Update all dependencies#145
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/all
branch
from
August 15, 2025 16:13
60e2355 to
b086190
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
September 5, 2025 15:45
b086190 to
7278fa1
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
September 19, 2025 04:14
0c3b0e4 to
2bca253
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
September 22, 2025 12:06
2bca253 to
93be112
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
October 1, 2025 19:33
93be112 to
2852862
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
October 12, 2025 06:53
2852862 to
b9bcc35
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
October 25, 2025 08:11
b9bcc35 to
40dd62b
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
November 22, 2025 07:59
ac1fc93 to
e2d7010
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
December 13, 2025 16:03
9961c9b to
519d9e0
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
December 31, 2025 07:36
519d9e0 to
1b3977d
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
January 21, 2026 08:15
7fd9518 to
5916ca8
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
February 2, 2026 07:03
5916ca8 to
5b82939
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
February 20, 2026 07:54
5b82939 to
35cc4fb
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
March 1, 2026 06:52
35cc4fb to
13c3c89
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
March 14, 2026 19:21
324d335 to
0e566a3
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
March 31, 2026 10:42
0e566a3 to
e529468
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 15, 2026 19:04
e529468 to
ef62e13
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
May 5, 2026 07:42
9f32c01 to
d86c012
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
4 times, most recently
from
May 17, 2026 07:00
35e0b5e to
dcbb315
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
May 22, 2026 03:39
dcbb315 to
2c4fcb4
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
June 11, 2026 15:57
8e5df27 to
9b19061
Compare
Member
|
This includes an update to poetry beyond our org standard version, so that will need to be removed from the PR first. |
renovate
Bot
force-pushed
the
renovate/all
branch
2 times, most recently
from
June 21, 2026 16:07
a38342f to
367763d
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
June 27, 2026 12:13
367763d to
92f3974
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
July 15, 2026 04:12
92f3974 to
e6a2f7a
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
renovate
Bot
force-pushed
the
renovate/all
branch
from
July 18, 2026 11:09
e6a2f7a to
8ece468
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.0.0→7.3.0v4→v6v4→v7v4→v8v5→v6v4→v7^2.2.1→2.3.3^2.0.4→2.3.2^24.0.0→24.10.0~5.6.0→~6.1.0^7.0.0→7.14.1^1.7.5→1.7.8^7.0.0→7.3.0^2024.0.0→2024.2.26v0.40.0→v0.49.1^5.12.0→5.13.2^3.0.0→3.8.0v4.6.0→v6.0.05.13.2→8.0.1^0.9.3→0.9.41.8.3→2.4.124.4.2→26.5.1^7.0.0→7.4.7^2.0.0→2.0.0Note: The
pre-commitmanager in Renovate is not supported by thepre-commitmaintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.Release Notes
PyCQA/flake8 (PyCQA/flake8)
v7.3.0Compare Source
v7.2.0Compare Source
v7.1.2Compare Source
v7.1.1Compare Source
v7.1.0Compare Source
actions/cache (actions/cache)
v6.1.0Compare Source
What's Changed
Full Changelog: actions/cache@v6...v6.1.0
v6.0.0Compare Source
What's Changed
Full Changelog: actions/cache@v5...v6.0.0
v6Compare Source
v5.1.0Compare Source
What's Changed
Full Changelog: actions/cache@v5...v5.1.0
v5.0.5Compare Source
What's Changed
Full Changelog: actions/cache@v5...v5.0.5
v5.0.4Compare Source
What's Changed
New Contributors
Full Changelog: actions/cache@v5...v5.0.4
v5.0.3Compare Source
What's Changed
@actions/cacheto v5.0.5 (Resolves: https://github.com/actions/cache/security/dependabot/33)@actions/coreto v2.0.3Full Changelog: actions/cache@v5...v5.0.3
v5.0.2: v.5.0.2Compare Source
v5.0.2
What's Changed
When creating cache entries, 429s returned from the cache service will not be retried.
v5.0.1Compare Source
v5.0.1
What's Changed
v5.0.0
What's Changed
Full Changelog: actions/cache@v5...v5.0.1
v5.0.0Compare Source
What's Changed
Full Changelog: actions/cache@v4.3.0...v5.0.0
v5Compare Source
actions/checkout (actions/checkout)
v7.0.0Compare Source
v7Compare Source
v6.0.3Compare Source
v6.0.2Compare Source
v6.0.1Compare Source
v6.0.0Compare Source
v6Compare Source
v5.0.1Compare Source
v5.0.0Compare Source
v5Compare Source
actions/download-artifact (actions/download-artifact)
v8.0.1Compare Source
What's Changed
Full Changelog: actions/download-artifact@v8...v8.0.1
v8.0.0Compare Source
v8 - What's new
Direct downloads
To support direct uploads in
actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks theContent-Typeheader ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the newskip-decompressparameter totrue.Enforced checks (breaking)
A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the
digest-mismatchparameter. To be secure by default, we are now defaulting the behavior toerrorwhich will fail the workflow run.ESM
To support new versions of the @actions/* packages, we've upgraded the package to ESM.
What's Changed
errorby @danwkennedy in #461Full Changelog: actions/download-artifact@v7...v8.0.0
v8Compare Source
v7.0.0Compare Source
v7 - What's new
Node.js 24
This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.
What's Changed
New Contributors
Full Changelog: actions/download-artifact@v6.0.0...v7.0.0
v7Compare Source
v6.0.0Compare Source
What's Changed
BREAKING CHANGE: this update supports Node
v24.x. This is not a breaking change per-se but we're treating it as such.@actions/artifacttov4.0.0v6.0.0by @danwkennedy in #438New Contributors
Full Changelog: actions/download-artifact@v5...v6.0.0
v6Compare Source
v5.0.0Compare Source
What's Changed
v5.0.0
🚨 Breaking Change
This release fixes an inconsistency in path behavior for single artifact downloads by ID. If you're downloading single artifacts by ID, the output path may change.
What Changed
Previously, single artifact downloads behaved differently depending on how you specified the artifact:
name: my-artifact→ extracted topath/(direct)artifact-ids: 12345→ extracted topath/my-artifact/(nested)Now both methods are consistent:
name: my-artifact→ extracted topath/(unchanged)artifact-ids: 12345→ extracted topath/(fixed - now direct)Migration Guide
✅ No Action Needed If:
merge-multiple: trueas a workaroundYou download single artifacts by ID and your workflows expect the nested directory structure.
Before v5 (nested structure):
To maintain old behavior (if needed):
New Contributors
Full Changelog: actions/download-artifact@v4...v5.0.0
v5Compare Source
actions/setup-python (actions/setup-python)
v6.3.0Compare Source
What's Changed
Enhancement
Dependency update
Documentation
New Contributors
Full Changelog: actions/setup-python@v6...v6.3.0
v6.2.0Compare Source
What's Changed
Dependency Upgrades
/__tests__/databy @dependabot in #1253 and #1264Full Changelog: actions/setup-python@v6...v6.2.0
v6.1.0Compare Source
What's Changed
Enhancements:
pip-installinput by @gowridurgad in #1201Dependency and Documentation updates:
allow-prereleasesby @yarikoptic in #979New Contributors
Full Changelog: actions/setup-python@v6...v6.1.0
v6.0.0Compare Source
What's Changed
Breaking Changes
Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes
Enhancements:
pip-versionby @priyagupta108 in #1129Bug fixes:
Dependency updates:
New Contributors
Full Changelog: actions/setup-python@v5...v6.0.0
v6Compare Source
actions/upload-artifact (actions/upload-artifact)
v7.0.1Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v7...v7.0.1
v7.0.0Compare Source
v7 What's new
Direct Uploads
Adds support for uploading single files directly (unzipped). Callers can set the new
archiveparameter tofalseto skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. Thenameparameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.ESM
To support new versions of the
@actions/*packages, we've upgraded the package to ESM.What's Changed
New Contributors
Full Changelog: actions/upload-artifact@v6...v7.0.0
v7Compare Source
v6.0.0Compare Source
v6 - What's new
Node.js 24
This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.
What's Changed
Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0
v6Compare Source
v5.0.0Compare Source
What's Changed
BREAKING CHANGE: this update supports Node
v24.x. This is not a breaking change per-se but we're treating it as such.@actions/artifacttov4.0.0v5.0.0by @danwkennedy in #734New Contributors
Full Changelog: actions/upload-artifact@v4...v5.0.0
v5Compare Source
agronholm/cbor2 (cbor2)
v6.1.3Compare Source
+instead of building the result once (#316; PR by @sahvx655-wq)datetime_as_timestampencoding whole-second datetimes before 1970 or after 2106 as floats instead of integers, because the timestamp was narrowed through an unsigned 32-bit integer (#317; PR by @sahvx655-wq)CBORDecodeErrorreadinginvalid types in input array; the encoder emits them as[address, null, zone id]but the decoder only handled the network and interface array forms, so a scoped~ipaddress.IPv6Addresscould not be decoded back (#324; PR by @sahvx655-wq)v6.1.2Compare Source
cbor2.load()crash caused by incorrect handling of internal read buffer extension during stream deserialization. (#307; PR by @noderyos)v6.1.1Compare Source
cbor2.load()returning corrupted data for payloads exceeding 4096 bytes (#304)v6.1.0Compare Source
allow_duplicate_keysparameter toCBORDecoder,loadandloads(default:True). When set toFalse, aCBORDecodeErroris raised upon encountering a duplicate key within the same map. (#283)memoryvieworbytearray) in addition tobytes(#297)v6.0.1Compare Source
v6.0.0Compare Source
v5.9.0Compare Source
max_depthdecoder parameter to limit the maximum allowed nesting level of containers, with a default value of 400 levels (CVE-2026-26209)read_sizefrom 4096 to 1 for backwards compatibility. The buffered reads introduced in 5.8.0 could cause issues when code needs to access the stream position after decoding. Users can opt-in to faster decoding by passingread_size=4096when they don't need to access the stream directly after decoding. Added a direct read path forread_size=1to avoid buffer management overhead. (#275; PR by @andreer)CBOREncoder.encode_shared()(#287)str_errorssetting when decoding strings, and improved string decoding performance by using stack allocation for small strings and eliminating unnecessary conditionals. Benchmarks show 9-17% faster deserialization. (#255; PR by @andreer)v5.8.0Compare Source
v5.7.1Compare Source
[
v5.7.0](https://redirect.github.com/agronholm/cbor2/releases/Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.