Skip to content

build(deps-dev): bump moto from 5.1.11 to 5.1.21#10206

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/master/moto-5.1.21
Open

build(deps-dev): bump moto from 5.1.11 to 5.1.21#10206
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/master/moto-5.1.21

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 1, 2026

Bumps moto from 5.1.11 to 5.1.21.

Changelog

Sourced from moto's changelog.

5.1.21

Docker Digest for 5.1.21: sha256:93ad54da7badce7f9c13e5e6439c93564c764663c42872d2c39f718aa484047a

General:
    * Moto now supports the new AWS partition for the EU sovereign cloud ('eusc-de-east-1')

New Services: * Account: * delete_alternate_contact() * get_alternate_contact() * put_alternate_contact()

* Connect:
    * associate_analytics_data_set()
    * create_instance()
    * delete_instance()
    * describe_instance()
    * disassociate_analytics_data_set()
    * list_analytics_data_associations()
    * list_instances()
    * list_tags_for_resource()
    * tag_resource()
    * untag_resource()

New Methods: * Backup: * create_report_plan() * delete_backup_vault() * delete_backup_vault_lock_configuration() * describe_backup_vault() * describe_report_plan() * list_report_plans() * put_backup_vault_lock_configuration()

* EKS:
    * update_nodegroup_config()
  • Route53Resolver:

    • get_resolver_query_log_config_association()
    • list_resolver_query_log_configs()
    • list_resolver_query_log_config_associations()
  • SecurityHub:

    • get_master_account()

Miscellaneous: * DynamoDB now supports multi-attribute composite key support for GSIs * ELBv2: Internal load balancers can now be dualstack * IAM: Policy validation now correctly validates Boolean conditions and NULL-resources

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Dependabot Updates pip Dependabot Updates Python labels Mar 1, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 1, 2026 19:09
@dependabot dependabot bot added dependencies Dependabot Updates pip Dependabot Updates Python labels Mar 1, 2026
@github-actions github-actions bot added the community Opened by the Community label Mar 1, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Mar 1, 2026

Conflict Markers Resolved

All conflict markers have been successfully resolved in this pull request.

@github-actions
Copy link
Contributor

github-actions bot commented Mar 1, 2026

⚠️ Changes detected in the following folders without a corresponding update to the CHANGELOG.md:

  • prowler (root dependency files changed)

Please add an entry to the corresponding CHANGELOG.md file to maintain a clear history of changes.

Bumps [moto](https://github.com/getmoto/moto) from 5.1.11 to 5.1.21.
- [Release notes](https://github.com/getmoto/moto/releases)
- [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md)
- [Commits](getmoto/moto@5.1.11...5.1.21)

---
updated-dependencies:
- dependency-name: moto
  dependency-version: 5.1.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/master/moto-5.1.21 branch from c567713 to 42c2ae1 Compare March 18, 2026 09:01
@github-actions
Copy link
Contributor

github-actions bot commented Mar 18, 2026

🔒 Container Security Scan

Image: prowler:802b97f
Last scan: 2026-03-18 09:11:21 UTC

📊 Vulnerability Summary

Severity Count
🔴 Critical 3
Total 3

3 package(s) affected

⚠️ Action Required

Critical severity vulnerabilities detected. These should be addressed before merging:

  • Review the detailed scan results
  • Update affected packages to patched versions
  • Consider using a different base image if updates are unavailable

📋 Resources:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community Opened by the Community dependencies Dependabot Updates pip Dependabot Updates Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants