Bump the pip group across 7 directories with 5 updates #3067
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the pip group with 1 update in the /integrations/bbot directory: bbot.
Bumps the pip group with 1 update in the /integrations/malware_tools_analyzers/requirements directory: flask.
Bumps the pip group with 1 update in the /integrations/nuclei_analyzer directory: flask.
Bumps the pip group with 1 update in the /integrations/pcap_analyzers directory: flask.
Bumps the pip group with 1 update in the /integrations/thug directory: flask.
Bumps the pip group with 1 update in the /integrations/tor_analyzers directory: flask.
Bumps the pip group with 3 updates in the /requirements directory: django, authlib and deepdiff.
Updates
bbotfrom 2.4.0 to 2.7.0Changelog
Sourced from bbot's changelog.
Commits
Updates
flaskfrom 3.1.0 to 3.1.1Release notes
Sourced from flask's releases.
Changelog
Sourced from flask's changelog.
Commits
7fff56frelease version 3.1.173d6504Merge commit from forkcbb6c36update docs about fallback orderfb54159secret key rotation: fix key list ordering941efd4use uv (#5727)0109e49use uve785166Async Iterable Response (#5659)410e5abAcceptAsyncIterablefor responsesbfffe87add ghsa links73ce26cremove tests about deprecated pkgutil.get_loader (#5702)Updates
flaskfrom 3.1.0 to 3.1.1Release notes
Sourced from flask's releases.
Changelog
Sourced from flask's changelog.
Commits
7fff56frelease version 3.1.173d6504Merge commit from forkcbb6c36update docs about fallback orderfb54159secret key rotation: fix key list ordering941efd4use uv (#5727)0109e49use uve785166Async Iterable Response (#5659)410e5abAcceptAsyncIterablefor responsesbfffe87add ghsa links73ce26cremove tests about deprecated pkgutil.get_loader (#5702)Updates
flaskfrom 3.1.0 to 3.1.1Release notes
Sourced from flask's releases.
Changelog
Sourced from flask's changelog.
Commits
7fff56frelease version 3.1.173d6504Merge commit from forkcbb6c36update docs about fallback orderfb54159secret key rotation: fix key list ordering941efd4use uv (#5727)0109e49use uve785166Async Iterable Response (#5659)410e5abAcceptAsyncIterablefor responsesbfffe87add ghsa links73ce26cremove tests about deprecated pkgutil.get_loader (#5702)Updates
flaskfrom 3.1.0 to 3.1.1Release notes
Sourced from flask's releases.
Changelog
Sourced from flask's changelog.
Commits
7fff56frelease version 3.1.173d6504Merge commit from forkcbb6c36update docs about fallback orderfb54159secret key rotation: fix key list ordering941efd4use uv (#5727)0109e49use uve785166Async Iterable Response (#5659)410e5abAcceptAsyncIterablefor responsesbfffe87add ghsa links73ce26cremove tests about deprecated pkgutil.get_loader (#5702)Updates
flaskfrom 3.1.0 to 3.1.1Release notes
Sourced from flask's releases.
Changelog
Sourced from flask's changelog.
Commits
7fff56frelease version 3.1.173d6504Merge commit from forkcbb6c36update docs about fallback orderfb54159secret key rotation: fix key list ordering941efd4use uv (#5727)0109e49use uve785166Async Iterable Response (#5659)410e5abAcceptAsyncIterablefor responsesbfffe87add ghsa links73ce26cremove tests about deprecated pkgutil.get_loader (#5702)Updates
djangofrom 4.2.17 to 4.2.26Commits
0dfd59e[4.2.x] Bumped version for 4.2.26 release.279f8b9[4.2.x] Refs CVE-2025-64459 -- Avoided propagating invalid arguments to Q on ...59ae82e[4.2.x] Fixed CVE-2025-64459 -- Prevented SQL injections in Q/QuerySet via th...770eea3[4.2.x] Fixed CVE-2025-64458 -- Mitigated potential DoS in HttpResponseRedire...80976bd[4.2.x] Skipped test_compressed_file_based_raster_creation() test on GDAL 3.5+.7838add[4.2.x] Fixed RelatedGeoModelTest.test_related_union_aggregate() crash on Pyt...1b50da7[4.2.x] Added stub release notes and release date for 4.2.26.cd3b21b[4.2.x] Made RemoteTestResultTest.test_pickle_errors_detection() compatible w...321af48[4.2.x] Fixed RelatedGeoModelTest.test_related_union_aggregate() test on Orac...0f6ee3e[4.2.x] Rewrapped security archive at 79 chars.Updates
authlibfrom 1.4.0 to 1.6.5Release notes
Sourced from authlib's releases.
... (truncated)
Changelog
Sourced from authlib's changelog.
... (truncated)
Commits
9ec4256chore: release 1.6.5b62b5b2Merge branch 'fix-GHSA-pq5p-34cr-23v9'e0863d5Merge pull request #830 from authlib/fix-GHSA-g7f3-828f-7h7m867e3f8fix(jose): add size limitation to prevent DoS75ad6d4Merge pull request #828 from authlib/dependabot/github_actions/dot-github/wor...68b9823chore(deps): bump SonarSource/sonarqube-scan-action5bdfc4bMerge pull request #827 from lisongmin/support-list-params-in-prepare-grant-uri30ea3c5feat: support list params in prepare_grant_uri4b5b570fix(jose): add max size for JWE zip=DEF decompression6e35a02Merge pull request #825 from azmeuk/request-paramsUpdates
deepdifffrom 8.2.0 to 8.6.1Release notes
Sourced from deepdiff's releases.
Commits
60ac5b9Merge commit from fork683756eBump version: 8.6.0 → 8.6.1 and add security vulnerability notesc69c06cSecurity fix: Prevent class pollution and remote code execution in Deltab639fecupdating the docs6f3d5eeBump version: 8.5.0 → 8.6.0388a60eMerge pull request #557 from seperman/dev0978fb8adding docs for 8.6.0d469a4cmaking type hints compatible with old pythone16507cfixing type hints33de087adding type hints to searchDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.