Skip to content

Bump the ci-constraints group across 1 directory with 20 updates - #66

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/ci/ci-constraints-645aacce14
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/ci/ci-constraints-645aacce14

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the ci-constraints group with 20 updates in the /ci directory:

Package From To
charset-normalizer 3.4.9 3.5.1
cyclonedx-python-lib 11.11.0 11.12.0
filelock 3.32.2 4.0.3
idna 3.18 3.20
msgpack 1.2.1 1.2.2
pip-api 0.0.34 0.0.35
platformdirs 4.11.0 4.11.13
pygments 2.20.0 2.21.0
pyparsing 3.3.2 3.3.3
urllib3 2.7.0 2.8.0
flake8 7.3.0 7.4.1
flake8-bugbear 25.11.29 26.9.9
pycodestyle 2.14.0 2.15.0
pyflakes 3.4.0 4.0.0
setuptools 83.0.0 84.0.0
imagesize 2.0.0 2.0.1
soupsieve 2.9.2 2.10
webencodings 0.5.1 0.6.1
coverage 7.15.4 7.16.1
wheel 0.47.0 0.48.0

Updates charset-normalizer from 3.4.9 to 3.5.1

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.1

3.5.1 (2026-08-15)

Changed

  • Raised upper bound of setuptools to v84 (#794)
  • Cache performance access optimization for our CharInfo struct (prebuilt only).

Fixed

  • No longer decoding large content when the noise detector output give a high entropy. Only impacted large content input >1M bytes.

Version 3.5.0

3.5.0 (2026-08-12)

Added

  • Explicit support for Python 3.15

Fixed

  • Comparing a CharsetMatch to a non-alias encoding strings (#773)
  • Return 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (#774)
  • A file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.
  • iso2022* cases misdetected due to a flaw in our multibyte chunking logic.

Changed

  • Replaced the optional mypyc build with Cython extensions while retaining the pure Python fallback. The previous engine (mypyc) started to hit rough limit around the optimization of our noise/coherence detector while Cython allows us to steer the engine toward the right generated optimized sources. This change SHOULD not impact bundler (e.g. Pyinstaller) as the module are immediately discoverable (i.e. not hidden import like mypyc did). Moreover, a long wished distribution is the abi3 wheels, this will allow us to no longer rush each year when a new Python interpreter is released. We still distribute the interpreter specific wheels for faster performance.
  • Applied micro-optimization on several utils.
  • CharsetMatches no longer sort on each match insertion.

Misc

  • Removed an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).
Changelog

Sourced from charset-normalizer's changelog.

3.5.1 (2026-08-15)

Changed

  • Raised upper bound of setuptools to v84 (#794)
  • Cache performance access optimization for our CharInfo struct (prebuilt only).

Fixed

  • No longer decoding large content when the noise detector output give a high entropy. Only impacted large content input >1M bytes.

3.5.0 (2026-08-12)

Added

  • Explicit support for Python 3.15

Fixed

  • Comparing a CharsetMatch to a non-alias encoding strings (#773)
  • Return 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (#774)
  • A file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.
  • iso2022* cases misdetected due to a flaw in our multibyte chunking logic.

Changed

  • Replaced the optional mypyc build with Cython extensions while retaining the pure Python fallback. The previous engine (mypyc) started to hit rough limit around the optimization of our noise/coherence detector while Cython allows us to steer the engine toward the right generated optimized sources. This change SHOULD not impact bundler (e.g. Pyinstaller) as the module are immediately discoverable (i.e. not hidden import like mypyc did). Moreover, a long wished distribution is the abi3 wheels, this will allow us to no longer rush each year when a new Python interpreter is released. We still distribute the interpreter specific wheels for faster performance.
  • Applied micro-optimization on several utils.
  • CharsetMatches no longer sort on each match insertion.

Misc

  • Removed an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).
Commits
  • e239bdc Merge pull request #795 from jawah/release-3.5.1
  • 648ad77 docs: update faq
  • fab2749 docs: write changelog for 3.5.1
  • 7d32774 chore: bump version to 3.5.1
  • 9a69f60 docs: update data/info
  • 5dcc6dd perf: charinfo cache access optimization in cython
  • ea3b447 fix: do not validate-decode large payload when md says it's noise
  • a05917f chore: allow setuptools 84 builds (#794)
  • 3325d87 Merge pull request #792 from jawah/update-cibuildwheel-action
  • 77203b1 chore: reformat noxfile.py
  • Additional commits viewable in compare view

Updates cyclonedx-python-lib from 11.11.0 to 11.12.0

Release notes

Sourced from cyclonedx-python-lib's releases.

v11.12.0 (2026-08-13)

Features

  • Add isExternal property to Component for CycloneDX v1.7 (#959, 6993dea)

What's Changed

New Contributors

Full Changelog: CycloneDX/cyclonedx-python-lib@v11.11.2...v11.12.0

v11.11.2 (2026-08-12)

Bug Fixes


What's Changed

New Contributors

Full Changelog: CycloneDX/cyclonedx-python-lib@v11.11.1...v11.11.2

v11.11.1 (2026-08-10)

Bug Fixes


What's Changed

... (truncated)

Changelog

Sourced from cyclonedx-python-lib's changelog.

v11.12.0 (2026-08-13)

Features

  • Add isExternal property to Component for CycloneDX v1.7 (#959, 6993dea)

v11.11.2 (2026-08-12)

Bug Fixes

v11.11.1 (2026-08-10)

Bug Fixes

Commits
  • 52cb3c9 chore(release): 11.12.0
  • 6993dea feat: add isExternal property to Component for CycloneDX v1.7 (#959)
  • 27b2d43 tests: add Python 3.14 to tox tests (#1029)
  • a092c49 chore(release): 11.11.2
  • 17a0136 fix: encode paths when loading XML schemas (#1028)
  • 8edee5c chore(release): 11.11.1
  • 7b5350c chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#1026)
  • 72e4e4c chore(deps): bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 (#1027)
  • d718ac2 fix: ComparablePackageURL includes name (#1022)
  • cb1a4e2 chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#1019)
  • Additional commits viewable in compare view

Updates filelock from 3.32.2 to 4.0.3

Release notes

Sourced from filelock's releases.

4.0.3

What's Changed

Full Changelog: tox-dev/filelock@4.0.2...4.0.3

4.0.2

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.1...4.0.2

4.0.1

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.0...4.0.1

4.0.0

What's Changed

Full Changelog: tox-dev/filelock@3.32.7...4.0.0

3.32.7

What's Changed

... (truncated)

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754
  • Reject negative timeouts other than -1 in blocking AsyncReadWriteLock and AsyncSoftReadWriteLock acquisitions. Keep -1 as an unlimited wait and ignore timeouts when blocking=False. :pr:755

4.0.4 (2026-09-26)


  • Hostnames that still differ after their first 253 escaped characters now publish distinct owners, so a soft lock no longer takes another such host's live holder for its own and reclaims its marker. :pr:748

4.0.3 (2026-09-23)


  • Importing filelock on CPython 3.10 or 3.11 no longer makes new threads fail with RuntimeError: Cannot install a trace function while another trace function is being installed under coverage or a debugger. filelock skips its fork-safety audit hook there, so forking from inside a thread's own lock-state transition no longer raises immediately on those versions. :pr:747

4.0.2 (2026-09-23)


  • Concurrent acquire() and release() on a thread_local=False lock no longer leak the OS lock, close a descriptor twice, drop a lease token, or leave a false deadlock after a cross-thread release (:issue:744). :pr:745
  • :class:~filelock.AsyncReadWriteLock and :class:~filelock.AsyncSoftReadWriteLock now give each asyncio task its own hold, so tasks sharing one instance no longer enter the write lock together. :pr:746
  • Correct the async cache example to create its data directory and clarify automatic creation of lock-file parent directories. :pr:740
  • Exclude sphinx-llm 1.1.0 from documentation dependencies because its Markdown builder emits unknown-node warnings. :pr:742

... (truncated)

Commits
  • 5283806 Release 4.0.3
  • fd10e07 🐛 fix(api): skip the fork audit hook on CPython <3.12 (#747)
  • 2d4530f Release 4.0.2
  • 6c46312 🐛 fix(async-rw): give each task its own hold (#746)
  • fe0e99d 🐛 fix(api): serialize concurrent transitions on shared locks (#745)
  • b26beda build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the github-acti...
  • 10572ec fix: ignore broken sphinx-llm release (#742)
  • 6c10af3 [pre-commit.ci] pre-commit autoupdate (#741)
  • 9380408 docs: create the data directory in the async cache example (#740)
  • b5016c4 Release 4.0.1
  • Additional commits viewable in compare view

Updates idna from 3.18 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.

v3.19

  • Restore the std3_rules option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that uts46_remap() defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.
  • Performance improvements to UTS #46 mapping, particularly for ASCII-only domains.
  • Test on free-threaded CPython with the GIL disabled and document thread safety.
  • Expose the Unicode version of the generated tables as idna.unicode_version, and show it in idna --version.
  • Add code, text, codepoint and position attributes to IDNAError so that the failed rule and the offending character can be identified without parsing the exception message.
  • The deprecated transitional argument to encode() and uts46_remap() is now completely ignored, and gives a deprecation warning for the latter.
  • Reject A-labels that are not the canonical Punycode encoding of their U-label.
  • Fix CONTEXTJ violations raising IDNAError instead of InvalidCodepointContext.
  • Consistently raise IDNAError for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.
  • Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.
  • Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.

Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.

3.19 (2026-08-18)

  • Restore the std3_rules option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that uts46_remap() defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again.
  • Performance improvements to UTS #46 mapping, particularly for ASCII-only domains.
  • Test on free-threaded CPython with the GIL disabled and document thread safety.
  • Expose the Unicode version of the generated tables as idna.unicode_version, and show it in idna --version.
  • Add code, text, codepoint and position attributes to IDNAError so that the failed rule and the offending character can be identified without parsing the exception message.
  • The deprecated transitional argument to encode() and uts46_remap() is now completely ignored, and gives a deprecation warning for the latter.
  • Reject A-labels that are not the canonical Punycode encoding of their U-label.
  • Fix CONTEXTJ violations raising IDNAError instead of InvalidCodepointContext.
  • Consistently raise IDNAError for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec.
  • Add property-based tests, extended fuzzing targets, coverage measurement, and CI checks that the data tables match the generator output.
  • Various code quality and tooling improvements.

Thanks to stefan6419846, LouieLuNZ, and Salvatore Corvaglia for contributions to this release.

Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates msgpack from 1.2.1 to 1.2.2

Release notes

Sourced from msgpack's releases.

v1.2.2

What's Changed

New Contributors

Full Changelog: msgpack/msgpack-python@v1.2.1...v1.2.2

Changelog

Sourced from msgpack's changelog.

1.2.2

Release Date: 2026-08-27

  • Fix the read_size documentation. #700
  • Fix silent truncation when unpacking an out-of-range timestamp with timestamp=3. #701
  • Prevent reentrant calls to Unpacker.feed() while unpacking. #704
  • Improve error handling and reporting in unpacking functions. #707
  • Fix Timestamp.from_datetime() precision for far-future datetimes. #710
  • Fix typos in the documentation. #712
  • Validate the nanoseconds range when unpacking timestamps in the C extension. #716
  • Fix a use-after-free in the unpackb() ExtraData path for non-contiguous input. #722
  • Prevent a buffer overflow when converting Packer's buf_size. #726
  • Translate RecursionError to StackError in the fallback Unpacker.skip(). #727
  • Raise OverflowError when use_single_float=True cannot represent a value. #728
Commits
  • 7381b31 release
  • ee1bd3c release v1.2.2 (#730)
  • 57d28a2 Raise OverflowError when use_single_float cannot represent a value (#728)
  • d374a17 Avoid parallel execution of the recursion-limit nesting test on free-threaded...
  • e94e1dc Validate nanoseconds range when unpacking timestamps in the C extension (#716)
  • 2e4be09 fix: translate RecursionError to StackError in fallback Unpacker.skip() (#727)
  • 9f9bdae Convert Packer's buf_size once (#726)
  • 809bfcd remove unused variable
  • 186d4db Bump pypa/cibuildwheel from 4.1.1 to 4.2.0(#724)
  • ea6b84f Bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 in the all-dependencie...
  • Additional commits viewable in compare view

Updates pip-api from 0.0.34 to 0.0.35

Release notes

Sourced from pip-api's releases.

0.0.35

What's Changed

Full Changelog: di/pip-api@0.0.34...0.0.35

Changelog

Sourced from pip-api's changelog.

0.0.35

Commits
  • 539f428 Update CHANGELOG (#299)
  • 8582df7 Prepare 0.0.35 release metadata (#298)
  • 51d317b Add Python 3.15 prerelease support (#296)
  • 1361fa5 Add tox factor support for pip 26.2.1 (#293)
  • dce99b7 Bump sigstore/gh-action-sigstore-python from 3.4.0 to 3.5.0 in the actions gr...
  • ba40af7 Add pip 26.2 to tox env matrix and move latest label (#289)
  • 209ad72 Bump actions/setup-python from 6 to 7 in the actions group (#287)
  • 4684261 Bump actions/checkout from 6 to 7 in the actions group (#286)
  • adcdf82 Bump sigstore/gh-action-sigstore-python from 3.3.0 to 3.4.0 in the actions gr...
  • d243983 Add pip 26.1.2 to the tox/CI compatibility matrix (#284)
  • Additional commits viewable in compare view

Updates platformdirs from 4.11.0 to 4.11.13

Release notes

Sourced from platformdirs's releases.

4.11.13

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.12...4.11.13

4.11.12

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.11.11...4.11.12

4.11.11

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.11.10...4.11.11

4.11.10

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.9...4.11.10

4.11.9

What's Changed

... (truncated)

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600
  • Document that a Homebrew Python puts the Homebrew prefix first in the macOS shared directories, with or without multipath. :pr:591
  • Document that the macOS media directories honor the XDG_*_DIR variables. :pr:592
  • Document the WIN_PD_OVERRIDE_COMMON_PROGRAMS variable. :pr:593
  • Document /usr/local/share/applications as the Linux site_applications_dir default. :pr:594
  • Correct the BSD user_runtime_dir defaults and describe the temporary directory fallback. :pr:595
  • Describe how platformdirs detects Android, finds the app folder and places the shared folders. :pr:596
  • Document that Microsoft Store Python redirects only new files and folders under AppData. :pr:597
  • Show how to load a font on Windows after copying it into user_fonts_dir. :pr:598

4.11.15 (2026-09-26)


  • Fix the pyjnius lookup of the Android app folder and media directories, which always failed. :pr:580

... (truncated)

Commits
  • 9ce6068 Release 4.11.13
  • 4440e9f 🐛 fix(dirs): create media dirs when ensure_exists is set (#560)
  • 6d28702 build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the all group (...
  • 0975949 Release 4.11.12
  • f0f5667 fix: ignore relative XDG user directory environment variables (#554)
  • 1f944d0 fix: ignore broken sphinx-llm release (#556)
  • 3e2e590 [pre-commit.ci] pre-commit autoupdate (#555)
  • 897097b docs: preserve nested directories in the migration recipe (#553)
  • 321e35a Release 4.11.11
  • 902c268 fix: reject app arguments that leave the base directory (#552)
  • Additional commits viewable in compare view

Updates pygments from 2.20.0 to 2.21.0

Release notes

Sourced from pygments's releases.

2.21.0

  • New lexers:

  • Updated lexers:

    • Bash: Fix coloured keyword at the beginning of a name (#2926)
    • Boogie: Add missing Boogie and Civl Verifier keywords (#3156)
    • C#:
      • Recognize interpolated verbatim strings with either $@ or @$ prefixes (#2685)
      • Support dollar-prefixed and multi-quote raw strings (#3129, #2897)
      • Recognize union (#3182)
    • C/C++:
      • Add C23/C++26 attributes (#3084)
      • Add more C2Y keywords (#3092)
      • Highlight a function following a namespace body (#2928)
      • Fix C/C++ lexer support for multiline pre-processor comments (#3051)
      • Add .ipp as a file extension (#3141, #1008)
    • Clojure: Recognize named, octal and unicode character literals such as \space and \o377 as a single token (#979)
    • Csound: Add missing opcode parameter type letter (#3161)
    • CUDA: Derive from the C++ lexer instead of C to highlight C++ constructs such as template, class and namespace (#3127)
    • D: Allow non-ASCII (Unicode) identifiers (#1088)
    • Fish: Fix single quote backslash escape (#3138, #2821)
    • Go: Various lexer improvements (#3199)
    • GoogleSQL: Require a word break after SET (#3167)
    • Hexdump: Only match valid digits (#3200, <...

      Description has been truncated

Bumps the ci-constraints group with 20 updates in the /ci directory:

| Package | From | To |
| --- | --- | --- |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.1` |
| [cyclonedx-python-lib](https://github.com/CycloneDX/cyclonedx-python-lib) | `11.11.0` | `11.12.0` |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.2` | `4.0.3` |
| [idna](https://github.com/kjd/idna) | `3.18` | `3.20` |
| [msgpack](https://github.com/msgpack/msgpack-python) | `1.2.1` | `1.2.2` |
| [pip-api](https://github.com/di/pip-api) | `0.0.34` | `0.0.35` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.0` | `4.11.13` |
| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |
| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.3.2` | `3.3.3` |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |
| [flake8](https://github.com/pycqa/flake8) | `7.3.0` | `7.4.1` |
| [flake8-bugbear](https://github.com/PyCQA/flake8-bugbear) | `25.11.29` | `26.9.9` |
| [pycodestyle](https://github.com/PyCQA/pycodestyle) | `2.14.0` | `2.15.0` |
| [pyflakes](https://github.com/PyCQA/pyflakes) | `3.4.0` | `4.0.0` |
| [setuptools](https://github.com/pypa/setuptools) | `83.0.0` | `84.0.0` |
| [imagesize](https://github.com/shibukawa/imagesize_py) | `2.0.0` | `2.0.1` |
| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.9.2` | `2.10` |
| [webencodings](https://github.com/CourtBouillon/webencodings) | `0.5.1` | `0.6.1` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.15.4` | `7.16.1` |
| [wheel](https://github.com/pypa/wheel) | `0.47.0` | `0.48.0` |



Updates `charset-normalizer` from 3.4.9 to 3.5.1
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.4.9...3.5.1)

Updates `cyclonedx-python-lib` from 11.11.0 to 11.12.0
- [Release notes](https://github.com/CycloneDX/cyclonedx-python-lib/releases)
- [Changelog](https://github.com/CycloneDX/cyclonedx-python-lib/blob/main/CHANGELOG.md)
- [Commits](CycloneDX/cyclonedx-python-lib@v11.11.0...v11.12.0)

Updates `filelock` from 3.32.2 to 4.0.3
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.2...4.0.3)

Updates `idna` from 3.18 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.18...v3.20)

Updates `msgpack` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/msgpack/msgpack-python/releases)
- [Changelog](https://github.com/msgpack/msgpack-python/blob/main/CHANGELOG.md)
- [Commits](msgpack/msgpack-python@v1.2.1...v1.2.2)

Updates `pip-api` from 0.0.34 to 0.0.35
- [Release notes](https://github.com/di/pip-api/releases)
- [Changelog](https://github.com/di/pip-api/blob/master/CHANGELOG)
- [Commits](di/pip-api@0.0.34...0.0.35)

Updates `platformdirs` from 4.11.0 to 4.11.13
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.0...4.11.13)

Updates `pygments` from 2.20.0 to 2.21.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.20.0...2.21.0)

Updates `pyparsing` from 3.3.2 to 3.3.3
- [Release notes](https://github.com/pyparsing/pyparsing/releases)
- [Changelog](https://github.com/pyparsing/pyparsing/blob/master/CHANGES)
- [Commits](pyparsing/pyparsing@3.3.2...3.3.3)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

Updates `flake8` from 7.3.0 to 7.4.1
- [Commits](PyCQA/flake8@7.3.0...7.4.1)

Updates `flake8-bugbear` from 25.11.29 to 26.9.9
- [Release notes](https://github.com/PyCQA/flake8-bugbear/releases)
- [Commits](PyCQA/flake8-bugbear@25.11.29...26.9.9)

Updates `pycodestyle` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/PyCQA/pycodestyle/releases)
- [Changelog](https://github.com/PyCQA/pycodestyle/blob/main/CHANGES.txt)
- [Commits](PyCQA/pycodestyle@2.14.0...2.15.0)

Updates `pyflakes` from 3.4.0 to 4.0.0
- [Changelog](https://github.com/PyCQA/pyflakes/blob/main/NEWS.rst)
- [Commits](PyCQA/pyflakes@3.4.0...4.0.0)

Updates `setuptools` from 83.0.0 to 84.0.0
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](pypa/setuptools@v83.0.0...v84.0.0)

Updates `imagesize` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/shibukawa/imagesize_py/releases)
- [Commits](shibukawa/imagesize_py@2.0.0...2.0.1)

Updates `soupsieve` from 2.9.2 to 2.10
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.9.2...2.10)

Updates `webencodings` from 0.5.1 to 0.6.1
- [Release notes](https://github.com/CourtBouillon/webencodings/releases)
- [Changelog](https://github.com/CourtBouillon/webencodings/blob/main/docs/changelog.rst)
- [Commits](CourtBouillon/webencodings@v0.5.1...v0.6.1)

Updates `coverage` from 7.15.4 to 7.16.1
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.15.4...7.16.1)

Updates `wheel` from 0.47.0 to 0.48.0
- [Release notes](https://github.com/pypa/wheel/releases)
- [Changelog](https://github.com/pypa/wheel/blob/main/docs/news.rst)
- [Commits](pypa/wheel@0.47.0...0.48.0)

---
updated-dependencies:
- dependency-name: charset-normalizer
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: cyclonedx-python-lib
  dependency-version: 11.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: filelock
  dependency-version: 4.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-constraints
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: msgpack
  dependency-version: 1.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-constraints
- dependency-name: pip-api
  dependency-version: 0.0.35
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-constraints
- dependency-name: platformdirs
  dependency-version: 4.11.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-constraints
- dependency-name: pygments
  dependency-version: 2.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: pyparsing
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-constraints
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: flake8
  dependency-version: 7.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: flake8-bugbear
  dependency-version: 26.9.9
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-constraints
- dependency-name: pycodestyle
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: pyflakes
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-constraints
- dependency-name: setuptools
  dependency-version: 84.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-constraints
- dependency-name: imagesize
  dependency-version: 2.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-constraints
- dependency-name: soupsieve
  dependency-version: '2.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: webencodings
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: coverage
  dependency-version: 7.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
- dependency-name: wheel
  dependency-version: 0.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-constraints
...

Signed-off-by: dependabot[bot] <support@github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants