chore(deps): bump the pip group across 2 directories with 6 updates#21
Open
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the pip group with 1 update in the /golden-paths/h2-enhancement/api-microservice/skeleton directory: [python-jose](https://github.com/mpdavis/python-jose). Bumps the pip group with 5 updates in the /golden-paths/h3-innovation/rag-application/skeleton directory: | Package | From | To | | --- | --- | --- | | [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.6` | `0.0.22` | | [azure-identity](https://github.com/Azure/azure-sdk-for-python) | `1.15.0` | `1.16.1` | | [langchain](https://github.com/langchain-ai/langchain) | `0.1.5` | `0.3.0.dev1` | | [langchain-community](https://github.com/langchain-ai/langchain) | `0.0.17` | `0.3.27` | | [pypdf](https://github.com/py-pdf/pypdf) | `4.0.1` | `6.9.2` | Updates `python-jose` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/mpdavis/python-jose/releases) - [Changelog](https://github.com/mpdavis/python-jose/blob/master/CHANGELOG.md) - [Commits](mpdavis/python-jose@3.3.0...3.4.0) Updates `python-multipart` from 0.0.6 to 0.0.22 - [Release notes](https://github.com/Kludex/python-multipart/releases) - [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md) - [Commits](Kludex/python-multipart@0.0.6...0.0.22) Updates `azure-identity` from 1.15.0 to 1.16.1 - [Release notes](https://github.com/Azure/azure-sdk-for-python/releases) - [Commits](Azure/azure-sdk-for-python@azure-identity_1.15.0...azure-identity_1.16.1) Updates `langchain` from 0.1.5 to 0.3.0.dev1 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain-ibm==0.1.5...langchain==0.3.0.dev1) Updates `langchain-community` from 0.0.17 to 0.3.27 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](https://github.com/langchain-ai/langchain/commits/langchain==0.3.27) Updates `pypdf` from 4.0.1 to 6.9.2 - [Release notes](https://github.com/py-pdf/pypdf/releases) - [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md) - [Commits](py-pdf/pypdf@4.0.1...6.9.2) --- updated-dependencies: - dependency-name: python-jose dependency-version: 3.4.0 dependency-type: direct:production dependency-group: pip - dependency-name: python-multipart dependency-version: 0.0.22 dependency-type: direct:production dependency-group: pip - dependency-name: azure-identity dependency-version: 1.16.1 dependency-type: direct:production dependency-group: pip - dependency-name: langchain dependency-version: 0.3.0.dev1 dependency-type: direct:production dependency-group: pip - dependency-name: langchain-community dependency-version: 0.3.27 dependency-type: direct:production dependency-group: pip - dependency-name: pypdf dependency-version: 6.9.2 dependency-type: direct:production dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the pip group with 1 update in the /golden-paths/h2-enhancement/api-microservice/skeleton directory: python-jose.
Bumps the pip group with 5 updates in the /golden-paths/h3-innovation/rag-application/skeleton directory:
0.0.60.0.221.15.01.16.10.1.50.3.0.dev10.0.170.3.274.0.16.9.2Updates
python-josefrom 3.3.0 to 3.4.0Release notes
Sourced from python-jose's releases.
Changelog
Sourced from python-jose's changelog.
Commits
82cd15fAdded release date to CHANGELOG.md for 3.4.0 (#371)4e01847Prepare 3.4.0 release (#370)0360fa3Replace usage of deprecated datetime.utcnow() with datetime.now(UTC) (#360)12f30c8Fix for CVE-2024-33663 (forbid public key for HMAC) (#369)638d047Bump cryptography from 42.0.4 to 43.0.1 (#368)8e1f521Fix for CVE-2024-33664. JWE limited to 250K (#352)c9403b5Bump cryptography from 41.0.3 to 42.0.4 (#358)58e543eBump cryptography from 39.0.1 to 41.0.350d1997Disabling test build for Python 3.7 on OS X since arm64 is no longer supporte...1967754Addingget_pem_for_keyandnormalize_pemmethods to normalize PEM formatt...Updates
python-multipartfrom 0.0.6 to 0.0.22Release notes
Sourced from python-multipart's releases.
... (truncated)
Changelog
Sourced from python-multipart's changelog.
... (truncated)
Commits
bea7bbbVersion 0.0.22 (#222)0fb59a9chore: add return type on test (#221)9433f4bMerge commit from forkd5c91ecBump the github-actions group with 2 updates (#219)5a90631bump uv (#218)1f72955Version 0.0.21 (#217)47ecfedAdd support for Python 3.14 and drop EOL 3.8 and 3.9 (#216)f18b709Bump the github-actions group across 1 directory with 4 updates (#214)b388e9achore: use depedency-groups inpyproject.toml(#212)6113e75Bump the github-actions group across 1 directory with 3 updates (#210)Updates
azure-identityfrom 1.15.0 to 1.16.1Commits
05f60c8Use esrp release task that supports federated auth (#35523)4699efbpin setuptools (#35212)6a07fc9[Identity] Fix device code tests (#35846)e16a704[Identity] Add Azure Arc key validation checksf07513c[DI] Enable to run sphinx in pipeline (#35078)dba02d4bump tcgc to 0.23.1 (#35119)828e833[ACR] Fix pylint and sphinx errors (#35080)9fa8967[core] Update perf-tests.yml (#35105)ca8ac49update to 0.23.0 (#35110)3519fdfDistro 1.4.0 (#35076)Updates
langchainfrom 0.1.5 to 0.3.0.dev1Release notes
Sourced from langchain's releases.
Commits
933f4abbump core dep in langchain42d8b36core: release 0.3.0.dev2 (#26120)4200876Merge branch 'v0.3rc' into v0.3/dev_releases5bbd536core[patch]: call RunnableConfigurableFields.model_rebuild() (#26118)f3b12f8vbump langchaine02b093community[patch]: Fix more issues (#26116)522203cMerge branch 'v0.3/dev_releases' of github.com:langchain-ai/langchain into v0...c492b7dvbump8c4a52apoetry0cc6584community[patch]: Resolve more linting issues (#26115)Updates
langchain-communityfrom 0.0.17 to 0.3.27Release notes
Sourced from langchain-community's releases.
Commits
Updates
pypdffrom 4.0.1 to 6.9.2Release notes
Sourced from pypdf's releases.
... (truncated)
Changelog
Sourced from pypdf's changelog.
... (truncated)
Commits
da867f4REL: 6.9.202b1345SEC: Avoid infinite loop in read_from_stream for broken files (#3693)3bef339MAINT: Prefer bytearray over bytes in image_inline (#3692)04b0a38ROB: Resolve UnboundLocalError for xobjs in _get_image (#3684)0e5157cREL: 6.9.10b5d05dSEC: Improve performance and limit length of array-based content streams (#3686)87aa1d4DEV: Remove unused reverse encoding dicts (#3685)84f5266MAINT: Use placeholder-based approach for logger_error (#3673)8f1f4aaREL: 6.9.05a9a0daBUG: Avoid sharing array-based content streams between pages (#3681)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.