chore(deps): bump the python-dependencies group with 29 updates#668
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): bump the python-dependencies group with 29 updates#668dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the python-dependencies group with 29 updates: | Package | From | To | | --- | --- | --- | | [bleach](https://github.com/mozilla/bleach) | `6.1.0` | `6.3.0` | | [boto3](https://github.com/boto/boto3) | `1.34.76` | `1.43.6` | | [django-storages](https://github.com/jschneier/django-storages) | `1.14.2` | `1.14.6` | | [pillow](https://github.com/python-pillow/Pillow) | `12.1.1` | `12.2.0` | | [django](https://github.com/django/django) | `5.2.12` | `5.2.14` | | [djangorestframework](https://github.com/encode/django-rest-framework) | `3.16.1` | `3.17.1` | | [mypy](https://github.com/python/mypy) | `1.18.2` | `1.19.1` | | [djangorestframework-stubs](https://github.com/typeddjango/djangorestframework-stubs) | `3.16.8` | `3.16.9` | | [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.80.0` | | [typos](https://github.com/crate-ci/typos) | `1.44.0` | `1.46.1` | | [pulumi-aws](https://github.com/pulumi/pulumi-aws) | `6.83.2` | `6.83.3` | | [types-python-dateutil](https://github.com/python/typeshed) | `2.9.0.20260305` | `2.9.0.20260508` | | [types-markdown](https://github.com/python/typeshed) | `3.10.2.20260211` | `3.10.2.20260508` | | [types-pygments](https://github.com/python/typeshed) | `2.19.0.20251121` | `2.20.0.20260508` | | [types-psycopg2](https://github.com/python/typeshed) | `2.9.21.20260223` | `2.9.21.20260509` | | [types-pycurl](https://github.com/python/typeshed) | `7.45.7.20251101` | `7.46.0.20260509` | | [types-six](https://github.com/python/typeshed) | `1.17.0.20251009` | `1.17.0.20260408` | | [social-auth-app-django](https://github.com/python-social-auth/social-app-django) | `5.6.0` | `5.9.0` | | [django-environ](https://github.com/joke2k/django-environ) | `0.11.2` | `0.13.0` | | [python-dateutil](https://github.com/dateutil/dateutil) | `2.9.0` | `2.9.0.post0` | | [django-htmx](https://github.com/adamchainz/django-htmx) | `1.17.3` | `1.27.0` | | [django-markdownify](https://github.com/erwinmatijsen/django-markdownify) | `0.9.3` | `0.9.6` | | [model-bakery](https://github.com/model-bakers/model_bakery) | `1.17.0` | `1.23.4` | | [mkdocs-material](https://github.com/squidfunk/mkdocs-material) | `9.7.4` | `9.7.6` | | [mysqlclient](https://github.com/PyMySQL/mysqlclient) | `2.2.0` | `2.2.8` | | [mariadb](https://github.com/mariadb-corporation/mariadb-connector-python) | `1.1.8` | `1.1.14` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.11` | `2.9.12` | | [coverage](https://github.com/coveragepy/coveragepy) | `7.13.4` | `7.13.5` | | [bump-my-version](https://github.com/callowayproject/bump-my-version) | `0.19.3` | `0.33.0` | Updates `bleach` from 6.1.0 to 6.3.0 - [Changelog](https://github.com/mozilla/bleach/blob/main/CHANGES) - [Commits](mozilla/bleach@v6.1.0...v6.3.0) Updates `boto3` from 1.34.76 to 1.43.6 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.34.76...1.43.6) Updates `django-storages` from 1.14.2 to 1.14.6 - [Changelog](https://github.com/jschneier/django-storages/blob/master/CHANGELOG.rst) - [Commits](jschneier/django-storages@1.14.2...1.14.6) Updates `pillow` from 12.1.1 to 12.2.0 - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.1.1...12.2.0) Updates `django` from 5.2.12 to 5.2.14 - [Commits](django/django@5.2.12...5.2.14) Updates `djangorestframework` from 3.16.1 to 3.17.1 - [Release notes](https://github.com/encode/django-rest-framework/releases) - [Commits](encode/django-rest-framework@3.16.1...3.17.1) Updates `mypy` from 1.18.2 to 1.19.1 - [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md) - [Commits](python/mypy@v1.18.2...v1.19.1) Updates `djangorestframework-stubs` from 3.16.8 to 3.16.9 - [Release notes](https://github.com/typeddjango/djangorestframework-stubs/releases) - [Commits](typeddjango/djangorestframework-stubs@3.16.8...3.16.9) Updates `grpcio` from 1.78.0 to 1.80.0 - [Release notes](https://github.com/grpc/grpc/releases) - [Commits](grpc/grpc@v1.78.0...v1.80.0) Updates `typos` from 1.44.0 to 1.46.1 - [Release notes](https://github.com/crate-ci/typos/releases) - [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md) - [Commits](crate-ci/typos@v1.44.0...v1.46.1) Updates `pulumi-aws` from 6.83.2 to 6.83.3 - [Release notes](https://github.com/pulumi/pulumi-aws/releases) - [Changelog](https://github.com/pulumi/pulumi-aws/blob/master/CHANGELOG_OLD.md) - [Commits](pulumi/pulumi-aws@v6.83.2...v6.83.3) Updates `types-python-dateutil` from 2.9.0.20260305 to 2.9.0.20260508 - [Commits](https://github.com/python/typeshed/commits) Updates `types-markdown` from 3.10.2.20260211 to 3.10.2.20260508 - [Commits](https://github.com/python/typeshed/commits) Updates `types-pygments` from 2.19.0.20251121 to 2.20.0.20260508 - [Commits](https://github.com/python/typeshed/commits) Updates `types-psycopg2` from 2.9.21.20260223 to 2.9.21.20260509 - [Commits](https://github.com/python/typeshed/commits) Updates `types-pycurl` from 7.45.7.20251101 to 7.46.0.20260509 - [Commits](https://github.com/python/typeshed/commits) Updates `types-six` from 1.17.0.20251009 to 1.17.0.20260408 - [Commits](https://github.com/python/typeshed/commits) Updates `social-auth-app-django` from 5.6.0 to 5.9.0 - [Release notes](https://github.com/python-social-auth/social-app-django/releases) - [Changelog](https://github.com/python-social-auth/social-app-django/blob/master/CHANGELOG.md) - [Commits](python-social-auth/social-app-django@5.6.0...5.9.0) Updates `django-environ` from 0.11.2 to 0.13.0 - [Release notes](https://github.com/joke2k/django-environ/releases) - [Changelog](https://github.com/joke2k/django-environ/blob/develop/CHANGELOG.rst) - [Commits](joke2k/django-environ@v0.11.2...v0.13.0) Updates `python-dateutil` from 2.9.0 to 2.9.0.post0 - [Release notes](https://github.com/dateutil/dateutil/releases) - [Changelog](https://github.com/dateutil/dateutil/blob/master/NEWS) - [Commits](dateutil/dateutil@2.9.0...2.9.0.post0) Updates `django-htmx` from 1.17.3 to 1.27.0 - [Changelog](https://github.com/adamchainz/django-htmx/blob/main/docs/changelog.rst) - [Commits](adamchainz/django-htmx@1.17.3...1.27.0) Updates `django-markdownify` from 0.9.3 to 0.9.6 - [Commits](erwinmatijsen/django-markdownify@0.9.3...0.9.6) Updates `model-bakery` from 1.17.0 to 1.23.4 - [Release notes](https://github.com/model-bakers/model_bakery/releases) - [Changelog](https://github.com/model-bakers/model_bakery/blob/main/CHANGELOG.md) - [Commits](model-bakers/model_bakery@1.17.0...1.23.4) Updates `mkdocs-material` from 9.7.4 to 9.7.6 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.7.4...9.7.6) Updates `mysqlclient` from 2.2.0 to 2.2.8 - [Release notes](https://github.com/PyMySQL/mysqlclient/releases) - [Changelog](https://github.com/PyMySQL/mysqlclient/blob/main/HISTORY.rst) - [Commits](PyMySQL/mysqlclient@v2.2.0...v2.2.8) Updates `mariadb` from 1.1.8 to 1.1.14 - [Release notes](https://github.com/mariadb-corporation/mariadb-connector-python/releases) - [Changelog](https://github.com/mariadb-corporation/mariadb-connector-python/blob/1.1/CHANGELOG.md) - [Commits](mariadb-corporation/mariadb-connector-python@v1.1.8...v1.1.14) Updates `psycopg2-binary` from 2.9.11 to 2.9.12 - [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS) - [Commits](psycopg/psycopg2@2.9.11...2.9.12) Updates `coverage` from 7.13.4 to 7.13.5 - [Release notes](https://github.com/coveragepy/coveragepy/releases) - [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst) - [Commits](coveragepy/coveragepy@7.13.4...7.13.5) Updates `bump-my-version` from 0.19.3 to 0.33.0 - [Release notes](https://github.com/callowayproject/bump-my-version/releases) - [Changelog](https://github.com/callowayproject/bump-my-version/blob/master/CHANGELOG.md) - [Commits](callowayproject/bump-my-version@0.19.3...0.33.0) --- updated-dependencies: - dependency-name: bleach dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: boto3 dependency-version: 1.43.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: django-storages dependency-version: 1.14.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: pillow dependency-version: 12.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: django dependency-version: 5.2.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: djangorestframework dependency-version: 3.17.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: mypy dependency-version: 1.19.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: djangorestframework-stubs dependency-version: 3.16.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: grpcio dependency-version: 1.80.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: typos dependency-version: 1.46.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: pulumi-aws dependency-version: 6.83.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: types-python-dateutil dependency-version: 2.9.0.20260508 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: types-markdown dependency-version: 3.10.2.20260508 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: types-pygments dependency-version: 2.20.0.20260508 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: types-psycopg2 dependency-version: 2.9.21.20260509 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: types-pycurl dependency-version: 7.46.0.20260509 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: types-six dependency-version: 1.17.0.20260408 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: social-auth-app-django dependency-version: 5.9.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: django-environ dependency-version: 0.13.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: python-dateutil dependency-version: 2.9.0.post0 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: django-htmx dependency-version: 1.27.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: django-markdownify dependency-version: 0.9.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: model-bakery dependency-version: 1.23.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: mkdocs-material dependency-version: 9.7.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: mysqlclient dependency-version: 2.2.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: mariadb dependency-version: 1.1.14 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: psycopg2-binary dependency-version: 2.9.12 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: coverage dependency-version: 7.13.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: bump-my-version dependency-version: 0.33.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Dependency ReviewThe following issues were found:
License Issuespoetry.lock
OpenSSF ScorecardScorecard details
Scanned Files
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-dependencies group with 29 updates:
6.1.06.3.01.34.761.43.61.14.21.14.612.1.112.2.05.2.125.2.143.16.13.17.11.18.21.19.13.16.83.16.91.78.01.80.01.44.01.46.16.83.26.83.32.9.0.202603052.9.0.202605083.10.2.202602113.10.2.202605082.19.0.202511212.20.0.202605082.9.21.202602232.9.21.202605097.45.7.202511017.46.0.202605091.17.0.202510091.17.0.202604085.6.05.9.00.11.20.13.02.9.02.9.0.post01.17.31.27.00.9.30.9.61.17.01.23.49.7.49.7.62.2.02.2.81.1.81.1.142.9.112.9.127.13.47.13.50.19.30.33.0Updates
bleachfrom 6.1.0 to 6.3.0Changelog
Sourced from bleach's changelog.
Commits
5546d5dchore: prep for 6.3.0 release88df3ffchore: fix readthedocsd8b2fb4fix: fix wbr handling (#488)55e48cechore: add support for Python 3.14 (#758)a4d6cddchore: drop support for Python 3.9 (#756)172d92fBump actions/setup-python from 5.6.0 to 6.0.0df88612Bump actions/checkout from 4.2.2 to 5.0.0cbcf6b1Bump actions/cache from 4.2.3 to 4.3.0d9aa7efSwitch from dependabot reviewers to CODEOWNERS06f0f76Update setuptools, wheel, and twine for devsUpdates
boto3from 1.34.76 to 1.43.6Commits
f2ccf9fMerge branch 'release-1.43.6'ffb5712Bumping version to 1.43.6cc7756aAdd changelog entries from botocore500f6a7Merge branch 'release-1.43.5'05f5628Merge branch 'release-1.43.5' into develop65d9798Bumping version to 1.43.5357614aAdd changelog entries from botocore5128f23Bump https://github.com/astral-sh/ruff-pre-commit (#4785)96f1897Merge branch 'release-1.43.4'91de1d8Merge branch 'release-1.43.4' into developUpdates
django-storagesfrom 1.14.2 to 1.14.6Changelog
Sourced from django-storages's changelog.
... (truncated)
Commits
3658c3dBump version for release (#1497)d51b0bfRelease version 1.14.6 (#1496)6ef553d[s3] Defaulturl_protocoltohttps:if set to None (#1483)80031d3[docs/azure] Fix broken link (#1492)8363be3[s3] Pass object parameters to head_object inexists(#1451)aa8a82e[docs/gcloud] Clean-up querystring auth language (#1489)758ad6f[gcloud] Add option to sign URLs via IAM Blob API (#1427)03566dcAdd missing CHANGELOG entry for Dropbox fix (#1488)3c0fe9fRelease version 1.14.5 (#1487)5db357aApply additional validation in overwrite path (#1486)Updates
pillowfrom 12.1.1 to 12.2.0Release notes
Sourced from pillow's releases.
... (truncated)
Commits
3c41c0912.2.0 version bumpcdaa29eCheck calloc return value (#9527)585b2f5Check calloc return valueecf011eCheck all allocs in the Arrow tree (#9488)cf6de8cReject non-numeric elements inside list coords (#9526)ffdcedeUpdate 12.2.0 release notes (#9522)7929d77Added security release notes (#149)c4f7aa5Added security release notes22cdb5fMove variable declaration inside define (#9525)fc15b3bResize tall images vertically first (#9524)Updates
djangofrom 5.2.12 to 5.2.14Commits
024c26b[5.2.x] Bumped version for 5.2.14 release.2115d4e[5.2.x] Fixed CVE-2026-6907 -- Prevented caching of requests when Vary header...47cf968[5.2.x] Fixed CVE-2026-35192 -- Ensured Vary header is sent when setting sess...2ec27ed[5.2.x] Fixed CVE-2026-5766 -- Enforced DATA_UPLOAD_MAX_MEMORY_SIZE in Memory...ed18840[5.2.x] Fixed typo in stub release notes for 5.2.14.de3f622[5.2.x] Added stub release notes and release date for 5.2.14.fb61c8a[5.2.x] Refs CVE-2026-4292 -- Isolated new test in AdminViewListEditable.bd1a758[5.2.x] Fixed two issues in release helper scripts/verify_release.sh.da57aaa[5.2.x] Added CVE-2026-3902, CVE-2026-4277, CVE-2026-4292, CVE-2026-33033, an...c9a8bdb[5.2.x] Post-release version bump.Updates
djangorestframeworkfrom 3.16.1 to 3.17.1Release notes
Sourced from djangorestframework's releases.
... (truncated)
Commits
22e231cPrepare bug fix release 3.17.1 (#9931)8e99b53Add condition to skip pushed tags from forks (#9924)c0407deFixHTMLFormRendererwith emptydatetimevalues (#9928)30d58a7Fix the book sizing in the documentation (#9926)6f03b79Tweak order of changes in release notes021ab56Bump version and update release notes for 3.17.0 (#9921)19ebad7Bump mkdocs-material[imaging] from 9.7.4 to 9.7.5 (#9923)f222c55Correct requires-python key in pyproject.toml7e7de6fRemove code fences from release checklistc599d30Update release processUpdates
mypyfrom 1.18.2 to 1.19.1Changelog
Sourced from mypy's changelog.
... (truncated)
Commits
412c19aBump version to 1.19.120aea0aUpdate changelog for 1.19.1 (#20414)2b23b50Serialize raw errors in cache metas (#20372)f60f90fFail on PyPy in main instead of setup.py (#20389)58d485bFail with an explicit error on PyPy (#20384)a4b31a2Allowtypes.NoneTypein match cases (#20383)8a6eff4[mypyc] fix generator regression with empty tuple (#20371)70eceeaFix noncommutative joins with bounded TypeVars (#20345)3890fc4Fix crash involving Unpack-ed TypeVarTuple (#20323)c93d917Fix crash on star import of redefinition (#20333)Updates
djangorestframework-stubsfrom 3.16.8 to 3.16.9Release notes
Sourced from djangorestframework-stubs's releases.
Commits
8d36f73Version 3.16.9 release (#942)478165cUpdate dependency mypy to >=1.13,<1.21 & fix tests (#940)0b29d9dLock file maintenance (#939)3a3009aLock file maintenancee80bdb2[pre-commit.ci] pre-commit autoupdate (#937)95adbfcFix incomplete types inrest_framework.utils(#935)a0f2554Update dependency types-requests to v2.33.0.20260327 (#936)3093590Update dependency uv_build to >=0.11.0,<0.12.0 (#933)1e2da42Update dependency types-requests to v2.32.4.20260324 (#934)579fcceLock file maintenanceUpdates
grpciofrom 1.78.0 to 1.80.0Release notes
Sourced from grpcio's releases.
... (truncated)
Commits
f5e2d6e[Release] Bump version to 1.80.0 (on v1.80.x branch) (#41857)938cfec[subchannel connection scaling] fix when we reset backoff (#41935)91778be[Backport][v1.80.x][Python] New_createmethod for aio.Metadata (#41888)f10b9f2[bzlmod] upgrade rules_swift to avoid BCR CI breakage on Windows with bazel 7...be4c1c5[subchannel] fix crash in connection scaling code (#41853)a71df73[Release] Bump version to 1.80.0-pre1 (on v1.80.x branch) (#41844)3ca09e4[Python] Fix GRPC_TRACE and add test to check the GRPC_TRACE logs print (#41814)260c6fd[PHP] Disable php infinite recursion check for callback from Core to PHP (#41...50957c5[Flakiness] Delete flaky iomgr fd_conservation_posix_test and create an Event...e1e1d0a[Bzlmod] Turn off bzlmod for PSM python tests. (#41810)Updates
typosfrom 1.44.0 to 1.46.1Release notes
Sourced from typos's releases.
Changelog
Sourced from typos's changelog.
Commits
5374cbfchore: Release52448f5docs: Update changelog030c719Merge pull request #1552 from epage/fixes7a688c7fix(dict): Confidentials isn't valid3bcd3b3Merge pull request #1548 from crate-ci/renovate/maturin-1.x5294011chore(deps): Update compatible (#1547)c3be360chore(deps): Update dependency maturin to >=1.13,<1.14bbaefadchore: Releasec19f54cchore: Released65608bdocs: Update changelogUpdates
pulumi-awsfrom 6.83.2 to 6.83.3Release notes
Sourced from pulumi-aws's releases.
Commits
0ca3121Get tokens from ESC6355f4eUpdate Go toolchain to 1.25.5 (security backport) (#6251)Updates
types-python-dateutilfrom 2.9.0.20260305 to 2.9.0.20260508Commits
Updates
types-markdownfrom 3.10.2.20260211 to 3.10.2.20260508Commits
Updates
types-pygmentsfrom 2.19.0.20251121 to 2.20.0.20260508Commits
Updates
types-psycopg2from 2.9.21.20260223 to 2.9.21.20260509Commits
Updates
types-pycurlfrom 7.45.7.20251101 to 7.46.0.20260509Commits
Updates
types-sixfrom 1.17.0.20251009 to 1.17.0.20260408Commits
Updates
social-auth-app-djangofrom 5.6.0 to 5.9.0Release notes
Sourced from social-auth-app-django's releases.
Changelog
Sourced from social-auth-app-django's changelog.