Bump the production-updates group across 1 directory with 7 updates #513
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the production-updates group with 7 updates in the / directory:
4.2.16
4.2.18
1.35.68
1.36.2
4.67.0
4.67.1
0.0.55
0.0.56
7.6.7
7.6.10
8.29.0
8.31.0
75.6.0
75.8.0
Updates
django
from 4.2.16 to 4.2.18Commits
a7b0e50
[4.2.x] Bumped version for 4.2.18 release.ad866a1
[4.2.x] Fixed CVE-2024-56374 -- Mitigated potential DoS in IPv6 validation.b0d309c
[4.2.x] Added stub release notes and release date for 4.2.18.39cf3c6
[4.2.x] Cleaned up CVE-2024-53907 and CVE-2024-53908 security archive descrip...0ff19d1
[4.2.x] Added CVE-2024-53907 and CVE-2024-53908 to security archive.6c4fc7d
[4.2.x] Post-release version bump.1f0356f
[4.2.x] Bumped version for 4.2.17 release.7376bcb
[4.2.x] Fixed CVE-2024-53908 -- Prevented SQL injections in direct HasKeyLook...790eb05
[4.2.x] Fixed CVE-2024-53907 -- Mitigated potential DoS in strip_tags().f663277
[4.2.x] Refs CVE-2024-11168 -- Updated vendored _urlsplit() to properly valid...Updates
boto3
from 1.35.68 to 1.36.2Commits
2d89f4d
Merge branch 'release-1.36.2'3632dae
Bumping version to 1.36.2f47c6aa
Add changelog entries from botocore9613882
Merge branch 'release-1.36.1'1753747
Merge branch 'release-1.36.1' into developb0198d1
Bumping version to 1.36.1dd793dc
Add changelog entries from botocoree2b2df5
Merge branch 'release-1.36.0'2f9e01d
Merge branch 'release-1.36.0' into develop80855f0
Bumping version to 1.36.0Updates
tqdm
from 4.67.0 to 4.67.1Release notes
Sourced from tqdm's releases.
Commits
0ed5d7f
bump version, merge pull request #1629 from tqdm/fix-guia2d5f1c
tests: fix codecov rate limitcac7150
tests: bump pytest-asyncio6338f62
deps: fix pybuild342b15e
tests: sync depsc66458d
gui: fix matplotlibUpdates
atproto
from 0.0.55 to 0.0.56Release notes
Sourced from atproto's releases.
Changelog
Sourced from atproto's changelog.
Commits
02f54e2
Fix generating and uploading attestations to PyPI (#486)0f0ea2a
Update lexicons fetched from ed22362 committed 2024-12-05T11:45:28Z (#485)edd7b03
Update lexicons fetched from c72145d committed 2024-11-29T18:00:48Z (#481)3f61605
Add ability to send aspect ratio with send_image and send_images (#480)e011bb4
Fix link to API docs for rate-limits in atproto_client/auth.md (#464)8aafc9a
Update lexicons fetched from a3ce23c committed 2024-11-23T02:36:55Z (#458)3f4c9c2
Update lexicons fetched from 2e7aa21 committed 2024-11-21T17:40:45Z (#452)2116fcb
Fixclone()
andwith_...()
methods forAsyncClient
(#457)d030829
Update lexicons fetched from a4b528e committed 2024-11-18T13:36:39Z (#442)b38b194
Fix typo in item ofSessionEvent
:'creat'
->'create'
(#439)Updates
coverage
from 7.6.7 to 7.6.10Changelog
Sourced from coverage's changelog.
... (truncated)
Commits
f0dcf65
docs: sample HTML for 7.6.100f26f35
docs: prep for 7.6.1081c5e43
docs: rewrite the subprocess page878410c
chore: make doc_upgradef1d320d
chore: make upgrade67f1440
debug: this condition is never true. really?c85eaba
fix: multi-line statements no longer confuse branch target descriptions. #187...73e58fa
refactor: clarify the code that fixes with-statement exitse16c9cc
typo: backslask865fd7f
chore: bump the action-dependencies group with 4 updates (#1909)Updates
ipython
from 8.29.0 to 8.31.0Commits
22d6a1c
release 8.31.0d1a77be
Backport PR #14626 on branch 8.x (whatsnew 8.31) (#14628)3850bad
Backport PR #14626: whatsnew 8.31c696eef
Backport PR #14601 on branch 8.x (Deprecate inputtransformer since 7.0) (#14603)028f9b3
Backport PR #14601: Deprecate inputtransformer since 7.086a74d8
Bump codecov/codecov-action from 4 to 5 in the actions group (#14593)9cdf92d
Fix completion tuple (#14594)1078df7
types hintsce148f2
fix IPCompleter inside tuples/arrays when jedi is disabled9b18d6c
Fix typo in whatsnew. (#14599)Updates
setuptools
from 75.6.0 to 75.8.0Changelog
Sourced from setuptools's changelog.
Commits
5c9d980
Bump version: 75.7.0 → 75.8.072c4222
Avoid using Any in function1c61d47
Add news fragments for PEP 643f285d01
Implement PEP 643 (Dynamic
field for core metadata) (#4698)a50f6e2
Fix _static.Dict.ior for Python 3.8b055895
Add extra tests for static/dynamic metadata770b4fc
Remove test workaround for unmarked static values from pyproject.toml8b22d73
Mark values from pyproject.toml as staticf699fd8
Fix spelling error8b4c8a3
Add tests for static 'attr' directiveDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions