Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security-updates #128

Merged
merged 23 commits into from
Jun 24, 2024
Merged

Security-updates #128

merged 23 commits into from
Jun 24, 2024

Commits on Apr 3, 2024

  1. Bump pillow from 9.3.0 to 10.3.0

    Bumps [pillow](https://github.com/python-pillow/Pillow) from 9.3.0 to 10.3.0.
    - [Release notes](https://github.com/python-pillow/Pillow/releases)
    - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
    - [Commits](python-pillow/Pillow@9.3.0...10.3.0)
    
    ---
    updated-dependencies:
    - dependency-name: pillow
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Apr 3, 2024
    Configuration menu
    Copy the full SHA
    a142805 View commit details
    Browse the repository at this point in the history

Commits on Apr 12, 2024

  1. Bump idna from 3.4 to 3.7

    Bumps [idna](https://github.com/kjd/idna) from 3.4 to 3.7.
    - [Release notes](https://github.com/kjd/idna/releases)
    - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.rst)
    - [Commits](kjd/idna@v3.4...v3.7)
    
    ---
    updated-dependencies:
    - dependency-name: idna
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Apr 12, 2024
    Configuration menu
    Copy the full SHA
    e49eb30 View commit details
    Browse the repository at this point in the history
  2. Bump dnspython from 2.2.1 to 2.6.1

    Bumps [dnspython](https://github.com/rthalley/dnspython) from 2.2.1 to 2.6.1.
    - [Release notes](https://github.com/rthalley/dnspython/releases)
    - [Changelog](https://github.com/rthalley/dnspython/blob/main/doc/whatsnew.rst)
    - [Commits](rthalley/dnspython@v2.2.1...v2.6.1)
    
    ---
    updated-dependencies:
    - dependency-name: dnspython
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Apr 12, 2024
    Configuration menu
    Copy the full SHA
    894f724 View commit details
    Browse the repository at this point in the history

Commits on Apr 15, 2024

  1. Bump sqlparse from 0.4.4 to 0.5.0

    Bumps [sqlparse](https://github.com/andialbrecht/sqlparse) from 0.4.4 to 0.5.0.
    - [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG)
    - [Commits](andialbrecht/sqlparse@0.4.4...0.5.0)
    
    ---
    updated-dependencies:
    - dependency-name: sqlparse
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Apr 15, 2024
    Configuration menu
    Copy the full SHA
    a438ba6 View commit details
    Browse the repository at this point in the history

Commits on Apr 17, 2024

  1. Bump gunicorn from 20.1.0 to 22.0.0

    Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 20.1.0 to 22.0.0.
    - [Release notes](https://github.com/benoitc/gunicorn/releases)
    - [Commits](benoitc/gunicorn@20.1.0...22.0.0)
    
    ---
    updated-dependencies:
    - dependency-name: gunicorn
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Apr 17, 2024
    Configuration menu
    Copy the full SHA
    c5af4a0 View commit details
    Browse the repository at this point in the history

Commits on Apr 18, 2024

  1. Bump aiohttp from 3.9.2 to 3.9.4

    Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.9.2 to 3.9.4.
    - [Release notes](https://github.com/aio-libs/aiohttp/releases)
    - [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
    - [Commits](aio-libs/aiohttp@v3.9.2...v3.9.4)
    
    ---
    updated-dependencies:
    - dependency-name: aiohttp
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Apr 18, 2024
    Configuration menu
    Copy the full SHA
    17608f4 View commit details
    Browse the repository at this point in the history

Commits on May 6, 2024

  1. Bump jinja2 from 3.1.3 to 3.1.4

    Bumps [jinja2](https://github.com/pallets/jinja) from 3.1.3 to 3.1.4.
    - [Release notes](https://github.com/pallets/jinja/releases)
    - [Changelog](https://github.com/pallets/jinja/blob/main/CHANGES.rst)
    - [Commits](pallets/jinja@3.1.3...3.1.4)
    
    ---
    updated-dependencies:
    - dependency-name: jinja2
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored May 6, 2024
    Configuration menu
    Copy the full SHA
    b2fa6fa View commit details
    Browse the repository at this point in the history

Commits on May 21, 2024

  1. ---

    updated-dependencies:
    - dependency-name: requests
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored May 21, 2024
    Configuration menu
    Copy the full SHA
    21a69a9 View commit details
    Browse the repository at this point in the history

Commits on Jun 6, 2024

  1. Bump tornado from 6.3.3 to 6.4.1

    Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.3.3 to 6.4.1.
    - [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst)
    - [Commits](tornadoweb/tornado@v6.3.3...v6.4.1)
    
    ---
    updated-dependencies:
    - dependency-name: tornado
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Jun 6, 2024
    Configuration menu
    Copy the full SHA
    bd9915c View commit details
    Browse the repository at this point in the history

Commits on Jun 18, 2024

  1. Bump urllib3 from 1.26.18 to 1.26.19

    Bumps [urllib3](https://github.com/urllib3/urllib3) from 1.26.18 to 1.26.19.
    - [Release notes](https://github.com/urllib3/urllib3/releases)
    - [Changelog](https://github.com/urllib3/urllib3/blob/1.26.19/CHANGES.rst)
    - [Commits](urllib3/urllib3@1.26.18...1.26.19)
    
    ---
    updated-dependencies:
    - dependency-name: urllib3
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    dependabot[bot] authored Jun 18, 2024
    Configuration menu
    Copy the full SHA
    08ae69a View commit details
    Browse the repository at this point in the history

Commits on Jun 24, 2024

  1. update dependencies

    devincowan committed Jun 24, 2024
    Configuration menu
    Copy the full SHA
    28266f1 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    54ae233 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    ddcf8ee View commit details
    Browse the repository at this point in the history
  4. Configuration menu
    Copy the full SHA
    0a9b61b View commit details
    Browse the repository at this point in the history
  5. Configuration menu
    Copy the full SHA
    ff6972b View commit details
    Browse the repository at this point in the history
  6. Configuration menu
    Copy the full SHA
    74a9bc5 View commit details
    Browse the repository at this point in the history
  7. Configuration menu
    Copy the full SHA
    8e33ce0 View commit details
    Browse the repository at this point in the history
  8. Configuration menu
    Copy the full SHA
    d76daca View commit details
    Browse the repository at this point in the history
  9. Configuration menu
    Copy the full SHA
    39741fb View commit details
    Browse the repository at this point in the history
  10. Configuration menu
    Copy the full SHA
    b0bd15f View commit details
    Browse the repository at this point in the history
  11. Configuration menu
    Copy the full SHA
    0efd5f5 View commit details
    Browse the repository at this point in the history
  12. Configuration menu
    Copy the full SHA
    f0503c9 View commit details
    Browse the repository at this point in the history
  13. Revert "Merge branch 'dependabot/pip/pillow-10.3.0' into security-upd…

    …ates"
    
    This reverts commit 0efd5f5, reversing
    changes made to b0bd15f.
    devincowan committed Jun 24, 2024
    Configuration menu
    Copy the full SHA
    3b9a8d0 View commit details
    Browse the repository at this point in the history