Bump the python-dependencies group across 1 directory with 6 updates #886
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the python-dependencies group with 6 updates in the / directory:
5.0.6
5.0.7
3.15.1
3.15.2
3.1.19
3.2.1
1.10.0
1.11.0
3.2.2
3.2.6
5.0.2
5.0.4
Updates
django
from 5.0.6 to 5.0.7Commits
deec9b9
[5.0.x] Bumped version for 5.0.7 release.3a7bf7f
[5.0.x] Made cosmetic edits to 5.0.7 release notes.8e7a44e
[5.0.x] Fixed CVE-2024-39614 -- Mitigated potential DoS in get_supported_lang...9f4f63e
[5.0.x] Fixed CVE-2024-39330 -- Added extra file name validation in Storage's...07cefde
[5.0.x] Fixed CVE-2024-39329 -- Standarized timing of verify_password() when ...7285644
[5.0.x] Fixed CVE-2024-38875 -- Mitigated potential DoS in urlize and urlizet...8303400
[5.0.x] Fixed 35506 -- Clarified initial references to URLconf in tutorial 1.c76089b
[5.0.x] Refs #35560 -- Corrected CheckConstraint argument name in model_field...43aa0c1
[5.0.x] Removed outdated note about limitations in Clickjacking protection.0602fc2
[5.0.x] Fixed #35560 -- Made Model.full_clean() ignore GeneratedFields for co...Updates
djangorestframework
from 3.15.1 to 3.15.2Commits
c7a7eae
Version 3.15.2 (#9439)3b41f01
Fix potential XSS vulnerability in break_long_headers template filter (#9435)fe92f0d
Add__hash__
method forpermissions.OperandHolder
class (#9417)fbdab09
docs: Correct some evaluation results and a httpie option in Tutorial1 (#9421)36d5c0e
tests: Check urlpatterns after cleanups (#9400)9d4ed05
Don't use Windows line endingsb34bde4
Fix typo in setup.cfg settingab681f2
Update requirements in docs2237724
bump pygments (security hygiene)d58b8da
Update deprecation hintsUpdates
psycopg
from 3.1.19 to 3.2.1Changelog
Sourced from psycopg's changelog.
... (truncated)
Commits
bb47d39
chore: bump psycopg package version to 3.2.155490a2
fix: fix versions in packaging metadata1cbc42a
docs: fix title level of major releases06a6e5e
docs: mention dropping Python 3.7 in psycopg 3.2 releaseea3735d
docs: better organization of the 3.2 release notes896eee2
chore: bump psycopg package version to 3.2.02e2f4d7
chore: bump psycopg package version to 3.1.207369d3b
Merge pull request #846 from eli-schwartz/tomllib6672c70
style: shorter line in pyproject.tomla517bb4
build: avoid installing tomli on recent pythonUpdates
mypy
from 1.10.0 to 1.11.0Changelog
Sourced from mypy's changelog.
... (truncated)
Commits
dbd5f5c
Remove +dev from version for 1.11 releasef0a8c69
Update CHANGELOG for mypy 1.11 (#17540)371f780
CHANGELOG.md update for 1.11 (#17539)2563da0
Fix daemon crash on invalid type in TypedDict (#17495)d8c67c3
[release 1.11] Ignore some errors in typeshed (#17510)294daff
Mention --enable-incomplete-feature=NewGenericSyntax (#17462)5c33abf
Further improvements to functools.partial handling (#17425)c37d972
Fix type comments crash inside generic definitions (#16849)d39f023
Add changelog entry for 1.10.1 (#17436)6c1d867
Fix ParamSpec inference against TypeVarTuple (#17431)Updates
pylint
from 3.2.2 to 3.2.6Commits
da19566
Bump pylint to 3.2.6, update changelog (#9825)810c59c
Update setuptools to >=71.0.4 (#9812) (#9824)5f19cd5
Fix a crash when a subclass extends__slots__
(#9817) (#9822)c0b1d22
Bump astroid to 3.2.4 (#9816) (#9821)1d877de
Fix consider-using-min-max-builtin (#9802) (#9803)8410f57
Fix a false positive formissing-param-doc
(#9740) (#9793)bd4c8f1
Handle assert_never() when imported from typing_extensions (#9782) (#9790)8eb2c4d
Fix FP forunexpected-keyword-arg
with ambiguous constructors (#9785) (#9788)9882537
Bump astroid to 3.2.3 (#9787)aea868c
Fixinvalid-name
regression for class attributes in subclasses (#9772) (#9775)Updates
django-stubs
from 5.0.2 to 5.0.4Commits
d60e31e
Prepare for a release5.0.4
(#2285)f48e722
Check correct model on other side of many to many reverse filtering (#2283)8eeed9b
convert as_manager hooks to base class hook (#2282)59ebe6f
fill QuerySet generics using the manager's model type (#2281)a28717d
Check model fields on filtering methods of queryset types (#2277)7dd81cc
Bump pytest from 8.3.1 to 8.3.2 (#2278)2f5a494
lookup manager type via mro (#2276)c7d734a
Prepare for a release5.0.3
(#2274)d6010fd
Check calls to filtering manager methods involvingManyToManyField
(#2275)d747285
Improve stackoverflow linkDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions