chore(deps): bump the dependencies group across 1 directory with 11 updates#345
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump the dependencies group across 1 directory with 11 updates#345dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…pdates Bumps the dependencies group with 11 updates in the /src/backend directory: | Package | From | To | | --- | --- | --- | | [bleach](https://github.com/mozilla/bleach) | `4.1.0` | `6.3.0` | | [boto3](https://github.com/boto/boto3) | `1.43.8` | `1.43.9` | | [botocore](https://github.com/boto/botocore) | `1.43.8` | `1.43.9` | | [django](https://github.com/django/django) | `5.2.14` | `6.0.5` | | [django-allauth](https://github.com/sponsors/pennersr) | `65.14.3` | `65.16.1` | | [django-otp](https://github.com/django-otp/django-otp) | `1.3.0` | `1.7.0` | | [importlib-metadata](https://github.com/python/importlib_metadata) | `8.7.1` | `9.0.0` | | [protobuf](https://github.com/protocolbuffers/protobuf) | `6.33.6` | `7.34.1` | | [wrapt](https://github.com/GrahamDumpleton/wrapt) | `1.17.3` | `2.1.2` | | [click](https://github.com/pallets/click) | `8.3.3` | `8.4.0` | | [ty](https://github.com/astral-sh/ty) | `0.0.1a21` | `0.0.37` | Updates `bleach` from 4.1.0 to 6.3.0 - [Changelog](https://github.com/mozilla/bleach/blob/main/CHANGES) - [Commits](mozilla/bleach@v4.1.0...v6.3.0) Updates `boto3` from 1.43.8 to 1.43.9 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.43.8...1.43.9) Updates `botocore` from 1.43.8 to 1.43.9 - [Commits](boto/botocore@1.43.8...1.43.9) Updates `django` from 5.2.14 to 6.0.5 - [Commits](django/django@5.2.14...6.0.5) Updates `django-allauth` from 65.14.3 to 65.16.1 - [Commits](https://github.com/sponsors/pennersr/commits) Updates `django-otp` from 1.3.0 to 1.7.0 - [Changelog](https://github.com/django-otp/django-otp/blob/master/CHANGES.rst) - [Commits](django-otp/django-otp@v1.3.0...v1.7.0) Updates `importlib-metadata` from 8.7.1 to 9.0.0 - [Release notes](https://github.com/python/importlib_metadata/releases) - [Changelog](https://github.com/python/importlib_metadata/blob/main/NEWS.rst) - [Commits](python/importlib_metadata@v8.7.1...v9.0.0) Updates `protobuf` from 6.33.6 to 7.34.1 - [Release notes](https://github.com/protocolbuffers/protobuf/releases) - [Commits](https://github.com/protocolbuffers/protobuf/commits) Updates `wrapt` from 1.17.3 to 2.1.2 - [Release notes](https://github.com/GrahamDumpleton/wrapt/releases) - [Changelog](https://github.com/GrahamDumpleton/wrapt/blob/develop/docs/changes.rst) - [Commits](GrahamDumpleton/wrapt@1.17.3...2.1.2) Updates `click` from 8.3.3 to 8.4.0 - [Release notes](https://github.com/pallets/click/releases) - [Changelog](https://github.com/pallets/click/blob/main/CHANGES.rst) - [Commits](pallets/click@8.3.3...8.4.0) Updates `ty` from 0.0.1a21 to 0.0.37 - [Release notes](https://github.com/astral-sh/ty/releases) - [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md) - [Commits](astral-sh/ty@0.0.1-alpha.21...0.0.37) --- updated-dependencies: - dependency-name: bleach dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: boto3 dependency-version: 1.43.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: botocore dependency-version: 1.43.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: django dependency-version: 6.0.5 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: django-allauth dependency-version: 65.16.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: django-otp dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: importlib-metadata dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: protobuf dependency-version: 7.34.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: wrapt dependency-version: 2.1.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: click dependency-version: 8.4.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: ty dependency-version: 0.0.37 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the dependencies group with 11 updates in the /src/backend directory:
4.1.06.3.01.43.81.43.91.43.81.43.95.2.146.0.565.14.365.16.11.3.01.7.08.7.19.0.06.33.67.34.11.17.32.1.28.3.38.4.00.0.1a210.0.37Updates
bleachfrom 4.1.0 to 6.3.0Changelog
Sourced from bleach's changelog.
... (truncated)
Commits
5546d5dchore: prep for 6.3.0 release88df3ffchore: fix readthedocsd8b2fb4fix: fix wbr handling (#488)55e48cechore: add support for Python 3.14 (#758)a4d6cddchore: drop support for Python 3.9 (#756)172d92fBump actions/setup-python from 5.6.0 to 6.0.0df88612Bump actions/checkout from 4.2.2 to 5.0.0cbcf6b1Bump actions/cache from 4.2.3 to 4.3.0d9aa7efSwitch from dependabot reviewers to CODEOWNERS06f0f76Update setuptools, wheel, and twine for devsUpdates
boto3from 1.43.8 to 1.43.9Commits
6d47260Merge branch 'release-1.43.9'7fb9872Bumping version to 1.43.91881c7fAdd changelog entries from botocore9ff48ecMerge branch 'release-1.43.8' into developUpdates
botocorefrom 1.43.8 to 1.43.9Commits
994b6d7Merge branch 'release-1.43.9'386e9cbBumping version to 1.43.9f1997acUpdate endpoints model964083cUpdate to latest modelsfc709c3Update resource leak test scaling factors and CI Python resolution (#3705)4841c13Merge branch 'release-1.43.8' into developUpdates
djangofrom 5.2.14 to 6.0.5Commits
8f8ad09[6.0.x] Bumped version for 6.0.5 release.44ad76e[6.0.x] Fixed CVE-2026-6907 -- Prevented caching of requests when Vary header...1b0184a[6.0.x] Fixed CVE-2026-35192 -- Ensured Vary header is sent when setting sess...ad8f9e1[6.0.x] Fixed CVE-2026-5766 -- Enforced DATA_UPLOAD_MAX_MEMORY_SIZE in Memory...990ab01[6.0.x] Fixed #37039 -- Removed outdated note from QuerySet.iterator() docs.f0c269f[6.0.x] Fixed typo in stub release notes for 5.2.14.8bcd15b[6.0.x] Fixed #37067 -- Added trailing slash in django_file_prefixes().3cdec64[6.0.x] Refs CVE-2026-25674 -- Clarified role of umask in upload permissions.5dd5c70[6.0.x] Added stub release notes and release date for 6.0.5 and 5.2.14.8ee7341[6.0.x] Refs #373, #34122 -- Removed warning that ForeignObject is an interna...Updates
django-allauthfrom 65.14.3 to 65.16.1Commits
Updates
django-otpfrom 1.3.0 to 1.7.0Changelog
Sourced from django-otp's changelog.
... (truncated)
Commits
fc0d50bVersion 1.7.056e4ce3Refactor test utilities8c4d4c2Update test matrix for Django 6.00ac4ff3Cleanup and changelogb10df0dMake OTPMiddleware async capable. (#185)8121179Raise requires-python to 3.8.38b7ebaVersion 1.6.3b9026d7Correct Missing Spanish Translationsae18ba9Fix #181: misdocumented return type.c9eef89Version 1.6.2Updates
importlib-metadatafrom 8.7.1 to 9.0.0Changelog
Sourced from importlib-metadata's changelog.
Commits
a9f883fFinalize9b0dfdfRaise an exception when no metadata file is found (#532)0f2229cMerge branch 'main' into feature/no-metadata-exception2f4088eRemove news fragments about internal details.0ac2720Add news fragment.a5c2154Finalizee66e226Drop support for EOL Python 3.9 (#530)6027933Add news fragment.b89388aImport os_helper directly.2dcb761Add uniform exclusions for test.support.Updates
protobuffrom 6.33.6 to 7.34.1Release notes
Sourced from protobuf's releases.
... (truncated)
Commits
Updates
wraptfrom 1.17.3 to 2.1.2Release notes
Sourced from wrapt's releases.
Changelog
Sourced from wrapt's changelog.
... (truncated)
Commits
1381ae8Merge branch 'release/2.1.2'26ab4fdUpdate ready for 2.1.2 release.fbdbef4Handle pypy which raises different exception type.87baf75Add tests for deletion of qualname and annotations.b48debfDecided only needed a patch level update,06c698fUpdate release notes for annotation deletion bug.6e6ed87Merge pull request #313 from bysiber/fix/delattr-annotations4fc2c23Add test to call proxy after weakref cleared.9e53a71Add change notes for ReferenceError fix.2cda4e6Merge pull request #312 from bysiber/fix/weakfunctionproxy-expired-instanceUpdates
clickfrom 8.3.3 to 8.4.0Release notes
Sourced from click's releases.
... (truncated)
Changelog
Sourced from click's changelog.
... (truncated)
Commits
41f410fRelease 8.4.0e3e69e3Add type annotations for instance attributes inutils(#3422)3bb230dWIP: FixHelpFormatter.write_usageproducing spurious characters (#3434)63274a7click.get_pager_file: add tests (#1572 followup) (#3405)0551bf5FixHelpFormatter.write_usageproducing spurious charactersfc41aa1Apply class-body annotations toKeepOpenFilefor consistencyb761edaSkip some tests on Windows98302acCheckPAGERusage, color preservation and edge-casesdbdae17Fix documentation1aa2d53Redesigned tests and get_pager_file branching to be more clear and not set colorUpdates
tyfrom 0.0.1a21 to 0.0.37Release notes
Sourced from ty's releases.
... (truncated)
Changelog
Sourced from ty's changelog.
... (truncated)
Commits
f18aed6Bump version to 0.0.37 (#3473)a63e559Bump version to 0.0.36 (#3463)94370d5Update prek dependencies (#3449)bc12d1cBump version to 0.0.35 (#3436)fb34d89Build riscv64 manylinux binary (#3402)05def00Update maturin to v1.13.1 (#3417)569c081Update prek dependencies (#3416)608f8ffUpdate renovate configuration (#3379)518b61dUpdate uraimo/run-on-arch-action action to v3.1.0 (#3405)5542959Update pre-commit hook astral-sh/ruff-pre-commit to v0.15.12 (#3404)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions