build(deps): bump the dependencies group with 3 updates
Type: Pull Request
State: Open
Association: Contributor
Comments: 1
(about 1 year ago)
(about 1 year ago)
dependencies python
Bumps the dependencies group with 3 updates: cryptography, coverage[toml] and freezegun.
Updates cryptography from 45.0.2 to 45.0.3
Changelog
Sourced from cryptography's changelog.
45.0.3 - 2025-05-25
* Fixed decrypting PKCS#8 files encrypted with long salts (this impacts keys encrypted by Bouncy Castle). * Fixed decrypting PKCS#8 files encrypted with DES-CBC-MD5. While wildly insecure, this remains prevalent... _v45-0-2:
Commits
5038495backports for 45.0.3 release (#12979)- See full diff in compare view
Updates coverage[toml] from 7.8.0 to 7.8.2
Release notes
Sourced from coverage[toml]'s releases.
7.8.2
Version 7.8.2 — 2025-05-23
- Wheels are provided for Windows ARM64 on Python 3.11, 3.12, and 3.13. Thanks, Finn Womack.
:arrow_right: PyPI page: coverage 7.8.2. :arrow_right: To install:
python3 -m pip install coverage==7.8.27.8.1
Version 7.8.1 — 2025-05-21
- A number of EncodingWarnings were fixed that could appear if you’ve enabled PYTHONWARNDEFAULTENCODING, fixing issue 1966. Thanks, Henry Schreiner.
- Fixed a race condition when using sys.monitoring with free-threading Python, closing issue 1970.
:arrow_right: PyPI page: coverage 7.8.1. :arrow_right: To install:
python3 -m pip install coverage==7.8.1
Changelog
Sourced from coverage[toml]'s changelog.
Version 7.8.2 — 2025-05-23
- Wheels are provided for Windows ARM64 on Python 3.11, 3.12, and 3.13. Thanks,
Finn Womack <pull 1972_>_... _issue 1971: nedbat/coveragepy#1971 .. _pull 1972: nedbat/coveragepy#1972
.. _changes_7-8-1:
Version 7.8.1 — 2025-05-21
A number of EncodingWarnings were fixed that could appear if you've enabled PYTHONWARNDEFAULTENCODING, fixing
issue 1966. Thanks,Henry Schreiner <pull 1967_>.Fixed a race condition when using sys.monitoring with free-threading Python, closing
issue 1970_... _issue 1966: nedbat/coveragepy#1966 .. _pull 1967: nedbat/coveragepy#1967 .. _issue 1970: nedbat/coveragepy#1970
.. _changes_7-8-0:
Commits
51ab2e5build: have to keep expected dist counts in syncbe7bbf2docs: sample HTML for 7.8.23cee850docs: prep for 7.8.239bc6b0docs: provide more details if the kit matrix is edited.a608fb3build: add support for Windows arm64 (#1972)2fe6225build: runtox lintif actions have changed3d93a78docs: docs need scriv for making github releases0c443a2build: bump version to 7.8.2ed98b87docs: sample HTML for 7.8.1b98bc9bdocs: prep for 7.8.1- Additional commits viewable in compare view
Updates freezegun from 1.5.1 to 1.5.2
Changelog
Sourced from freezegun's changelog.
1.5.2
- Remove support for Python 3.7
- Explicitly marks support for Python 3.13
- Improved project documentation
Commits
ba06fa4Increase version numberda2885dMerge pull request #572 from jayaddison/debian-bug-1106274/tests-datetime-tod...695aa15Merge branch 'master' into debian-bug-1106274/tests-datetime-today-tz-localiz...132ecdbMerge pull request #573 from spulec/admin/indicate-py-13-compatf9235aeMark support for Python 3.139072d08Merge pull request #544 from spulec/remove-py-37-support74a6914Merge pull request #565 from joethesaint/improve-documentation1343509README: update example code for consistency with tests9468f70Tests: fixup: replacedatetime.todaymethod calls withdatetime.dateclas...9e4012aTests: restore somedatetime.date-based comparisons- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions
Pull Request Statistics
0
0
+0
-0
Package Dependencies
Technical Details
| ID: | 667207 |
| UUID: | 3092104003 |
| Node ID: | PR_kwDOAHkylc6Xr6tj |
| Host: | GitHub |
| Repository: | theupdateframework/python-tuf |