-
Notifications
You must be signed in to change notification settings - Fork 66
Deps: Bump the python-packages group with 8 updates #1256
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Bumps the python-packages group with 8 updates: | Package | From | To | | --- | --- | --- | | [lxml](https://github.com/lxml/lxml) | `6.0.0` | `6.0.1` | | [coverage](https://github.com/nedbat/coveragepy) | `7.10.3` | `7.10.5` | | [pontos](https://github.com/greenbone/pontos) | `25.7.2` | `25.8.1` | | [types-paramiko](https://github.com/typeshed-internal/stub_uploader) | `4.0.0.20250809` | `4.0.0.20250822` | | [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/) | `4.13.4` | `4.13.5` | | [h2](https://github.com/python-hyper/h2) | `4.2.0` | `4.3.0` | | [requests](https://github.com/psf/requests) | `2.32.4` | `2.32.5` | | [ruff](https://github.com/astral-sh/ruff) | `0.12.8` | `0.12.10` | Updates `lxml` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/lxml/lxml/releases) - [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt) - [Commits](lxml/lxml@lxml-6.0.0...lxml-6.0.1) Updates `coverage` from 7.10.3 to 7.10.5 - [Release notes](https://github.com/nedbat/coveragepy/releases) - [Changelog](https://github.com/nedbat/coveragepy/blob/master/CHANGES.rst) - [Commits](coveragepy/coveragepy@7.10.3...7.10.5) Updates `pontos` from 25.7.2 to 25.8.1 - [Release notes](https://github.com/greenbone/pontos/releases) - [Commits](greenbone/pontos@v25.7.2...v25.8.1) Updates `types-paramiko` from 4.0.0.20250809 to 4.0.0.20250822 - [Commits](https://github.com/typeshed-internal/stub_uploader/commits) Updates `beautifulsoup4` from 4.13.4 to 4.13.5 Updates `h2` from 4.2.0 to 4.3.0 - [Changelog](https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst) - [Commits](python-hyper/h2@v4.2.0...v4.3.0) Updates `requests` from 2.32.4 to 2.32.5 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.4...v2.32.5) Updates `ruff` from 0.12.8 to 0.12.10 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.12.8...0.12.10) --- updated-dependencies: - dependency-name: lxml dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-packages - dependency-name: coverage dependency-version: 7.10.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-packages - dependency-name: pontos dependency-version: 25.8.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-packages - dependency-name: types-paramiko dependency-version: 4.0.0.20250822 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-packages - dependency-name: beautifulsoup4 dependency-version: 4.13.5 dependency-type: indirect update-type: version-update:semver-patch dependency-group: python-packages - dependency-name: h2 dependency-version: 4.3.0 dependency-type: indirect update-type: version-update:semver-minor dependency-group: python-packages - dependency-name: requests dependency-version: 2.32.5 dependency-type: indirect update-type: version-update:semver-patch dependency-group: python-packages - dependency-name: ruff dependency-version: 0.12.10 dependency-type: indirect update-type: version-update:semver-patch dependency-group: python-packages ... Signed-off-by: dependabot[bot] <[email protected]>
Dependency ReviewThe following issues were found:
License Issuespoetry.lock
Allowed Licenses: 0BSD, AGPL-3.0-or-later, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause-Clear, BSD-3-Clause, BSL-1.0, CAL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-4.0, CC0-1.0, EPL-2.0, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-2.0, GPL-3.0-only, GPL-3.0-or-later, GPL-3.0, ISC, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, LGPL-2.1, LGPL-3.0-only, LGPL-3.0, LGPL-3.0-or-later, MIT, MIT-CMU, MPL-1.1, MPL-2.0, OFL-1.1, PSF-2.0, Python-2.0, Python-2.0.1, Unicode-DFS-2016, Unlicense, Zlib, ZPL-2.1 OpenSSF Scorecard
Scanned Files
|
Conventional Commits Report
🚀 Conventional commits found. |
a-h-abdelsalam
approved these changes
Aug 25, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
dependencies
Pull requests that update a dependency file
python
Pull requests that update Python code
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the python-packages group with 8 updates:
6.0.06.0.17.10.37.10.525.7.225.8.14.0.0.202508094.0.0.202508224.13.44.13.54.2.04.3.02.32.42.32.50.12.80.12.10Updates
lxmlfrom 6.0.0 to 6.0.1Changelog
Sourced from lxml's changelog.
Commits
5aca07dPrepare release of lxml 6.0.1.f0e555aBuild: Add Py3.14 also to tox.ini.afc745aUpdate changelog.25242c6Build: Add "riscv64" wheels for Py3.12+.457c564Build: Mark Py3.14 as officially supported.66a3cc3Remove Py2 test code.6e88838CI: Fix version usage in cache keys.fe5df46Build: bump the github-actions group across 1 directory with 3 updates (#476)9177121CI: Configure library versions centrally in pyproject.toml to prevent build t...525c6b9Build: Separate libs cache by CPU architecture.Updates
coveragefrom 7.10.3 to 7.10.5Changelog
Sourced from coverage's changelog.
Commits
810abebchore: make upgrade3c8f1b5build: use --universal to keep platform conditions in .pip files107ae05docs: sample HTML for 7.10.5b5bc6d4docs: prep for 7.10.5a5c18ccstyle: auto-generated changes shouldn't trigger ruff re-formatting1f9f840build: tooling for ruff formatting9ee5b3echore: make upgradebfeb2aestyle: fix things so pylint is happy with ruff82467f7chore:ruff format .0a7b733refactor: remove unused things from lab/Updates
pontosfrom 25.7.2 to 25.8.1Release notes
Sourced from pontos's releases.
Commits
7189a16Automatic release to 25.8.183e17f1Change: Rust support for workspace.package.versionc2656f8Deps: Bump actions/checkout from 4.2.2 to 4.3.0 in the actions group18e2deeDeps: Bump coverage from 7.10.3 to 7.10.4 in the python-packages group69db3f9Automatic adjustments after release [skip ci]f004abbAutomatic release to 25.8.0cabc6eaFix: Use 'Array' in cargo tests instead of 'Table'57ca3c2change: Make it possible to read [workspace.project] in cargo.tomla5e524cDeps: Bump the python-packages group with 3 updates0be1621Deps: Bump the python-packages group with 3 updatesUpdates
types-paramikofrom 4.0.0.20250809 to 4.0.0.20250822Commits
Updates
beautifulsoup4from 4.13.4 to 4.13.5Updates
h2from 4.2.0 to 4.3.0Changelog
Sourced from h2's changelog.
Commits
1aae569v4.3.09e4bbedmerge surrounding whitespace and uppercase validators into illegal character ...035e989be stricter about which characters to accept for headers883ed37reject header names and values containing unpermitted characters\r,\n, ...0583911lint: fix TC006bbd3d90fix(packaging): bump twine to pass meta check wildcard bugsea3140fcleanup9ce83ffexclude RDT from sdist492d3dbUpdate .readthedocs.yaml243461dCreate RTD configUpdates
requestsfrom 2.32.4 to 2.32.5Release notes
Sourced from requests's releases.
Changelog
Sourced from requests's changelog.
Commits
b25c87dv2.32.5131e506Merge pull request #7010 from psf/dependabot/github_actions/actions/checkout-...b336cb2Bump actions/checkout from 4.2.0 to 5.0.046e939bUpdate publish workflow to useartifact-idinstead ofname4b9c546Merge pull request #6999 from psf/dependabot/github_actions/step-security/har...7618dbeBump step-security/harden-runner from 2.12.0 to 2.13.02edca11Add support for Python 3.14 and drop support for Python 3.8 (#6993)fec96cdUpdate Makefile rules (#6996)d58d8aadocs: clarify timeout parameter uses seconds in Session.request (#6994)91a3eabBump github/codeql-action from 3.28.5 to 3.29.0Updates
rufffrom 0.12.8 to 0.12.10Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
c68ff8dBump 0.12.10 (#20025)5931a52[ty] Stop running every mdtest twice692be72Move diff rendering toruff_db(#20006)14fe122[ty] Perform assignability etc checks using newConstraintstrait (#19838)045cba3[ty] Usededentin cursor tests (#20019)a5cbca1Fix rust feature activation (#20012)d43a3d3[ty] Avoid unnecessary argument type expansion (#19999)9911196[ty] Add link for namespaces being partial (#20015)859475f[ty] add docstrings to completions based on type (#20008)7b75aee[pyupgrade] Avoid reporting__future__features as unnecessary when they ...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions