Skip to content

fix(deps): pin dependencies#136

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/pin-dependencies
Open

fix(deps): pin dependencies#136
renovate[bot] wants to merge 1 commit intomainfrom
renovate/pin-dependencies

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Jan 18, 2026

This PR contains the following updates:

Package Type Update Change OpenSSF
@muenchen/muc-patternlab-vue dependencies pin ^7.4.17.4.1 OpenSSF Scorecard
@​types/dompurify devDependencies pin ^3.0.53.0.5
@vue/eslint-config-typescript devDependencies pin ^14.7.014.7.0 OpenSSF Scorecard
@vue/test-utils devDependencies pin ^2.4.02.4.0 OpenSSF Scorecard
bs4 project.dependencies pin >=0.0.2==0.0.2
cryptography (changelog) project.dependencies pin >=46.0.4==46.0.5 OpenSSF Scorecard
dompurify dependencies pin ^3.3.13.3.2 OpenSSF Scorecard
eslint (source) devDependencies pin ^10.0.210.0.2 OpenSSF Scorecard
eslint-plugin-vue (source) devDependencies pin ^10.8.010.8.0 OpenSSF Scorecard
gitpython project.dependencies pin >=3.1.45==3.1.46 OpenSSF Scorecard
httpx (changelog) project.dependencies pin >=0.28.1==0.28.1 OpenSSF Scorecard
ipykernel dependency-groups pin >=7.1.0==7.1.0 OpenSSF Scorecard
langchain (changelog) dependency-groups pin >=0.3.27==1.2.7 OpenSSF Scorecard
langchain-community (changelog) dependency-groups pin >=0.3.28==0.4.1 OpenSSF Scorecard
langchain-docling (changelog) dependency-groups pin >=1.1.0==2.0.0 OpenSSF Scorecard
langchain-openai (changelog) dependency-groups pin >=0.3.32==1.1.7 OpenSSF Scorecard
langchain-openai (changelog) project.dependencies pin >=1.1.7==1.1.7 OpenSSF Scorecard
langchain-postgres project.optional-dependencies pin >=0.0.15==0.0.16
langchain-postgres project.dependencies pin >=0.0.16==0.0.16
langchain-text-splitters (changelog) project.dependencies pin >=1.1.0==1.1.0 OpenSSF Scorecard
legacy-cgi project.dependencies pin >=2.6.4==2.6.4 OpenSSF Scorecard
marked (source) dependencies pin ^17.0.117.0.3 OpenSSF Scorecard
mistralai project.dependencies pin >=1.9.11==1.10.1 OpenSSF Scorecard
pgvector project.dependencies pin <0.4==0.3.6 OpenSSF Scorecard
pre-commit dependency-groups pin >=4.5.1==4.5.1 OpenSSF Scorecard
psycopg (changelog) project.dependencies pin >=3.2.9==3.3.2 OpenSSF Scorecard
pydantic (changelog) project.dependencies pin >=2.11.7==2.12.5 OpenSSF Scorecard
pydantic-settings (changelog) project.dependencies pin >=2.10.1==2.12.0 OpenSSF Scorecard
pypdf (changelog) dependency-groups pin >=6.4.1==6.9.2 OpenSSF Scorecard
pypdf (changelog) project.dependencies pin >=6.6.0==6.9.2 OpenSSF Scorecard
pytest (changelog) dependency-groups pin >=9.0.2==9.0.2 OpenSSF Scorecard
pytest-asyncio (changelog) project.dependencies pin >=1.3.0==1.3.0 OpenSSF Scorecard
python-dotenv dependency-groups pin >=1.2.1==1.2.1 OpenSSF Scorecard
pyyaml (source) project.dependencies pin >=6.0.2==6.0.3 OpenSSF Scorecard
ruff (source, changelog) dependency-groups pin >=0.14.11==0.14.14 OpenSSF Scorecard
sqlalchemy (changelog) project.dependencies pin >=2.0.42==2.0.46
sqlmodel (changelog) project.dependencies pin >=0.0.24==0.0.32 OpenSSF Scorecard
stamina (changelog) project.dependencies pin >=25.1.0==25.2.0 OpenSSF Scorecard
truststore project.dependencies pin >=0.10.4==0.10.4 OpenSSF Scorecard
ty (changelog) dependency-groups pin >=0.0.11==0.0.14 OpenSSF Scorecard
uv_build (source, changelog) build-system.requires pin >=0.9.13,<0.10.0==0.9.30 OpenSSF Scorecard

⚠️ Renovate's pin functionality does not currently wire in the release age for a package, so the Minimum Release Age checks can apply. You will need to manually validate the Minimum Release Age for these package(s).

Add the preset :preserveSemverRanges to your config if you don't want to pin your dependencies.


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) in timezone Europe/Berlin, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai bot commented Jan 18, 2026

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • 🔍 Trigger a full review

Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate bot force-pushed the renovate/pin-dependencies branch 5 times, most recently from 78dcf40 to 5f92210 Compare January 27, 2026 10:23
@renovate renovate bot force-pushed the renovate/pin-dependencies branch 2 times, most recently from f092031 to 233442d Compare January 29, 2026 12:33
@renovate renovate bot changed the title fix(deps): pin dependencies Pin dependencies Jan 29, 2026
@renovate renovate bot force-pushed the renovate/pin-dependencies branch 6 times, most recently from af0a9b6 to 87cb13f Compare January 30, 2026 11:15
@renovate renovate bot changed the title Pin dependencies fix(deps): pin dependencies Jan 30, 2026
@renovate renovate bot force-pushed the renovate/pin-dependencies branch 7 times, most recently from 414c4eb to 64be9e1 Compare February 3, 2026 22:59
@renovate renovate bot force-pushed the renovate/pin-dependencies branch 12 times, most recently from 0513157 to 455b4b4 Compare February 17, 2026 10:56
@renovate renovate bot force-pushed the renovate/pin-dependencies branch 13 times, most recently from b862045 to 8dbd83a Compare February 26, 2026 13:46
@renovate renovate bot force-pushed the renovate/pin-dependencies branch from 8dbd83a to 913a701 Compare March 1, 2026 12:45
@github-actions
Copy link
Copy Markdown

github-actions bot commented Mar 1, 2026

Dependency Review

The following issues were found:

  • ❌ 1 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 5 package(s) with unknown licenses.
  • ⚠️ 26 packages with OpenSSF Scorecard issues.

View full job summary

@renovate renovate bot force-pushed the renovate/pin-dependencies branch 2 times, most recently from 5628510 to a9607c0 Compare March 2, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants