changelog](https://github.com/statsmodels/statsmodels/blob/main/CHANGES.md)
- [Commits](statsmodels/statsmodels@v0.14.6...v0.15.0)

Updates `qis` from 5.12.0 to 5.33.2
- [Release notes](https://github.com/ArturSepp/QuantInvestStrats/releases)
- [Changelog](https://github.com/ArturSepp/QuantInvestStrats/blob/main/CHANGELOG.md)
- [Commits](ArturSepp/QuantInvestStrats@v5.12.0...v5.33.2)

Updates `ruff` from 0.16.9 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.9...0.16.10)

---
updated-dependencies:
- dependency-name: numba
  dependency-version: 0.68.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: statsmodels
  dependency-version: 0.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: qis
  dependency-version: 5.33.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 5, 2026
@ArturSepp
ArturSepp merged commit 82006e5 into main Oct 7, 2026
19 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/python-dependencies-e59c1747de branch October 7, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant