chore(deps): bump the python-packages group with 5 updates
Type: Pull Request
State: Merged
Association: Contributor
Comments: 0
(12 months ago)
(11 months ago)
(11 months ago)
by josegonzalez
dependencies python
Bumps the python-packages group with 5 updates:
| Package | From | To |
|---|---|---|
| flake8 | 7.2.0 |
7.3.0 |
| pycodestyle | 2.13.0 |
2.14.0 |
| pyflakes | 3.3.2 |
3.4.0 |
| pygments | 2.19.1 |
2.19.2 |
| urllib3 | 2.4.0 |
2.5.0 |
Updates flake8 from 7.2.0 to 7.3.0
Commits
c48217eRelease 7.3.0f9e0f33Merge pull request #1986 from PyCQA/document-f5426bcdb62document F54270a15b8Merge pull request #1985 from PyCQA/upgrade-deps4941a3eupgrade pyflakes / pycodestyle23e4005Merge pull request #1983 from PyCQA/py314019424badd support for t-strings6b6f3d5Merge pull request #1980 from PyCQA/asottile-patch-18dfa669add rtd sphinx configce34111Merge pull request #1976 from PyCQA/document-f824- Additional commits viewable in compare view
Updates pycodestyle from 2.13.0 to 2.14.0
Commits
814a0d1Release 2.14.08621e31fix false positive with TypeVar defaults with more than one argument292cdd0Merge pull request #1285 from PyCQA/sphinx-config46bc333add sphinx configuration for rtfda986384[pre-commit.ci] pre-commit autoupdatec85e740Merge pull request #1283 from PyCQA/py314ae41b34updates for python 3.1434fc7f0Merge pull request #1280 from PyCQA/pre-commit-ci-update-config7182ac8[pre-commit.ci] auto fixes from pre-commit.com hooks1845a92[pre-commit.ci] pre-commit autoupdate- See full diff in compare view
Updates pyflakes from 3.3.2 to 3.4.0
Changelog
Sourced from pyflakes's changelog.
3.4.0 (2025-06-20)
- Add support for python 3.14
- Add "t-string is missing placeholders" error
- Fix annotation erroneously causing a name to be defined with
from __future__ import annotations- Add support for always-deferred annotations (PEP 749)
Commits
59ec459Release 3.4.0e5d4ba1updates for python 3.14 (#842)- See full diff in compare view
Updates pygments from 2.19.1 to 2.19.2
Commits
cfca62ePrepare v2.19.2 release.6688300Disable pyodide (currently broken.)66997c3Update ruff version.94dda77Update CHANGES.26634c8Merge pull request #2882 from thavelick/fix_lua_runaway_regexb6a51ecfix lua regex causing runaway backtracking.edef94dInvestigation for #2839.fb6a00eMerge pull request #2837 from dlazin/sql-cleanupbf7aa23Clean up sql.py- See full diff in compare view
Updates urllib3 from 2.4.0 to 2.5.0
Release notes
Sourced from urllib3's releases.
2.5.0
๐ urllib3 is fundraising for HTTP/2 support
urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.
Thank you for your support.
Security issues
urllib3 2.5.0 fixes two moderate security issues:
- Pool managers now properly control redirects when
retriesis passed โ CVE-2025-50181 reported by@โsandumjacob(5.3 Medium, GHSA-pq67-6m6q-mj2v)- Redirects are now controlled by urllib3 in the Node.js runtime โ CVE-2025-50182 (5.3 Medium, GHSA-48p4-8xcf-vxj5)
Features
- Added support for the
compression.zstdmodule that is new in Python 3.14. See PEP 784 for more information. (#3610)- Added support for version 0.5 of
hatch-vcs(#3612)Bugfixes
Changelog
Sourced from urllib3's changelog.
2.5.0 (2025-06-18)
Features
- Added support for the
compression.zstdmodule that is new in Python 3.14. SeePEP 784 <https://peps.python.org/pep-0784/>_ for more information. ([#3610](https://github.com/urllib3/urllib3/issues/3610) <https://github.com/urllib3/urllib3/issues/3610>__)- Added support for version 0.5 of
hatch-vcs([#3612](https://github.com/urllib3/urllib3/issues/3612) <https://github.com/urllib3/urllib3/issues/3612>__)Bugfixes
- Fixed a security issue where restricting the maximum number of followed redirects at the
urllib3.PoolManagerlevel via theretriesparameter did not work.- Made the Node.js runtime respect redirect parameters such as
retriesandredirects.- Raised exception for
HTTPResponse.shutdownon a connection already released to the pool. ([#3581](https://github.com/urllib3/urllib3/issues/3581) <https://github.com/urllib3/urllib3/issues/3581>__)- Fixed incorrect
CONNECTstatement when using an IPv6 proxy withconnection_from_host. Previously would not be wrapped in[]. ([#3615](https://github.com/urllib3/urllib3/issues/3615) <https://github.com/urllib3/urllib3/issues/3615>__)
Commits
aaab4ecRelease 2.5.07eb4a2aMerge commit from forkf05b132Merge commit from forkd03fe32Fix HTTP tunneling with IPv6 in older Python versions11661e9Bump github/codeql-action from 3.28.0 to 3.29.0 (#3624)6a0ecc6Update v2 migration guide to 2.4.0 (#3621)8e32e60Raise exception for shutdown on a connection already released to the pool (#3...9996e0fFix emscripten CI for Chrome 137+ (#3599)4fd1a99Bump RECENT_DATE (#3617)c4b5917Add support for the newcompression.zstdmodule in Python 3.14 (#3611)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
Pull Request Statistics
1
1
+5
-5
Package Dependencies
Security Advisories
urllib3 does not control redirects in browsers and Node.js
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Technical Details
| ID: | 2540611 |
| UUID: | 2612155739 |
| Node ID: | PR_kwDOB4w7nM6bslVb |
| Host: | GitHub |
| Repository: | josegonzalez/python-gitlab-backup |
| Merge State: | Unknown |