Bump the python-security-updates group across 1 directory with 16 updates - #624
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…ates Bumps the python-security-updates group with 16 updates in the / directory: | Package | From | To | | --- | --- | --- | | [lxml](https://github.com/lxml/lxml) | `5.3.1` | `6.1.0` | | [black](https://github.com/psf/black) | `25.1.0` | `26.3.1` | | [poetry](https://github.com/python-poetry/poetry) | `2.0.1` | `2.3.4` | | [requests](https://github.com/psf/requests) | `2.32.3` | `2.33.0` | | [bleach](https://github.com/mozilla/bleach) | `6.2.0` | `6.4.0` | | [dulwich](https://github.com/dulwich/dulwich) | `0.22.7` | `1.2.15` | | [filelock](https://github.com/tox-dev/py-filelock) | `3.17.0` | `3.20.3` | | [fonttools](https://github.com/fonttools/fonttools) | `4.56.0` | `4.60.2` | | [idna](https://github.com/kjd/idna) | `3.10` | `3.15` | | [jinja2](https://github.com/pallets/jinja) | `3.1.5` | `3.1.6` | | [lxml-html-clean](https://github.com/fedora-python/lxml_html_clean) | `0.4.1` | `0.4.4` | | [mistune](https://github.com/lepture/mistune) | `2.0.5` | `3.3.3` | | [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.1` | | [pygments](https://github.com/pygments/pygments) | `2.19.1` | `2.20.0` | | [urllib3](https://github.com/urllib3/urllib3) | `2.3.0` | `2.7.0` | | [virtualenv](https://github.com/pypa/virtualenv) | `20.29.2` | `20.36.1` | Updates `lxml` from 5.3.1 to 6.1.0 - [Release notes](https://github.com/lxml/lxml/releases) - [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt) - [Commits](lxml/lxml@lxml-5.3.1...lxml-6.1.0) Updates `black` from 25.1.0 to 26.3.1 - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@25.1.0...26.3.1) Updates `poetry` from 2.0.1 to 2.3.4 - [Release notes](https://github.com/python-poetry/poetry/releases) - [Changelog](https://github.com/python-poetry/poetry/blob/main/CHANGELOG.md) - [Commits](python-poetry/poetry@2.0.1...2.3.4) Updates `requests` from 2.32.3 to 2.33.0 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.3...v2.33.0) Updates `bleach` from 6.2.0 to 6.4.0 - [Changelog](https://github.com/mozilla/bleach/blob/main/CHANGES) - [Commits](mozilla/bleach@v6.2.0...v6.4.0) Updates `dulwich` from 0.22.7 to 1.2.15 - [Release notes](https://github.com/dulwich/dulwich/releases) - [Changelog](https://github.com/jelmer/dulwich/blob/main/NEWS) - [Commits](jelmer/dulwich@dulwich-0.22.7...dulwich-1.2.15) Updates `filelock` from 3.17.0 to 3.20.3 - [Release notes](https://github.com/tox-dev/py-filelock/releases) - [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst) - [Commits](tox-dev/filelock@3.17.0...3.20.3) Updates `fonttools` from 4.56.0 to 4.60.2 - [Release notes](https://github.com/fonttools/fonttools/releases) - [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst) - [Commits](fonttools/fonttools@4.56.0...4.60.2) Updates `idna` from 3.10 to 3.15 - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md) - [Commits](kjd/idna@v3.10...v3.15) Updates `jinja2` from 3.1.5 to 3.1.6 - [Release notes](https://github.com/pallets/jinja/releases) - [Changelog](https://github.com/pallets/jinja/blob/main/CHANGES.rst) - [Commits](pallets/jinja@3.1.5...3.1.6) Updates `lxml-html-clean` from 0.4.1 to 0.4.4 - [Changelog](https://github.com/fedora-python/lxml_html_clean/blob/main/CHANGES.rst) - [Commits](fedora-python/lxml_html_clean@0.4.1...0.4.4) Updates `mistune` from 2.0.5 to 3.3.3 - [Release notes](https://github.com/lepture/mistune/releases) - [Changelog](https://github.com/lepture/mistune/blob/main/docs/changes.rst) - [Commits](lepture/mistune@v2.0.5...v3.3.3) Updates `msgpack` from 1.1.0 to 1.2.1 - [Release notes](https://github.com/msgpack/msgpack-python/releases) - [Changelog](https://github.com/msgpack/msgpack-python/blob/main/CHANGELOG.md) - [Commits](msgpack/msgpack-python@v1.1.0...v1.2.1) Updates `pygments` from 2.19.1 to 2.20.0 - [Release notes](https://github.com/pygments/pygments/releases) - [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES) - [Commits](pygments/pygments@2.19.1...2.20.0) Updates `urllib3` from 2.3.0 to 2.7.0 - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.3.0...2.7.0) Updates `virtualenv` from 20.29.2 to 20.36.1 - [Release notes](https://github.com/pypa/virtualenv/releases) - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst) - [Commits](pypa/virtualenv@20.29.2...20.36.1) --- updated-dependencies: - dependency-name: lxml dependency-version: 6.1.0 dependency-type: direct:production dependency-group: python-security-updates - dependency-name: black dependency-version: 26.3.1 dependency-type: direct:development dependency-group: python-security-updates - dependency-name: poetry dependency-version: 2.3.4 dependency-type: direct:development dependency-group: python-security-updates - dependency-name: requests dependency-version: 2.33.0 dependency-type: direct:development dependency-group: python-security-updates - dependency-name: bleach dependency-version: 6.4.0 dependency-type: indirect dependency-group: python-security-updates - dependency-name: dulwich dependency-version: 1.2.15 dependency-type: indirect dependency-group: python-security-updates - dependency-name: filelock dependency-version: 3.20.3 dependency-type: indirect dependency-group: python-security-updates - dependency-name: fonttools dependency-version: 4.60.2 dependency-type: indirect dependency-group: python-security-updates - dependency-name: idna dependency-version: '3.15' dependency-type: indirect dependency-group: python-security-updates - dependency-name: jinja2 dependency-version: 3.1.6 dependency-type: indirect dependency-group: python-security-updates - dependency-name: lxml-html-clean dependency-version: 0.4.4 dependency-type: indirect dependency-group: python-security-updates - dependency-name: mistune dependency-version: 3.3.3 dependency-type: indirect dependency-group: python-security-updates - dependency-name: msgpack dependency-version: 1.2.1 dependency-type: indirect dependency-group: python-security-updates - dependency-name: pygments dependency-version: 2.20.0 dependency-type: indirect dependency-group: python-security-updates - dependency-name: urllib3 dependency-version: 2.7.0 dependency-type: indirect dependency-group: python-security-updates - dependency-name: virtualenv dependency-version: 20.36.1 dependency-type: indirect dependency-group: python-security-updates ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/pip/python-security-updates-17ae4d8831
branch
September 19, 2026 21:24
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-security-updates group with 16 updates in the / directory:
5.3.16.1.025.1.026.3.12.0.12.3.42.32.32.33.06.2.06.4.00.22.71.2.153.17.03.20.34.56.04.60.23.103.153.1.53.1.60.4.10.4.42.0.53.3.31.1.01.2.12.19.12.20.02.3.02.7.020.29.220.36.1Updates
lxmlfrom 5.3.1 to 6.1.0Release notes
Sourced from lxml's releases.
Changelog
Sourced from lxml's changelog.
... (truncated)
Commits
43722f4Update changelog.8747040Name version of option change in docstring.6c36e6cFix pypistats URL in download statistics script.c7d76d6Change security policy to point to Github security advisories.378ccf8Update project income report.315270bDocs: Reduce TOC depth of package pages and move module contents first.6dbba7fDocs: Show current year in copyright line.e4385bfUpdate project income report.5bed1e1Validate file hashes in release download script.c13ee10Prepare release of 6.1.0.Updates
blackfrom 25.1.0 to 26.3.1Release notes
Sourced from black's releases.
... (truncated)
Changelog
Sourced from black's changelog.
... (truncated)
Commits
c6755bbPrepare release 26.3.1 (#5046)69973fdHarden blackd browser-facing request handling (#5039)4937fe6Fix some shenanigans with the cache file and IPython (#5038)2e641d1docs: remove outdated Black Playground references (#5044)c014b22Remove unused internal code (#5041)0dae20bAdd new changelog (#5036)c5c1cbdMinor release patches (#5035)7e5a828docs: clarify relationship between Black style and PEP 8 (#5025)69705dedocs: add clearer pyproject configuration guidance (#5026)35ea679Prepare release 26.3.0 (#5032)Updates
poetryfrom 2.0.1 to 2.3.4Release notes
Sourced from poetry's releases.
