Bump the prod-dependencies group across 1 directory with 3 updates - #100
Open
dependabot[bot] wants to merge 2 commits into
Open
Bump the prod-dependencies group across 1 directory with 3 updates#100dependabot[bot] wants to merge 2 commits into
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps the prod-dependencies group with 3 updates in the / directory: [faker](https://github.com/joke2k/faker), [pyrefly](https://github.com/facebook/pyrefly) and [copier](https://github.com/copier-org/copier). Updates `faker` from 40.28.1 to 40.36.0 - [Release notes](https://github.com/joke2k/faker/releases) - [Changelog](https://github.com/joke2k/faker/blob/master/CHANGELOG.md) - [Commits](joke2k/faker@v40.28.1...v40.36.0) Updates `pyrefly` from 1.1.1 to 1.2.0 - [Release notes](https://github.com/facebook/pyrefly/releases) - [Commits](facebook/pyrefly@1.1.1...1.2.0) Updates `copier` from 9.16.0 to 9.17.1 - [Release notes](https://github.com/copier-org/copier/releases) - [Changelog](https://github.com/copier-org/copier/blob/master/CHANGELOG.md) - [Commits](copier-org/copier@v9.16.0...v9.17.1) --- updated-dependencies: - dependency-name: faker dependency-version: 40.36.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-dependencies - dependency-name: pyrefly dependency-version: 1.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-dependencies - dependency-name: copier dependency-version: 9.17.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the prod-dependencies group with 3 updates in the / directory: faker, pyrefly and copier.
Updates
fakerfrom 40.28.1 to 40.36.0Release notes
Sourced from faker's releases.
Changelog
Sourced from faker's changelog.
Commits
62d5a6aBump version: 40.35.0 → 40.36.009c254a📝 Update CHANGELOG.mdce45ebdfix(uk_UA): correct bban_format to 6 digits + 19 letters so iban() is valid (...8ad78a6Merge pull request #2434 from joke2k/joke2k-security-mdce3d3b1Add SECURITY.md to the manifest fileac535cfRevise security policy for clarity and updates4b7d4d7💄 Lint code2e83f45Bump version: 40.34.0 → 40.35.0b1caba1📝 Update CHANGELOG.md706aaca💄 Lint codeUpdates
pyreflyfrom 1.1.1 to 1.2.0Release notes
Sourced from pyrefly's releases.
... (truncated)
Commits
1933169cut 1.2.0df11f5dEnforce call-boundary consumption in productione67bc8eTransfer quantified handles to call boundaries6ba516fMove deferred call state into its boundary8888e70Scope call contexts to a lexical boundaryf8c9e7cLSP: default lspArguments to ["lsp"] when empty3f0c228Remove dead .hgignore335510dimprove Sandbox: link shortening #1063 (#4327)41094b9Keep lambda hint decomposition transactional3193b6afix behavior of init=False for pydantic.BaseModel (#4352)Updates
copierfrom 9.16.0 to 9.17.1Release notes
Sourced from copier's releases.
Changelog
Sourced from copier's changelog.
Commits
e8c85cebump: version 9.17.0 → 9.17.13f1c1a6fix: prevent code execution via Jinja finalizer by disallowing YAML tagsa5e9f3ffix: prevent code execution via Jinja sandbox escape through path and setting...cd0d3aabuild(deps): bump pymdown-extensions from 10.21.3 to 11.002e1574bump: version 9.16.0 → 9.17.07408f0dfix: prevent trust bypass via encoded URL traversalb8e2218build(deps): update dependency mypy to v2.2.0baeffdabuild(deps): update astral-sh/setup-uv action to v8.3.1c89ebf5build(deps): update dependency markdown-exec to v1.12.3fcedc44build(deps): update dependency poethepoet to v0.48.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions