build(deps): bump the pip group across 1 directory with 10 updates - #3922
Open
dependabot[bot] wants to merge 1 commit into
Open
build(deps): bump the pip group across 1 directory with 10 updates#3922dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the pip group with 10 updates in the /requirements directory: | Package | From | To | | --- | --- | --- | | [pycti](https://github.com/OpenCTI-Platform/opencti) | `6.8.8` | `6.9.7` | | [django](https://github.com/django/django) | `4.2.27` | `5.2.16` | | [authlib](https://github.com/authlib/authlib) | `1.6.5` | `1.6.12` | | [daphne](https://github.com/django/daphne) | `4.2.1` | `4.2.2` | | [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.41` | `3.1.58` | | [pillow](https://github.com/python-pillow/Pillow) | `11.0.0` | `12.3.0` | | [pyzipper](https://github.com/danifus/pyzipper) | `0.3.6` | `0.4.0` | | [langchain](https://github.com/langchain-ai/langchain) | `0.3.30` | `1.3.9` | | [deepdiff](https://github.com/qlustered/deepdiff) | `8.6.1` | `8.6.2` | | [lxml](https://github.com/lxml/lxml) | `6.0.2` | `6.1.0` | Updates `pycti` from 6.8.8 to 6.9.7 - [Release notes](https://github.com/OpenCTI-Platform/opencti/releases) - [Commits](OpenCTI-Platform/opencti@6.8.8...6.9.7) Updates `django` from 4.2.27 to 5.2.16 - [Commits](django/django@4.2.27...5.2.16) Updates `authlib` from 1.6.5 to 1.6.12 - [Release notes](https://github.com/authlib/authlib/releases) - [Changelog](https://github.com/authlib/authlib/blob/1.6.12/docs/changelog.rst) - [Commits](authlib/authlib@v1.6.5...1.6.12) Updates `daphne` from 4.2.1 to 4.2.2 - [Changelog](https://github.com/django/daphne/blob/main/CHANGELOG.txt) - [Commits](django/daphne@4.2.1...4.2.2) Updates `gitpython` from 3.1.41 to 3.1.58 - [Release notes](https://github.com/gitpython-developers/GitPython/releases) - [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES) - [Commits](gitpython-developers/GitPython@3.1.41...3.1.58) Updates `pillow` from 11.0.0 to 12.3.0 - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@11.0.0...12.3.0) Updates `pyzipper` from 0.3.6 to 0.4.0 - [Changelog](https://github.com/danifus/pyzipper/blob/master/HISTORY.rst) - [Commits](danifus/pyzipper@v0.3.6...v0.4.0) Updates `langchain` from 0.3.30 to 1.3.9 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain==0.3.30...langchain==1.3.9) Updates `deepdiff` from 8.6.1 to 8.6.2 - [Release notes](https://github.com/qlustered/deepdiff/releases) - [Changelog](https://github.com/qlustered/deepdiff/blob/master/CHANGELOG.md) - [Commits](qlustered/deepdiff@8.6.1...8.6.2) Updates `lxml` from 6.0.2 to 6.1.0 - [Release notes](https://github.com/lxml/lxml/releases) - [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt) - [Commits](lxml/lxml@lxml-6.0.2...lxml-6.1.0) --- updated-dependencies: - dependency-name: pycti dependency-version: 6.9.7 dependency-type: direct:production dependency-group: pip - dependency-name: django dependency-version: 5.2.16 dependency-type: direct:production dependency-group: pip - dependency-name: authlib dependency-version: 1.6.12 dependency-type: direct:production dependency-group: pip - dependency-name: daphne dependency-version: 4.2.2 dependency-type: direct:production dependency-group: pip - dependency-name: gitpython dependency-version: 3.1.58 dependency-type: direct:production dependency-group: pip - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production dependency-group: pip - dependency-name: pyzipper dependency-version: 0.4.0 dependency-type: direct:production dependency-group: pip - dependency-name: langchain dependency-version: 1.3.9 dependency-type: direct:production dependency-group: pip - dependency-name: deepdiff dependency-version: 8.6.2 dependency-type: direct:production dependency-group: pip - dependency-name: lxml dependency-version: 6.1.0 dependency-type: direct:production dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the pip group with 10 updates in the /requirements directory:
6.8.86.9.74.2.275.2.161.6.51.6.124.2.14.2.23.1.413.1.5811.0.012.3.00.3.60.4.00.3.301.3.98.6.18.6.26.0.26.1.0Updates
pyctifrom 6.8.8 to 6.9.7Release notes
Sourced from pycti's releases.
... (truncated)
Commits
97ca75e[backend/worker] Release 6.9.79485636[backend] Implement new inference rules (#13990, #11383, #10505)e2a540b[backend/client] Support multiple files upload at creation of entities (#13975)2cb4539[backend] Allow escape function in safeEjs for Simple Mailer templates (#13753)b21a404[client/backend/frontend] Upload file at creation of entities instead of afte...c69df32[frontend] Remove unused Interval parameter from bookmark widget configuratio...2db4102[frontend] Fix Form Intakes Toggle field ignoring defaultValue on initializat...d9dab7c[backend] Add missing securityCoverage resolver for Campaign entities (#13970)0412c91[backend] Fix AI Insights Containers Digest returning Markdown instead of HTM...a384a2f[deps] Update dependency uuid to v13 (#12783)Updates
djangofrom 4.2.27 to 5.2.16Commits
6c8eee4[5.2.x] Bumped version for 5.2.16 release.d5d60ed[5.2.x] Fixed CVE-2026-53878 -- Prevented newlines from being accepted in Dom...6c66eb8[5.2.x] Fixed CVE-2026-53877 -- Prevented heap buffer over-read when creating...721685a[5.2.x] Fixed CVE-2026-48588 -- Prevented caching of responses that set cooki...61a829d[5.2.x] Added stub release notes and release date 5.2.16.21af510[5.2.x] Avoided breaking sha1sum verification in the generated checksum.txt f...039df55[5.2.x] Replaced the defunct pgp.mit.edu keyserver with GitHub for key import.2b3093f[5.2.x] Fixed #29187 -- Fixed flaky receiver count assertion in signals tests.4abc595[5.2.x] Refs #16281 -- Fixed isolation of admin_views.ViewOnSiteTests.f87add9[5.2.x] Added CVE-2026-6873, CVE-2026-7666, CVE-2026-8404, CVE-2026-35193, an...Updates
authlibfrom 1.6.5 to 1.6.12Release notes
Sourced from authlib's releases.
Changelog
Sourced from authlib's changelog.
... (truncated)
Commits
e46e515chore: bump to 1.6.129babc13fix: redirecting to unvalidated redirect_uri on InvalidScopeError in OIDC grants0dc0e5bchore: bump to 1.6.11aa7b8e4Merge commit from fork401a770fix: CSRF issue with starlette clientef09aebchore: release 1.6.103be0846fix: redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError9266eaachore: release 1.6.9b9bb2b2fix(oidc): fail close at validating c_hash and at_hash1b0a1d9fix(jose): generate random cek when cek length doesn't matchUpdates
daphnefrom 4.2.1 to 4.2.2Changelog
Sourced from daphne's changelog.
Commits
c19f2f4Bumped version for v4.2.2 release.32f8be0Fixed CVE-2026-44545: Limit WebSocket sizes in autobahn config.2628b7bFixed CVE-2026-44546: Prevent header injection on WebSocket upgrade pathfef65a7Added .DS_Store files to .gitignore.8b56967Bump actions/setup-python from 5 to 6 (#569)032c560Bump actions/checkout from 4 to 5 (#564)cb23638[pre-commit.ci] pre-commit autoupdate (#563)Updates
gitpythonfrom 3.1.41 to 3.1.58Release notes
Sourced from gitpython's releases.
... (truncated)
Commits
30be45dprepare changelog for upcoming releasefc2f02cMerge pull request #2197 from Cyrus580529/shared-symlink-guardb10e250test: use the shared guard instead of local copiese3e5da8test: skip tests that need symlink privileges30d05e3test: add a shared symlink capability guard9a8f6feMerge pull request #2204 from gitpython-developers/security-fixesf2550b6Guard pathspec file inputs in high-level commandsd9ddb55Guard unsafe git init options9b5dcafGuard read-tree index output paths96a888fCheck joined short-option values before Git executionUpdates
pillowfrom 11.0.0 to 12.3.0Release notes
Sourced from pillow's releases.
... (truncated)
Changelog
Sourced from pillow's changelog.
Commits
bb1d8e812.3.0 version bumpe63fc48Add release notes for SBOM and performance improvements (#9747)13b701bAdd release notes for #96795564ca7List methodsa0920fdSpeed up ImageChops operations (#9738)07e9a6cSpeed upImage.filter()(#9736)a94578cSpeed upImage.getchannel(),Image.merge(),Image.putalpha()and `Image...53e02c4Speed upImage.fill(),Image.linear_gradient()and `Image.radial_gradient...af03747Speed upImage.resample()(#9739)5c9ca56Speed upalpha_composite,matrix,negative,quantize(#9740)Updates
pyzipperfrom 0.3.6 to 0.4.0Changelog
Sourced from pyzipper's changelog.
Commits
a814388Merge commit from fork6836583Update test to loop through all compression methods4c23f26Update README to include information about the CRC bug9d2a95cFix README.rst block quote43b001bUpdate HISTORY.rst and versionbf7a6bdAdd SECURITY.rst85ce9a5Update README.rst with CRC information93ce88eRemove CRC32 values from file entries for small files (CVE-2026-44722)919e199Merge pull request #42 from danifus/update20260561d3529Quote python versions in github workflow to fix 3.10Updates
langchainfrom 0.3.30 to 1.3.9Release notes
Sourced from langchain's releases.
... (truncated)
Commits
3bfb6a3release(langchain): 1.3.9 (#38104)dcaf779fix(langchain,anthropic): confine file-search results and tighten anthropic `...0392b6bfix(core): fix Pydantic v1 support in tools/runnable (#33698)f6d63bcrelease(langchain): 1.3.8 (#38096)5d20596style(core,langchain,langchain-classic,partners): replace double backticks in...fb55c66chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/huggingface (#38...51daae5chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/chroma (#38092)70e9579chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (#38093)6c0e9afchore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/xai (#38094)222dc84ci(infra): clarify early PR auto-close guidance (#38090)Updates
deepdifffrom 8.6.1 to 8.6.2Release notes
Sourced from deepdiff's releases.
Commits
0d07ec2Merge commit from fork791f5aaupdating CVE numbera6aafeaupdating docsa0950abBump version: 8.6.1 → 8.6.2887128aFix (CVE-2025-58367)Updates
lxmlfrom 6.0.2 to 6.1.0Changelog
Sourced from lxml's changelog.
... (truncated)
Commits
43722f4Update changelog.8747040Name version of option change in docstring.6c36e6cFix pypistats URL in download statistics script.c7d76d6Change security policy to point to Github security advisories.378ccf8Update project income report.315270bDocs: Reduce TOC depth of package pages and move module contents first.6dbba7fDocs: Show current year in copyright line.e4385bfUpdate project income report.5bed1e1Validate file hashes in release download script.c13ee10Prepare release of 6.1.0.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.