Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
184 commits
Select commit Hold shift + click to select a range
bee16a2
initial upload
stefan6419846 May 16, 2025
13b836a
fix authors and maintainers
stefan6419846 May 16, 2025
6c10ebb
include Python packages into Dependabot configuration
stefan6419846 May 16, 2025
ce49416
pytest-runner is obsolete
stefan6419846 May 16, 2025
4ba1e58
remove obsolete pytest-runner
stefan6419846 May 16, 2025
6a9d448
Bump cryptography from 44.0.3 to 45.0.2 (#4)
dependabot[bot] May 19, 2025
1bb19cf
Make `tomli` a dependency only on Python <3.11 (#6)
johnthagen May 19, 2025
b94ca9d
Further cleanup
stefan6419846 May 20, 2025
bab1086
fix typo
stefan6419846 May 20, 2025
eb377e5
Bump coverage[toml] from 7.8.0 to 7.8.1 (#9)
dependabot[bot] May 22, 2025
4a6a47e
Bump cryptography from 45.0.2 to 45.0.3 (#10)
dependabot[bot] May 26, 2025
29afe13
Bump coverage[toml] from 7.8.1 to 7.8.2 (#11)
dependabot[bot] May 26, 2025
b588459
Version 1.1.0
stefan6419846 May 26, 2025
7f74bbe
Refactor dependencies to include type stubs in dev extra
stefan6419846 May 26, 2025
df6b537
Remove obsolete mypy parameter
stefan6419846 May 26, 2025
e1d6dc3
Bump zipp from 3.21.0 to 3.22.0 (#12)
dependabot[bot] May 27, 2025
d837866
Test against Python 3.14
stefan6419846 May 28, 2025
7dc85ac
Bump mypy from 1.15.0 to 1.16.0 (#13)
dependabot[bot] May 30, 2025
4cecd92
Allow SPDX OR clauses (#15)
b-kamphorst Jun 3, 2025
da8a2c3
Bump pytest from 8.3.5 to 8.4.0 (#16)
dependabot[bot] Jun 3, 2025
da208ac
Improve coverage (#17)
stefan6419846 Jun 3, 2025
a019711
version 1.2.0
stefan6419846 Jun 3, 2025
776b6b3
Bump types-docutils from 0.21.0.20250526 to 0.21.0.20250604 (#18)
dependabot[bot] Jun 4, 2025
3674e4d
Replace pycodestyle with flake8 (#19)
stefan6419846 Jun 4, 2025
ef662ee
Bump zipp from 3.22.0 to 3.23.0 (#20)
dependabot[bot] Jun 9, 2025
e67744f
Bump cryptography from 45.0.3 to 45.0.4 (#21)
dependabot[bot] Jun 10, 2025
0bee653
Bump requests from 2.32.3 to 2.32.4 (#22)
dependabot[bot] Jun 10, 2025
593b2ec
Bump coverage[toml] from 7.8.2 to 7.9.0 (#23)
dependabot[bot] Jun 12, 2025
26c86ec
Bump pytest-cov from 6.1.1 to 6.2.0 (#24)
dependabot[bot] Jun 12, 2025
8aaec49
Bump typing-extensions from 4.13.2 to 4.14.0 (#25)
dependabot[bot] Jun 13, 2025
ba58e44
Bump pytest-cov from 6.2.0 to 6.2.1 (#26)
dependabot[bot] Jun 13, 2025
cd88c70
Bump certifi from 2025.4.26 to 2025.6.15 (#27)
dependabot[bot] Jun 16, 2025
7a57d9d
Bump coverage[toml] from 7.9.0 to 7.9.1 (#28)
dependabot[bot] Jun 16, 2025
c2d7b99
Bump mypy from 1.16.0 to 1.16.1 (#29)
dependabot[bot] Jun 17, 2025
058be97
Bump pytest from 8.4.0 to 8.4.1 (#30)
dependabot[bot] Jun 18, 2025
a1b2e84
Bump urllib3 from 2.4.0 to 2.5.0 (#31)
dependabot[bot] Jun 19, 2025
628edc3
Bump pygments from 2.19.1 to 2.19.2 (#33)
dependabot[bot] Jun 23, 2025
20edb29
Bump flake8 from 7.2.0 to 7.3.0 (#35)
dependabot[bot] Jun 23, 2025
6e8ad25
Bump jaraco-functools from 4.1.0 to 4.2.1 (#36)
dependabot[bot] Jun 23, 2025
a0733ab
Bump license-expression from 30.4.1 to 30.4.2 (#37)
dependabot[bot] Jun 25, 2025
793b5de
Bump license-expression from 30.4.2 to 30.4.3 (#38)
dependabot[bot] Jun 26, 2025
7027acb
Bump pip-licenses-lib from 0.5.0 to 0.6.0 (#39)
dependabot[bot] Jun 26, 2025
d2c66f0
Make pyproject.toml configuration section name backwards-compatible (…
wrvdklooster Jun 28, 2025
8759752
add version 1.3.0
stefan6419846 Jun 28, 2025
4f30697
version 1.3.0
stefan6419846 Jun 28, 2025
24d14fc
Fix README reference to `pip-licenses-lib` (#42)
johnthagen Jun 30, 2025
ab9e7ec
fix formatting
stefan6419846 Jul 1, 2025
b21cf60
Add a --collect-all-failures flag (#44)
joeyjurjens Jul 2, 2025
063d81d
version 1.4.0
stefan6419846 Jul 2, 2025
6940b14
Bump cryptography from 45.0.4 to 45.0.5 (#45)
dependabot[bot] Jul 3, 2025
1cb8969
Bump coverage[toml] from 7.9.1 to 7.9.2 (#46)
dependabot[bot] Jul 3, 2025
edef4e0
Bump typing-extensions from 4.14.0 to 4.14.1 (#47)
dependabot[bot] Jul 7, 2025
3af6518
Bump types-docutils from 0.21.0.20250604 to 0.21.0.20250708 (#48)
dependabot[bot] Jul 8, 2025
00cd1c3
Bump certifi from 2025.6.15 to 2025.7.9 (#50)
dependabot[bot] Jul 9, 2025
eec430a
Bump types-docutils from 0.21.0.20250708 to 0.21.0.20250710 (#51)
dependabot[bot] Jul 10, 2025
4afb2f8
Bump certifi from 2025.7.9 to 2025.7.14 (#55)
dependabot[bot] Jul 14, 2025
1e33467
Bump types-docutils from 0.21.0.20250710 to 0.21.0.20250715 (#58)
dependabot[bot] Jul 15, 2025
a46971b
Bump mypy from 1.16.1 to 1.17.0 (#57)
dependabot[bot] Jul 15, 2025
361c6b5
Bump types-pygments from 2.19.0.20250516 to 2.19.0.20250715 (#56)
dependabot[bot] Jul 15, 2025
5c1a9ba
Bump nh3 from 0.2.21 to 0.2.22 (#60)
dependabot[bot] Jul 16, 2025
d74f2d2
Add --collect-all-failures docs to USAGE.md (#61)
pkwasniok Jul 16, 2025
0970bb3
Bump nh3 from 0.2.22 to 0.3.0 (#63)
dependabot[bot] Jul 18, 2025
dd59577
Bump license-expression from 30.4.3 to 30.4.4 (#64)
dependabot[bot] Jul 22, 2025
7036e3f
Bump types-docutils from 0.21.0.20250715 to 0.21.0.20250722 (#65)
dependabot[bot] Jul 22, 2025
8cdb86e
Bump rich from 14.0.0 to 14.1.0 (#66)
dependabot[bot] Jul 25, 2025
59e282e
Bump coverage[toml] from 7.9.2 to 7.10.0 (#67)
dependabot[bot] Jul 25, 2025
8f5e4c5
Improve modularization (#69)
stefan6419846 Jul 28, 2025
a437305
Bump types-docutils from 0.21.0.20250722 to 0.21.0.20250728 (#70)
dependabot[bot] Jul 29, 2025
1f896bb
Bump coverage[toml] from 7.10.0 to 7.10.1 (#71)
dependabot[bot] Jul 29, 2025
b5b7bc6
Licenses filtering doesn't work properly when list ends with semicolo…
pkwasniok Jul 30, 2025
46a0bf2
version 2.0.0
stefan6419846 Jul 30, 2025
7024a4f
Bump docutils from 0.21.2 to 0.22 (#72)
dependabot[bot] Jul 30, 2025
100126f
Bump mypy from 1.17.0 to 1.17.1 (#73)
dependabot[bot] Jul 31, 2025
a47f22a
Bump pip-tools from 7.4.1 to 7.5.0 (#74)
dependabot[bot] Jul 31, 2025
db7ded6
Bump types-colorama from 0.4.15.20240311 to 0.4.15.20250801 (#75)
dependabot[bot] Aug 1, 2025
2e14ea5
Bump coverage[toml] from 7.10.1 to 7.10.2 (#76)
dependabot[bot] Aug 4, 2025
2a06a9d
Bump certifi from 2025.7.14 to 2025.8.3 (#77)
dependabot[bot] Aug 4, 2025
0986765
Bump build from 1.2.2.post1 to 1.3.0 (#78)
dependabot[bot] Aug 4, 2025
b4856f0
Bump actions/download-artifact from 4 to 5 (#79)
dependabot[bot] Aug 6, 2025
ca53bcc
Bump cryptography from 45.0.5 to 45.0.6 (#80)
dependabot[bot] Aug 6, 2025
15376b4
Bump coverage[toml] from 7.10.2 to 7.10.3 (#81)
dependabot[bot] Aug 11, 2025
42aa0ff
Bump types-docutils from 0.21.0.20250728 to 0.21.0.20250809 (#82)
dependabot[bot] Aug 11, 2025
3e228c0
Bump charset-normalizer from 3.4.2 to 3.4.3 (#83)
dependabot[bot] Aug 11, 2025
0fb7b63
Bump types-pygments from 2.19.0.20250715 to 2.19.0.20250809 (#84)
dependabot[bot] Aug 11, 2025
03d3d43
Bump types-pexpect from 4.9.0.20250516 to 4.9.0.20250809 (#85)
dependabot[bot] Aug 11, 2025
28a1720
Bump actions/checkout from 4 to 5 (#86)
dependabot[bot] Aug 12, 2025
a1cfc03
Small improvements to Makefile (#54)
reactive-firewall Aug 14, 2025
97d8556
fix usage of docutils.frontend.get_default_settings
stefan6419846 Aug 14, 2025
8289e8b
Bump types-docutils from 0.21.0.20250809 to 0.22.0.20250814 (#87)
dependabot[bot] Aug 14, 2025
f8bda83
Bump coverage[toml] from 7.10.3 to 7.10.4 (#88)
dependabot[bot] Aug 18, 2025
ebfc34f
Bump requests from 2.32.4 to 2.32.5 (#90)
dependabot[bot] Aug 19, 2025
8b33c0f
Bump jaraco-functools from 4.2.1 to 4.3.0 (#89)
dependabot[bot] Aug 19, 2025
9fc529c
Bump types-docutils from 0.22.0.20250814 to 0.22.0.20250822 (#91)
dependabot[bot] Aug 22, 2025
b7d99ea
Bump coverage[toml] from 7.10.4 to 7.10.5 (#92)
dependabot[bot] Aug 26, 2025
1302735
Bump typing-extensions from 4.14.1 to 4.15.0 (#93)
dependabot[bot] Aug 27, 2025
8567de8
Bump platformdirs from 4.3.8 to 4.4.0 (#94)
dependabot[bot] Aug 27, 2025
59f6de3
Bump coverage[toml] from 7.10.5 to 7.10.6 (#95)
dependabot[bot] Sep 3, 2025
fe74f22
Bump cryptography from 45.0.6 to 45.0.7 (#96)
dependabot[bot] Sep 3, 2025
95d2228
Bump more-itertools from 10.7.0 to 10.8.0 (#97)
dependabot[bot] Sep 4, 2025
3744642
Bump actions/setup-python from 5 to 6 (#98)
dependabot[bot] Sep 4, 2025
b81540c
Bump twine from 6.1.0 to 6.2.0 (#99)
dependabot[bot] Sep 5, 2025
0f529b2
Bump pytest from 8.4.1 to 8.4.2 (#100)
dependabot[bot] Sep 5, 2025
5197312
Bump pytest-cov from 6.2.1 to 6.3.0 (#101)
dependabot[bot] Sep 8, 2025
6cf7b03
Bump cffi from 1.17.1 to 2.0.0 (#102)
dependabot[bot] Sep 9, 2025
9331886
Bump pycparser from 2.22 to 2.23 (#103)
dependabot[bot] Sep 10, 2025
af76e09
Bump pytest-cov from 6.3.0 to 7.0.0 (#104)
dependabot[bot] Sep 10, 2025
3a14226
Bump mypy from 1.17.1 to 1.18.1 (#105)
dependabot[bot] Sep 12, 2025
972e528
Bump types-docutils from 0.22.0.20250822 to 0.22.0.20250914 (#106)
dependabot[bot] Sep 15, 2025
eb52871
Bump types-pexpect from 4.9.0.20250809 to 4.9.0.20250916 (#107)
dependabot[bot] Sep 16, 2025
314801c
Bump cryptography from 45.0.7 to 46.0.1 (#108)
dependabot[bot] Sep 17, 2025
3affdaa
Bump docutils from 0.22 to 0.22.1 (#109)
dependabot[bot] Sep 18, 2025
b1a4879
Bump black from 25.1.0 to 25.9.0 (#110)
dependabot[bot] Sep 19, 2025
48d038d
Bump types-docutils from 0.22.0.20250914 to 0.22.0.20250919 (#111)
dependabot[bot] Sep 19, 2025
4a2bbb8
Bump mypy from 1.18.1 to 1.18.2 (#112)
dependabot[bot] Sep 19, 2025
df14749
Bump docutils from 0.22.1 to 0.22.2 (#113)
dependabot[bot] Sep 22, 2025
604d328
Bump coverage[toml] from 7.10.6 to 7.10.7 (#114)
dependabot[bot] Sep 22, 2025
1251238
Bump types-docutils from 0.22.0.20250919 to 0.22.1.20250923 (#115)
dependabot[bot] Sep 23, 2025
3c0ff49
Bump wcwidth from 0.2.13 to 0.2.14 (#116)
dependabot[bot] Sep 23, 2025
8e4def4
Bump types-docutils from 0.22.1.20250923 to 0.22.2.20250924 (#117)
dependabot[bot] Sep 24, 2025
35929d5
Bump cryptography from 46.0.1 to 46.0.2 (#118)
dependabot[bot] Oct 1, 2025
4473b35
Bump pip-tools from 7.5.0 to 7.5.1 (#119)
dependabot[bot] Oct 2, 2025
dd43f37
Bump isort from 6.0.1 to 6.1.0 (#120)
dependabot[bot] Oct 2, 2025
08994cc
Bump certifi from 2025.8.3 to 2025.10.5 (#121)
dependabot[bot] Oct 6, 2025
657a402
Bump types-docutils from 0.22.2.20250924 to 0.22.2.20251006 (#122)
dependabot[bot] Oct 6, 2025
e2356fd
Bump nh3 from 0.3.0 to 0.3.1 (#123)
dependabot[bot] Oct 7, 2025
be3d9b1
Bump attrs from 25.3.0 to 25.4.0 (#124)
dependabot[bot] Oct 7, 2025
fcb020f
Bump tomli from 2.2.1 to 2.3.0 (#125)
dependabot[bot] Oct 10, 2025
583f0e7
Document compatibility with pip-licenses
stefan6419846 Oct 10, 2025
0c23898
Bump rich from 14.1.0 to 14.2.0 (#126)
dependabot[bot] Oct 10, 2025
579b650
stop testing on Python 3.9, use released 3.14
stefan6419846 Oct 12, 2025
10efb40
Bump idna from 3.10 to 3.11 (#127)
dependabot[bot] Oct 13, 2025
61b1277
Bump charset-normalizer from 3.4.3 to 3.4.4 (#128)
dependabot[bot] Oct 14, 2025
3def5d8
Drop dependency on pytest
stefan6419846 Oct 15, 2025
ada3a88
Bump cryptography from 46.0.2 to 46.0.3 (#130)
dependabot[bot] Oct 16, 2025
0b1c2ae
Add support for emitting multiple files and License-File entries
stefan6419846 Oct 20, 2025
a9ee12e
fix plain-vertical for omitted license paths and output order
stefan6419846 Oct 20, 2025
041521d
version bump branch to v6.0
reactive-firewall Mar 29, 2026
133ea73
docs: add common options summary table to README
SAY-5 May 19, 2026
702ff95
docs: apply reviewer suggestions (pluralize header, clarify flag word…
SAY-5 May 26, 2026
bf7c9f0
[DOCUMENTAION] Resolve documentation chore (GHI #328)
reactive-firewall May 26, 2026
6e988ab
fix: update allow-only tests to handle filelock Unlicense metadata ch…
Aydeing Jun 12, 2026
344a120
fix: correct inline comments about filelock license direction
Aydeing Jun 13, 2026
68b30e1
style: apply ruff format to fix CI lint
Aydeing Jun 14, 2026
9f9d672
Merge branch 'fix/filelock-unlicense-test-regression' into dev-v6.0
reactive-firewall Jun 15, 2026
d4d0076
[UPDATE] (deps): Bump codecov/codecov-action in /.github/workflows
dependabot[bot] Jun 12, 2026
b4572f5
fix: Upgrade samples packages in README to avoid false alarms in CVE …
matejkloska Apr 21, 2026
cce6692
fix: update allow-only tests to handle filelock Unlicense metadata ch…
Aydeing Jun 12, 2026
3ec4766
fix: correct inline comments about filelock license direction
Aydeing Jun 13, 2026
bb16ff7
style: apply ruff format to fix CI lint
Aydeing Jun 14, 2026
7e9cf53
[UPDATE] (deps): Bump codecov/codecov-action in /.github/workflows
dependabot[bot] Jun 12, 2026
be8482a
fix: Upgrade samples packages in README to avoid false alarms in CVE …
matejkloska Apr 21, 2026
6a0f2ee
[SYNC] Synchronize known fixes from PR #345
reactive-firewall Jul 6, 2026
58a44b8
fix: Upgrade samples packages in README to avoid false alarms in CVE …
matejkloska Apr 21, 2026
0f31625
[CHORE] Upgrade samples packages in README (PR #326)
reactive-firewall Jul 6, 2026
e8c1f3b
[EMPTY] Supersedes PR #326
reactive-firewall Jul 6, 2026
c0bf7b7
[PATCH] Minor improvement to Makefile
reactive-firewall Jul 8, 2026
d883bb7
[FILTER] Pin relevant files with fixes from 0b1c2ae56d0d8bd0bac078bf7…
stefan6419846 Jul 30, 2026
83c7835
[FILTER] Best effort staging commit to credit all those involved incl…
reactive-firewall Jul 30, 2026
f949437
[DOCUMENTATION] Extra commit to show `git rerere` how to resolve conf…
reactive-firewall Jul 30, 2026
2f26c3c
[DOCUMENATION] Show `git rerere` how to resolve conflicts.
reactive-firewall Jul 30, 2026
96f6dfb
[DOCUMENATION] Show `git rerere` how to resolve conflicts.
reactive-firewall Jul 30, 2026
804332f
[DOCUMENATION] Show `git rerere` how to resolve conflicts.
reactive-firewall Jul 30, 2026
a227ffd
[DOCUMENTATION] Merge into one file
reactive-firewall Jul 30, 2026
ec4d04c
[PATCH] Possible workaround for GHI #71 (WIP #242)
reactive-firewall Jul 30, 2026
cbe1184
[TESTING] Updated various tests for GHI #242 and #71 (WIP)
reactive-firewall Jul 10, 2026
789780b
[TESTING] Minor tweaks to improve code coverage slightly (- WIP #309 -)
reactive-firewall Jul 11, 2026
6eb56b6
[UPDATE] Supperceeds PR #343
reactive-firewall Jul 12, 2026
7679c47
[UPDATE] superceeds PR #325
reactive-firewall Jul 13, 2026
8b17bd7
[UPDATE] Supperceeds PR #341
reactive-firewall Jul 14, 2026
0d91f3c
[TESTING] Imporved test coverage slightly.
reactive-firewall Jul 16, 2026
a584608
[TESTING] slight improved coverage
reactive-firewall Jul 16, 2026
b444f8a
[TESTING] Possible fix for regression due to fine-grain controls
reactive-firewall Jul 16, 2026
9dfc692
[PATCH] Apply changes discussed in review of PR #346
reactive-firewall Jul 28, 2026
141ede4
Release Candidate for development build (v-6.0.0a0)
reactive-firewall Jul 30, 2026
54da0fb
Release Candidate for v6.0 alpha (EXPEREMENTAL) Dev Build
reactive-firewall Jul 30, 2026
0a0ced4
[DOCUMENTATION] Chore: Update note about legacy python versions no-lo…
reactive-firewall Jul 31, 2026
dd28630
[PATCH] Version bump docker base to recent version (3.14-slim-trixie)
reactive-firewall Jul 31, 2026
c951a86
Merge branch 'dev-v6-docs' into alpha-v6.0.0
reactive-firewall Jul 31, 2026
fe17c49
RUF036 -- Moved 'None' to end of union
reactive-firewall Aug 1, 2026
d3c0062
PERF403 -- Tossed use of local variable to refactor filter dictionary…
reactive-firewall Aug 2, 2026
b3f0ce9
PLW0127 -- allow monkey patching (for now)
reactive-firewall Aug 2, 2026
4e80d41
PLW1510 -- make check=False explicit as suggested by linter
reactive-firewall Aug 2, 2026
7d2d6be
[SECURITY] update development dependencies
reactive-firewall Aug 2, 2026
9d2b039
Updated changelog for alpha-1 pre-release for version 6.0.0 as part o…
reactive-firewall Aug 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 7 additions & 7 deletions .github/workflows/CD-PyPi.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,8 @@ on:
permissions: {}

env:
# Define Python versions at the top level -- Expected format: X.Y (e.g., 3.13)
PYTHON_DEFAULT: "${{ vars.PYTHON_DEFAULT || '3.13' }}"
# Define Python versions at the top level -- Expected format: X.Y (e.g., 3.14)
PYTHON_DEFAULT: "${{ vars.PYTHON_DEFAULT || '3.14' }}"

jobs:
pypi-publish:
Expand Down Expand Up @@ -40,13 +40,13 @@ jobs:
build_status: ${{ steps.build.outcome }}
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- id: build-python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
with:
python-version: "${{ env.PYTHON_DEFAULT || 3.13 }}"
python-version: "${{ env.PYTHON_DEFAULT || 3.14 }}"
- id: output_python
name: "bootstrap Python"
shell: bash
Expand All @@ -60,7 +60,7 @@ jobs:
- name: Setup build tools
id: build_deps
shell: bash
run: pip install --no-input --user "pip>=26.0" "setuptools>=82.0" "wheel>=0.45" "build>=1.2.1"
run: pip install --no-input --user "pip>=26.0.1" "setuptools>=83.0" "wheel>=0.47" "build>=1.2.1"
- name: Pre-Clean
id: clean
shell: bash
Expand All @@ -77,9 +77,9 @@ jobs:
run: |
shasum -a 512 dist/* > build.checksums.txt
- name: "Attest Build with Checksums"
id: multicast-build-chksum-attest
id: piplicenses-build-chksum-attest
if: ${{ !cancelled() && (github.repository == 'raimon49/pip-licenses') && startsWith(github.ref, 'refs/tags/') }}
uses: actions/attest@59d89421af93a897026c735860bf21b6eb4f7b26 # v4.1.0
uses: actions/attest@a1948c3f048ba23858d222213b7c278aabede763 # v4.1.1
with:
subject-checksums: build.checksums.txt
github-token: ${{ github.token }}
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/python-package.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Set up Python
Expand All @@ -41,7 +41,7 @@ jobs:
python-version: ['3.9', '3.10', '3.11', '3.12', '3.13', '3.14']
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Set up Python ${{ matrix.python-version }}
Expand All @@ -56,7 +56,7 @@ jobs:
run: |
pytest -v --cov --cov-report=xml
- name: Update coverage artifact
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage-${{ matrix.python-version }}
path: coverage.xml
Expand All @@ -70,15 +70,15 @@ jobs:
if: ${{ github.actor != 'dependabot[bot]' && github.event.sender.login != 'dependabot[bot]' }}
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
persist-credentials: false
- name: Download all coverage artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: coverage-*
- name: Upload code coverage to Codecov
uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v6.0.0
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
token: ${{ secrets.CODECOV_TOKEN }}
name: codecov-umbrella
Expand Down
15 changes: 15 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,20 @@
## CHANGELOG

### pre-6.0.0 (ALPHA WIP)

(SUBJECT TO CHANGE IN NEXT RELEASE)

* Fixed priority logic regression from v5.5.x that lead to non-determinant ordering of multiple-source results, (WIP GHI #309), and possibly resolving? (GHI #330 - needs new testing)
* Fixed multiple regressions in tests due to recent version bumps, closing GHI #337 & GHI #338
* Updated various portions of the README document (WIP), closing GHI #328
* Improved handling of multiple license files in a single package (WIP GHI #71)
* Implemented new flags (WIP GHI #242)
* Fixed multiple false positives including:
* [CVE-2026-4539 reDoS](https://github.com/advisories/GHSA-5239-wwwm-4pmq)
* [CVE-2026-44432 Leak](https://github.com/advisories/GHSA-mf9v-mfxr-j63j)
* [CVE-2026-44431](https://github.com/advisories/GHSA-qccp-gfcp-xxvc)
* Updated testing in CI to resolve python3.9 coverage regresions

### 5.5.5

* Updated cc lines and officially made note of change in maintainers
Expand Down
4 changes: 2 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
FROM python:3.11-slim-bullseye
LABEL maintainer="raimon <raimon49@hotmail.com>"
FROM python:3.14-slim-trixie
LABEL maintainer="reactive-firewall <reactive-firewall@users.noreply.github.com>"

ARG APPDIR=/opt/piplicenses

Expand Down
2 changes: 2 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -135,6 +135,8 @@ endif
# file path to extra developer requirements generated by pip-compile
DEV_DEPENDS:='dev-requirements'

.SUFFIXES: .py .pyc .pyi

.DEFAULT_GOAL:= help
.PHONY: help, setup, local-install, local-uninstall, update-depends, lint, test, deploy, test-deploy, build, clean, full-clean, un-setup

Expand Down
Loading
Loading