... (truncated)
Changelog
Sourced from poetry's changelog.
... (truncated)
Commits
7c7af71release: bump version to 2.3.4e512e7ffix: refuse to write files outside the target directory during sdist extracti...506c09dperf: useos.path.abspath()instead ofPath.resolve()(#10821)3d0151arelease: bump version to 2.3.389f09aafix long path issue on Windows (#10794)e068177installer: fix path traversal (#10792)d76a2f6chore: require new poetry-core version (#10790)859d443Update init & new commands for PEP 639 (License) (#10787)2ff2845fix: pass auth via Request constructor instead of calling HTTPBasicAuth on un...286e43benv: improve error handling if.venvis not a directory but a file (#10777)Updates
requestsfrom 2.32.3 to 2.33.0Release notes
Sourced from requests's releases.
... (truncated)
Changelog
Sourced from requests's changelog.
... (truncated)
Commits
bc04dfdv2.33.066d21cbMerge commit from fork8b9bc8fMove badges to top of README (#7293)e331a28Remove unused extraction call (#7292)753fd08docs: fix FAQ grammar in httplib2 example774a0b8docs(socks): same block as other sections9c72a41Bump github/codeql-action from 4.33.0 to 4.34.1ebf7190Bump github/codeql-action from 4.32.0 to 4.33.00e4ae38docs: exclude Response.is_permanent_redirect from API docs (#7244)d568f47docs: clarify Quickstart POST example (#6960)Updates
bleachfrom 6.2.0 to 6.4.0Changelog
Sourced from bleach's changelog.
... (truncated)
Commits
f0355a7fix: fix last release date in CHANGESae4e8a2chore: bleach 6.4.0 and final release970df58fix: uri-sanitization in formaction attributes7c4867cfix: xss bypass in allowed protocol test using unicode invisible characters913ab75fix: reduce redundancy in workflow jobs218c15afix: rework pip caching4f0b097fix: fix tox platform restrictionse95a79dchore: update pytest91539d4Bump actions/cache from 5.0.3 to 5.0.4cd47b4cfix: handle left-angle-bracket that's not a tag (#733)Updates
dulwichfrom 0.22.7 to 1.2.15Release notes
Sourced from dulwich's releases.
... (truncated)
Changelog
Sourced from dulwich's changelog.
... (truncated)
Commits
b84b2adRelease 1.2.15ee235e8Memoize tag peeling on the object store (#2407)7fe797bMemoize tag peeling on the object storef6fc1b3protocol: Avoid quadratic cost in PktLineParser.parse (#2410)60660d2protocol: Avoid quadratic cost in PktLineParser.parsee0952f9More gitignore matching improvements (#2409)fa2d6daMatch ignore patterns by entry name and type, as git does43d67ebShare one ignore decision path between filter and managercb0d914Name the directory re-inclusion checks in ignore matchingfa1a579Keep a directory excluded by name against a "!dir/**/" negationUpdates
filelockfrom 3.17.0 to 3.20.3Release notes
Sourced from filelock's releases.
... (truncated)
Changelog
Sourced from filelock's changelog.
... (truncated)
Commits
41b42ddFix TOCTOU symlink vulnerability in SoftFileLock (#465)f2e7d40[pre-commit.ci] pre-commit autoupdate (#464)5088854Support Unix systems without O_NOFOLLOW (#463)377f622[pre-commit.ci] pre-commit autoupdate (#460)4724d7fFix TOCTOU symlink vulnerability in lock file creation (#461)cb69414Bump actions/upload-artifact from 5 to 6 (#459)0769294Bump actions/download-artifact from 6 to 7 (#458)414193a[pre-commit.ci] pre-commit autoupdate (#457)1456797[pre-commit.ci] pre-commit autoupdate (#456)8d6bf90Bump actions/checkout from 5 to 6 (#455)Updates
fonttoolsfrom 4.56.0 to 4.60.2Release notes
Sourced from fonttools's releases.