Bump the all group in /localcert with 11 updates #88
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the all group in /localcert with 11 updates:
2023.7.22
2024.2.2
42.0.0
42.0.5
4.2.7
5.0.2
0.58.1
0.61.1
3.7
3.8
3.4
3.6
2.0.7
2.2.1
4.12.2
4.12.3
7.3.2
7.4.3
2.4.2
2.6.1
6.1.0
7.0.0
Updates
certifi
from 2023.7.22 to 2024.2.2Commits
45eb611
2024.02.02 (#266)83f4f04
fix leaking certificate issue (#265)bbf2208
Bump actions/upload-artifact from 4.2.0 to 4.3.0 (#264)9e837a5
Bump actions/upload-artifact from 4.1.0 to 4.2.0 (#262)05d071b
Bump actions/upload-artifact from 4.0.0 to 4.1.0 (#261)2a3088a
Bump actions/download-artifact from 4.1.0 to 4.1.1 (#260)d4ca66e
Bump actions/upload-artifact from 3.1.3 to 4.0.0 (#258)5d15663
Bump actions/download-artifact from 3.0.2 to 4.1.0 (#257)d66ef9d
Bump actions/setup-python from 4.7.1 to 5.0.0 (#256)8f0d412
Bump pypa/gh-action-pypi-publish from 1.8.10 to 1.8.11 (#255)Updates
cryptography
from 42.0.0 to 42.0.5Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
33833f0
Release 42.0.5 (#10470)4be53bf
Added a budget for NC checks to protect against DoS (#10467) (#10468)8e9de30
Bump pyo3 from 0.20.2 to 0.20.3 in /src/rust (#10462) (#10465)fe18470
Bump for 42.0.4 release (#10445)aaa2dd0
Fix ASN.1 issues in PKCS#7 and S/MIME signing (#10373) (#10442)7a4d012
Fixes #10422 -- don't crash when a PKCS#12 key and cert don't match (#10423) ...df314bb
backport actions m1 switch to 42.0.x (#10415)c49a7a5
changelog and version bump for 42.0.3 (#10396)396bcf6
fix provider loading take two (#10390) (#10395)0e0e46f
backport: initialize openssl's legacy provider in rust (#10323) (#10333)Updates
django
from 4.2.7 to 5.0.2Commits
428d06c
[5.0.x] Bumped version for 5.0.2 release.16a8fe1
[5.0.x] Fixed CVE-2024-24680 -- Mitigated potential DoS in intcomma template ...2cfa3fb
[5.0.x] Changed severity levels to list in security policy docs.761946f
[5.0.x] Fixed #35149 -- Fixed crashes of db_default with unresolvable output ...914eee1
[5.0.x] Refs #35149 -- Made equivalent db_default alterations noops.3e7a30f
[5.0.x] Fixed #35162 -- Fixed crash when adding fields with db_default on MySQL.741f080
[5.0.x] Fixed #35147 -- Added backward incompatibility note about filtering a...58d5e57
[5.0.x] Fixed typo in docs/topics/db/managers.txt.a8f9c29
[5.0.x] Removed mention of designers in DTL design philosophy.06b05c7
[5.0.x] Refs #34936 -- Added test for altering DecimalField with db_default t...Updates
django-allauth
from 0.58.1 to 0.61.1Changelog
Sourced from django-allauth's changelog.
... (truncated)
Commits
da3fe9b
chore: Release 0.61.12fa4294
tests(google): python 3.7 compatibility4037177
fix(account/middleware): SyncToAsync never awaiteda2a051d
feat(google): Verify id_token signature701bcc6
refactor(socialaccount): Extract JWT verification9c08094
chore: Opening 0.61.1-dev6123cca
chore: Release 0.61.0c3b0af2
fix(account): Don't check redirect url if there's no redirect93d47fd
fix(google): Gracefully handle cases where id_token is absent48a661a
fix(mfa): Prevent reuse of TOTP codesUpdates
django-csp
from 3.7 to 3.8Release notes
Sourced from django-csp's releases.
... (truncated)
Changelog
Sourced from django-csp's changelog.
Commits
4899179
Prepare for 3.8 final release684b12a
Prepare for 3.8rc1 release - just one packaging changeb1dd37e
Tomlify setup.py (#216)7200b16
Prepare for 3.8rc release (#215)4be512c
Update GH actions helpers to use Node 20-based versions (#214)371da46
Bring codebase up to modern Python using pyupgrade (#213)9698258
MiddlewareMixin is always present in django>=3.212116dc
Update settings documentation to move deprecated-within-csp settings to their...61f3124
Update README.rst58113ef
Fix sphinx theme installation (#208)Updates
idna
from 3.4 to 3.6Changelog
Sourced from idna's changelog.
Commits
4ae74cf
Release v3.621888f3
Merge pull request #164 from mgorny/sdist-testc5ba76a
Include tests in sdist2eb16d3
Merge pull request #162 from kjd/release-3.589cd061
Release v3.59fc29cd
Merge pull request #161 from kjd/masteracb8c4a
Merge pull request #160 from cclauss/patch-1adca101
README.rst: Fix typos33a8f7b
Merge pull request #159 from diogoteles08/add-scorecard354a412
Add Scorecard GitHub ActionUpdates
urllib3
from 2.0.7 to 2.2.1Release notes
Sourced from urllib3's releases.
... (truncated)
Changelog
Sourced from urllib3's changelog.
Commits
54d6edf
Release 2.2.149b2dda
Stop casting request headers to HTTPHeaderDict (#3344)e22f651
Fix docstring of retries parameterfa54179
Distinguish between truncated and excess content in response (#3273)cfe52f9
Fix InsecureRequestWarning for HTTPS Emscripten requests (#3333)25155d7
Ensure no remote connections during testing (#3328)12f9233
Bump cryptography to 42.0.2 and PyOpenSSL to 24.0.0 (#3340)9929d3c
Add nox session to start local Pyodide consoleaa8d3dd
Fix ssl_version tests for upcoming migration to pytest 823f2287
Remove TODO about informational responses (#3319)Updates
beautifulsoup4
from 4.12.2 to 4.12.3Updates
coverage
from 7.3.2 to 7.4.3Changelog
Sourced from coverage's changelog.
... (truncated)
Commits
1af3624
docs: sample HTML for 7.4.3f06c5e4
docs: prep for 7.4.308fc997
fix: get atomic copies of iterables when flushing data. #17334e34571
build: put a time limit on the Python nightly testsa1d8d29
build: make targets should use underscores not dashesf7d40a0
build: tweak the release instructions0f19b82
build: bump version5d69334
test: if a test fails randomly, let it retry with@flaky
65d686c
docs: sample HTML for 7.4.2026dca7
docs: prep for 7.4.2Updates
dnspython
from 2.4.2 to 2.6.1Release notes
Sourced from dnspython's releases.
Changelog
Sourced from dnspython's changelog.
... (truncated)
Commits
0a742b9
update CI0ea5ad0
The Tudoor fix should not eat valid Truncated exceptions #1053 (#1054)f12d398
2.6.1 version prepcecb853
Further improve CVE fix coverage to 100% for sync and async.7952e31
test IgnoreErrorse093299
For the Tudoor fix, we also need the UDP nameserver to ignore_unexpected.3af9f78
2.6.0 versioningca63d95
Require cryptography >=41 instead of 42.902cbf3
Create CODE_OF_CONDUCT.mded9795f
github contributing and pull request templateUpdates
flake8
from 6.1.0 to 7.0.0Commits
88a4f9b
Release 7.0.06f3a60d
Merge pull request #1906 from PyCQA/upgrade-pyflakescde8570
upgrade pyflakes to 3.2.x2ab9d76
Merge pull request #1903 from PyCQA/pre-commit-ci-update-confige27611f
[pre-commit.ci] pre-commit autoupdate9d20be1
Merge pull request #1902 from PyCQA/pre-commit-ci-update-config06c1503
[pre-commit.ci] auto fixes from pre-commit.com hooksb67ce03
Fix bugbear lintsc8801c1
[pre-commit.ci] pre-commit autoupdate045f297
Merge pull request #1893 from PyCQA/pre-commit-ci-update-configDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions