Bump the all-pip-updates group across 3 directories with 15 updates#69447
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the all-pip-updates group across 3 directories with 15 updates#69447dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [pip](https://github.com/pypa/pip), [cryptography](https://github.com/pyca/cryptography), [pyopenssl](https://github.com/pyca/pyopenssl), [tornado](https://github.com/tornadoweb/tornado), [urllib3](https://github.com/urllib3/urllib3), [virtualenv](https://github.com/pypa/virtualenv), [filelock](https://github.com/tox-dev/py-filelock), [pylint](https://github.com/pylint-dev/pylint), [boto3](https://github.com/boto/boto3), [botocore](https://github.com/boto/botocore), [pynacl](https://github.com/pyca/pynacl), [vcert](https://github.com/Venafi/vcert-python), [xmldiff](https://github.com/Shoobx/xmldiff), [pygit2](https://github.com/libgit2/pygit2) and [python-telegram-bot](https://github.com/python-telegram-bot/python-telegram-bot) to permit the latest version. Updates `pip` from 25.2 to 26.0.1 - [Changelog](https://github.com/pypa/pip/blob/main/NEWS.rst) - [Commits](pypa/pip@25.2...26.0.1) Updates `cryptography` to 49.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.7...49.0.0) Updates `pyopenssl` to 26.3.0 - [Changelog](https://github.com/pyca/pyopenssl/blob/main/CHANGELOG.rst) - [Commits](pyca/pyopenssl@26.2.0...26.3.0) Updates `tornado` to 6.5.7 - [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst) - [Commits](tornadoweb/tornado@v6.5.6...v6.5.7) Updates `urllib3` to 2.6.3 - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@1.26.20...2.6.3) Updates `virtualenv` to 21.5.0 - [Release notes](https://github.com/pypa/virtualenv/releases) - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst) - [Commits](pypa/virtualenv@21.4.2...21.5.0) Updates `cryptography` to 49.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.7...49.0.0) Updates `virtualenv` to 21.5.0 - [Release notes](https://github.com/pypa/virtualenv/releases) - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst) - [Commits](pypa/virtualenv@21.4.2...21.5.0) Updates `filelock` to 3.29.4 - [Release notes](https://github.com/tox-dev/py-filelock/releases) - [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst) - [Commits](tox-dev/filelock@3.29.1...3.29.4) Updates `pylint` to 4.0.5 - [Release notes](https://github.com/pylint-dev/pylint/releases) - [Commits](pylint-dev/pylint@v3.1.0...v4.0.5) Updates `boto3` to 1.43.29 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.43.24...1.43.29) Updates `botocore` to 1.43.29 - [Commits](boto/botocore@1.43.24...1.43.29) Updates `pynacl` to 1.6.2 - [Changelog](https://github.com/pyca/pynacl/blob/main/CHANGELOG.rst) - [Commits](pyca/pynacl@1.5.0...1.6.2) Updates `vcert` to 0.18.1 - [Release notes](https://github.com/Venafi/vcert-python/releases) - [Commits](Venafi/vcert-python@v0.9.0...v0.18.1) Updates `xmldiff` to 3.0 - [Release notes](https://github.com/Shoobx/xmldiff/releases) - [Changelog](https://github.com/Shoobx/xmldiff/blob/master/CHANGES.rst) - [Commits](Shoobx/xmldiff@2.7.0...3.0) Updates `pygit2` to 1.19.3 - [Release notes](https://github.com/libgit2/pygit2/releases) - [Changelog](https://github.com/libgit2/pygit2/blob/master/CHANGELOG.md) - [Commits](libgit2/pygit2@v1.19.2...v1.19.3) Updates `python-telegram-bot` to 22.8 - [Release notes](https://github.com/python-telegram-bot/python-telegram-bot/releases) - [Commits](python-telegram-bot/python-telegram-bot@v22.7...v22.8) Updates `cryptography` to 49.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.7...49.0.0) Updates `pyopenssl` from 26.2.0 to 26.3.0 - [Changelog](https://github.com/pyca/pyopenssl/blob/main/CHANGELOG.rst) - [Commits](pyca/pyopenssl@26.2.0...26.3.0) Updates `tornado` from 6.5.6 to 6.5.7 - [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst) - [Commits](tornadoweb/tornado@v6.5.6...v6.5.7) --- updated-dependencies: - dependency-name: pip dependency-version: 26.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-pip-updates - dependency-name: cryptography dependency-version: 49.0.0 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: pyopenssl dependency-version: 26.3.0 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: tornado dependency-version: 6.5.7 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: urllib3 dependency-version: 2.6.3 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: virtualenv dependency-version: 21.5.0 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: cryptography dependency-version: 49.0.0 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: virtualenv dependency-version: 21.5.0 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: filelock dependency-version: 3.29.4 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: pylint dependency-version: 4.0.5 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: boto3 dependency-version: 1.43.29 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: botocore dependency-version: 1.43.29 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: pynacl dependency-version: 1.6.2 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: vcert dependency-version: 0.18.1 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: xmldiff dependency-version: '3.0' dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: pygit2 dependency-version: 1.19.3 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: python-telegram-bot dependency-version: '22.8' dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: cryptography dependency-version: 49.0.0 dependency-type: direct:production dependency-group: all-pip-updates - dependency-name: pyopenssl dependency-version: 26.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-pip-updates - dependency-name: tornado dependency-version: 6.5.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-pip-updates ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Warning
Dependabot will stop supporting
python v3.9!Please upgrade to one of the following versions:
v3.9,v3.10,v3.11,v3.12,v3.13, orv3.14.Updates the requirements on pip, cryptography, pyopenssl, tornado, urllib3, virtualenv, filelock, pylint, boto3, botocore, pynacl, vcert, xmldiff, pygit2 and python-telegram-bot to permit the latest version.
Updates
pipfrom 25.2 to 26.0.1Changelog
Sourced from pip's changelog.
... (truncated)
Commits
5fe4ea4Bump for releasebea3cbewindows fix testsed22252News Entryaf13274Match release control behavior to the same as format control behavior2f4d4a8Merge pull request #13779 from notatallshaw/fix-26.0-news04307a4fix 26.0 news6ec7b0aMerge pull request #13775 from notatallshaw/release/26.04104356Bump for release58be883Update AUTHORS.txt66f2decMerge pull request #13778 from ichard26/docs/groupsUpdates
cryptographyto 49.0.0Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
e300bbebump version and changelog for 49.0.0 (#15030)fa74cd8Add external mu (message representative) support for ML-DSA (#14979)f594db3chore(deps): bump openssl from 0.10.80 to 0.10.81 (#15029)608e011chore(deps): bump openssl-sys from 0.9.116 to 0.9.117 (#15028)a322bc4chore(deps): bump cc from 1.2.63 to 1.2.64 (#15027)33181a7Reject critical nameConstraints extensions containing directoryName constrain...6080dc7Bump dependencies that dependabot isn't (#15026)121faa3chore(deps): bump virtualenv from 21.4.2 to 21.4.3 (#15023)829520bAdd more robust processing for DH parameters. (#15016)0f05001Bump downstream dependencies in CI (#15025)Updates
pyopensslto 26.3.0Changelog
Sourced from pyopenssl's changelog.
... (truncated)
Commits
a34aa1dPrepare 26.3.0 release (#1515)24db880Deprecate X509Name and the remaining APIs that consume or return it (#1514)1dc08beAdd as_cryptography parameter to Connection.get_client_ca_list (#1508)55653a5Require cryptography 49, drop Python 3.8 (#1513)9bad760Remove deprecated CSR functionality (#1507)98ca874Enforce that Session is only re-used with the Context it came from (#1512)cbcb1daDeprecate Context.set_passwd_cb (#1511)3b9d07dDeprecate all the mutable APIs on X509 (#1510)e096920Deprecate PKey.generate_key, PKey.check, and dump_privatekey (#1509)7079d6dFix zizmor findings in GitHub Actions workflows (#1506)Updates
tornadoto 6.5.7Changelog
Sourced from tornado's changelog.
... (truncated)
Commits
48fc2d4Merge pull request #3633 from bdarnell/curl-reset-654ae1dddRelease notes and version bump for 6.5.73154caacurl_httpclient: Reset the curl object before putting it on the freelist7d869c0Merge pull request #3631 from bdarnell/cve-links288241fdocs: Use the correct link syntax8da981cdocs: Add CVE links to 6.5.6 release notesUpdates
urllib3to 2.6.3Release notes
Sourced from urllib3's releases.
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
0248277Release 2.6.38864ac4Merge commit from fork70cecb2Fix Scorecard issues related to vulnerable dev dependencies (#3755)41f249aMove "v2.0 Migration Guide" to the end of the table of contents (#3747)fd4dffdPatchVerifiedHTTPSConnectionfor Emscripten (#3752)13f0bfdHandle massive values in Retry-After when calculating time to sleep for (#3743)8c480bfBump actions/upload-artifact from 5.0.0 to 6.0.0 (#3748)4b40616Bump actions/cache from 4.3.0 to 5.0.1 (#3750)82b8479Bump actions/download-artifact from 6.0.0 to 7.0.0 (#3749)34284cbMention experimental features in the security policy (#3746)Updates
virtualenvto 21.5.0Release notes
Sourced from virtualenv's releases.
Changelog
Sourced from virtualenv's changelog.
... (truncated)
Commits
90735e0release 21.5.079ce906✨ feat: drop Python 3.8 support (#3170)f1f4d68Upgrade embedded pip/setuptools/wheel (#3168)78df6f0Set git identity in upgrade changelog rename step (#3169)134b080release 21.4.32a36128🐛 fix(discovery): resolve base interpreter executable-only symlinks (#3166)5389c25Add wheel-0.47.0 to seed packages as mitigation of CVE-2026-24049 (#3167)0134feechore(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#3165)af1ed9fchore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#3164)1b00ec8[pre-commit.ci] pre-commit autoupdate (#3163)Updates
cryptographyto 49.0.0Changelog
Sourced from cryptography's changelog.
... (truncated)
Commits
e300bbebump version and changelog for 49.0.0 (#15030)fa74cd8Add external mu (message representative) support for ML-DSA (#14979)f594db3chore(deps): bump openssl from 0.10.80 to 0.10.81 (#15029)608e011chore(deps): bump openssl-sys from 0.9.116 to 0.9.117 (#15028)a322bc4chore(deps): bump cc from 1.2.63 to 1.2.64 (#15027)33181a7Reject critical nameConstraints extensions containing directoryName constrain...6080dc7Bump dependencies that dependabot isn't (#15026)121faa3chore(deps): bump virtualenv from 21.4.2 to 21.4.3 (#15023)829520bAdd more robust processing for DH parameters. (#15016)0f05001Bump downstream dependencies in CI (#15025)Updates
virtualenvto 21.5.0Release notes
Sourced from virtualenv's releases.
Changelog
Sourced from virtualenv's changelog.
... (truncated)
Commits
90735e0release 21.5.079ce906✨ feat: drop Python 3.8 support (#3170)f1f4d68Upgrade embedded pip/setuptools/wheel (#3168)78df6f0Set git identity in upgrade changelog rename step (#3169)134b080release 21.4.32a36128🐛 fix(discovery): resolve base interpreter executable-only symlinks (#3166)5389c25Add wheel-0.47.0 to seed packages as mitigation of CVE-2026-24049 (#3167)0134feechore(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#3165)af1ed9fchore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#3164)1b00ec8[pre-commit.ci] pre-commit autoupdate (#3163)Updates
filelockto 3.29.4Release notes
Sourced from filelock's releases.
Changelog
Sourced from filelock's changelog.
... (truncated)
Commits
f3c11c0Release 3.29.45d663eekeep the read/write heartbeat alive on a transient touch error (#562)406d0a2verify inode in break_lock_file before unlinking a stale lock (#561)85e73d7🐛 fix(ci): publish from release.yaml on tag push (#560)f86dcb1Release 3.29.3643bdbe🐛 fix(ci): restore release environment on tag job (#559)7a8f74avalidate pid range in _parse_lock_holder (#556)d1d49a0🔧 ci(release): publish to PyPI on tag push (#557)b37e162build(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#558)d9216deRelease 3.29.2Updates
pylintto 4.0.5Commits
88e1ab7Bump pylint to 4.0.5, update changelog (#10860)d96d489[Backport maintenance/4.0.x] Relax isort version constraint to allow isort 8 ...0b08ccbFix dynamic color mapping for "fail-on" messages when using multiple reporter...154dba4[Backport maintenance/4.0.x] Fix FP forinvalid-namewithtyping.Finalon...7b73bfdDisable unspecified-encoding for py-version above Python 3.15 (#10800)4cc98be[Backport maintenance/4.0.x] Fix setting options for import order checker (#1...f0d30a2Sync astroid version with requirements file again38bdf02[Backport maintenance/4.0.x] Fixlogging-unsupported-formatwhen logging ...f08c33a[Backport maintenance/4.0.x] Properly detectself.fail()as a terminating...e16f942Bump pylint to 4.0.4, update changelogUpdates
boto3to 1.43.29Commits
3d3204cMerge branch 'release-1.43.29'4cc6c64Bumping version to 1.43.2973137eaAdd changelog entries from botocoreb42ee1dBump https://github.com/astral-sh/ruff-pre-commit (#4798)803cba4Merge branch 'release-1.43.28'1ed6c48Merge branch 'release-1.43.28' into develop0044dd3Bumping version to 1.43.2843e2d2aAdd changelog entries from botocore5d9ac3eMerge branch 'release-1.43.27'52b9481Merge branch 'release-1.43.27' into developUpdates
botocoreto 1.43.29Commits
77da2d8Merge branch 'release-1.43.29'564f462Bumping version to 1.43.290b96b9bUpdate endpoints modeld47197eUpdate to latest modelsbf0ad13Bump https://github.com/astral-sh/ruff-pre-commit (#3726)b3f27bfMerge branch 'release-1.43.28'72abfc3Merge branch 'release-1.43.28' into develop28cf5f1Bumping version to 1.43.28e48fcf4Update to latest models0ffcb23Merge branch 'release-1.43.27'Updates
pynaclto 1.6.2Changelog
Sourced from pynacl's changelog.
... (truncated)
Commits
ecf41f5changelog and version bump for 1.6.2 (#923)685a5e7Switch to PyPI trusted publishing (#925)78e0aa3missed adding these files as part of the libsodium update (#924)9631488Bump libsodium to the latest 1.0.20 (#922)563b25bAdd script to update vendored libsodium (#921)