deps: bump the prod-deps group across 1 directory with 13 updates #5110
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the prod-deps group with 13 updates in the / directory:
4.2.244.2.251.21.101.21.116.0.26.0.33.2.83.2.91.2.21.3.01.17.01.18.11.40.301.40.457.10.67.10.74.30.24.30.37.0.07.1.037.6.037.8.00.21.20.22.26.138.166.140.3Updates
djangofrom 4.2.24 to 4.2.25Commits
57d20b2[4.2.x] Bumped version for 4.2.25 release.9504bba[4.2.x] Fixed CVE-2025-59682 -- Fixed potential partial directory-traversal v...38d9ef8[4.2.x] Fixed CVE-2025-59681 -- Protected QuerySet.annotate(), alias(), aggre...7c7d2a4[4.2.x] Added stub release notes and release date for 4.2.25.3e27d61[4.2.x] Added missing backticks in docs/releases/security.txt.07e5fb9[4.2.x] Added CVE-2025-57833 to security archive.5636e82[4.2.x] Post-release version bump.Updates
drf-yasgfrom 1.21.10 to 1.21.11Release notes
Sourced from drf-yasg's releases.
Changelog
Sourced from drf-yasg's changelog.
... (truncated)
Commits
f8cb2dbAdd version 1.21.11 details to the changelog (#939)0c6d08dUpdate the ruff lint rules (#920)055a74dBump actions/setup-python from 5 to 6 in the github-actions group (#937)a8813acBump actions/checkout from 4 to 5 in the github-actions group (#936)9f4b449Restore the live demo and replace heroku with apprunner (#935)2983251fix list views with parameters in last path segment not named "list" views (#...a746893allow overriding produces/consumes with@swagger_auto_schema decorator (#916)e747ad6Fixes issue with filter parameters not appearing in Swagger after upgrading t...ee3c871update Python, Django, and DRF versions & packaging configuration (#922)be6eeedRemove usage of pkg_resources (#928)Updates
pyyamlfrom 6.0.2 to 6.0.3Release notes
Sourced from pyyaml's releases.
Changelog
Sourced from pyyaml's changelog.
Commits
49790e7Release 6.0.3 (#889)Updates
xlsxwriterfrom 3.2.8 to 3.2.9Changelog
Sourced from xlsxwriter's changelog.
Commits
e943beePrep for release 3.2.9392bd9etyping: remove py.typed fileUpdates
larkfrom 1.2.2 to 1.3.0Release notes
Sourced from lark's releases.
... (truncated)
Commits
e332c2dVersion bump (1.3.0)aa5666cMerge pull request #1541 from pdeibert/master41934d3Merge pull request #1553 from lark-parser/issue155223c95eaBugfix: issue when unpickling in the standalone parser, due to lingeringd1a456dMerge pull request #1547 from lark-parser/dev2e3108eUnexpectedInput.pos_in_stream now defaults to 00d248fcFix in indenter - now always creating dedents with line informationc2e2048Merge pull request #1540 from lark-parser/pr15062f286ccAdded tests for cache_grammar8a0b02dSmall fix, comments, added some typesUpdates
django-two-factor-auth[phonenumbers]from 1.17.0 to 1.18.1Release notes
Sourced from django-two-factor-auth[phonenumbers]'s releases.
Changelog
Sourced from django-two-factor-auth[phonenumbers]'s changelog.
Commits
38a6ba7Merge pull request #778 from claudep/missing_trans004c938Fixes #777 - Add missing Azerbaijani and Serbian translations59f4466Merge pull request #776 from jazzband/pre-commit-ci-update-configd551704[pre-commit.ci] pre-commit autoupdate7405b6fMerge pull request #774 from moggers87/release-1.18.0b47945cUpdate CHANGELOG with latest changesb20741cMerge branch 'master' into release-1.18.0966dab4Merge pull request #775 from claudep/phoneplugin29c72f87Refs #469 - Only import phonenumber functions when plugin is installedec0923bPull latest translations from TransifexUpdates
boto3from 1.40.30 to 1.40.45Commits
4a131a0Merge branch 'release-1.40.45'c572cacBumping version to 1.40.45584a71bAdd changelog entries from botocore61ee934Merge branch 'release-1.40.44'7b6ce2aMerge branch 'release-1.40.44' into develop01553e7Bumping version to 1.40.441b47e9eAdd changelog entries from botocorea295071Merge branch 'release-1.40.43'a349ff9Merge branch 'release-1.40.43' into develop86bb6e1Bumping version to 1.40.43Updates
coveragefrom 7.10.6 to 7.10.7Changelog
Sourced from coverage's changelog.
Commits
92a2af5docs: sample HTML for 7.10.7952afdadocs: prep for 7.10.7a301761build: riscv64 wheels (#2055)5daff8ddocs: now source is formatted with ruff04bbc3adocs: discuss cog in the contributing docsc181b93build: use cog --check-fail-msg to instruct devs33c4ba1chore: make upgrade0744b73chore: bump the action-dependencies group across 1 directory with 2 updates (...0d5a112perf: bulk narrowing to avoid N**2. #2048a868ed9docs: mention Python Discord on the index pageUpdates
toxfrom 4.30.2 to 4.30.3Release notes
Sourced from tox's releases.
Changelog
Sourced from tox's changelog.
Commits
01442darelease 4.30.3984dc78[pre-commit.ci] pre-commit autoupdate (#3615)660adb5Fix incorrect type annotations in PythonPathPackageWithDeps (fixes #3607) (#3...393de39[pre-commit.ci] pre-commit autoupdate (#3608)6e32426Fix none config file issue 3611 (#3613)0805c83Isolate the test suite from any existingDEFAULT_CONFIG_FILEfile (#3612)Updates
psutilfrom 7.0.0 to 7.1.0Changelog
Sourced from psutil's changelog.
... (truncated)
Commits
0d18187Revert HISTORY notes about #2629. We still do publish 3.6 and 3.7 wheels.229e2dePre-releasefb75b28Chore: skip CI tests except on Python 3.8 and 3.133a4c016Stop publishing wheels for Python 3.6 and 3.7 (#2629)83e4f7fOSX: disable failing testdf0d4e2Call GetExtended[Tcp|Udp]Table twice under free-threaded build (round 2) (#2627)dcbfb81[Windows] fix unicode issues around service APIs (#2626)ef72dcdrevert #2590 (Call GetExtended[Tcp|Udp]Table twice under free-threaded build)8773698small refact around UTXENT_MUTEX_LOCK13b711fLock around uses of getutent/setutent/endutent (#2615)Updates
fakerfrom 37.6.0 to 37.8.0Release notes
Sourced from faker's releases.
Changelog
Sourced from faker's changelog.
Commits
4bde8f5Bump version: 37.7.0 → 37.8.0f542f36📝 Update CHANGELOG.mde28d7cbfix teste4305b0fix paddinga359441💄 format code0e3f0bdAdd Automotive providers forja_JPlocale (#2251)d4fa69dBump version: 37.6.0 → 37.7.0f636f06📝 Update CHANGELOG.md9a482dd💄 Format code2493b2dfix: fix minor grammar typo (#2259)Updates
docutilsfrom 0.21.2 to 0.22.2Commits
Updates
hypothesisfrom 6.138.16 to 6.140.3Release notes
Sourced from hypothesis's releases.
... (truncated)
Commits
bbbb0f7Bump hypothesis-python version to 6.140.3 and update changelog70eda0fMerge pull request #4536 from Liam-DeVoe/provider-conformance-realization2c062f8pin pytest-run-parallel6431451make crosshair profile inherit from default0da8df6spacing2934b0bMerge branch 'master' into provider-conformance-realization275d496Bump hypothesis-python version to 6.140.2 and update changelog5964b65reword recommendation3b95a47Merge pull request #4553 from Liam-DeVoe/tox-ci915a8d5Merge branch 'master' into provider-conformance-realizationDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions