build(deps): bump the uv group across 1 directory with 6 updates - #331
Open
dependabot[bot] wants to merge 1 commit into
Open
build(deps): bump the uv group across 1 directory with 6 updates#331dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the uv group with 3 updates in the / directory: [aiohttp](https://github.com/aio-libs/aiohttp), [jupyter-server](https://github.com/jupyter-server/jupyter_server) and [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions). Updates `aiohttp` from 3.13.5 to 3.14.1 - [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst) - [Commits](aio-libs/aiohttp@v3.13.5...v3.14.1) Updates `jupyter-server` from 1.15.6 to 2.20.0 - [Release notes](https://github.com/jupyter-server/jupyter_server/releases) - [Changelog](https://github.com/jupyter-server/jupyter_server/blob/main/CHANGELOG.md) - [Commits](jupyter-server/jupyter_server@v1.15.6...v2.20.0) Updates `jupyterlab` from 3.3.4 to 2.3.2 - [Release notes](https://github.com/jupyterlab/jupyterlab/releases) - [Changelog](https://github.com/jupyterlab/jupyterlab/blob/main/RELEASE.md) - [Commits](https://github.com/jupyterlab/jupyterlab/compare/@jupyterlab/vdom@3.3.4...@jupyterlab/celltags@2.3.2) Updates `protobuf` from 3.20.3 to 6.33.6 - [Release notes](https://github.com/protocolbuffers/protobuf/releases) - [Commits](https://github.com/protocolbuffers/protobuf/commits) Updates `pymdown-extensions` from 10.21.3 to 11.0 - [Release notes](https://github.com/facelessuser/pymdown-extensions/releases) - [Commits](facelessuser/pymdown-extensions@10.21.3...11.0) Updates `requests` from 2.15.1 to 2.32.5 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.15.1...v2.32.5) --- updated-dependencies: - dependency-name: aiohttp dependency-version: 3.14.1 dependency-type: indirect dependency-group: uv - dependency-name: jupyter-server dependency-version: 2.20.0 dependency-type: indirect dependency-group: uv - dependency-name: jupyterlab dependency-version: 2.3.2 dependency-type: indirect dependency-group: uv - dependency-name: protobuf dependency-version: 6.33.6 dependency-type: indirect dependency-group: uv - dependency-name: pymdown-extensions dependency-version: '11.0' dependency-type: indirect dependency-group: uv - dependency-name: requests dependency-version: 2.32.5 dependency-type: indirect dependency-group: uv ... Signed-off-by: dependabot[bot] <support@github.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the uv group with 3 updates in the / directory: aiohttp, jupyter-server and pymdown-extensions.
Updates
aiohttpfrom 3.13.5 to 3.14.1Changelog
Sourced from aiohttp's changelog.
... (truncated)
Commits
9c35d03Release v3.14.1 (#12864)38b956c[PR #12861/59684b5c backport][3.14] Revert "Drop list compression (#12857)" (...8f31009[PR #12857/69dff14d backport][3.14] Drop list compression (#12858)dfdfa9d[PR #12830/93a2b1c3 backport][3.14] Bound pipelined request queue per connect...0e9cedd[PR #12827/ccf218ab backport][3.14] Numeric ipv4 resolver bypass (#12849)a762eda[PR #12831/1ac92dae backport][3.14] Payload close on disconnect (#12843)a329a7a[PR #12824/60b85e98 backport][3.14] Preserve host-only cookie scope across Co...4f7480e[PR #12828/13b635d7 backport][3.14] Bounded unread compressed drain (#12845)5ab61bb[PR #12826/36df6c13 backport][3.14] Enforce max_line_size on fragmented reque...3912667[3.14] Add test that env proxy auth is scoped to the redirect-selected proxy ...Updates
jupyter-serverfrom 1.15.6 to 2.20.0Release notes
Sourced from jupyter-server's releases.
... (truncated)
Changelog
Sourced from jupyter-server's changelog.
... (truncated)
Commits
05a78adPublish 2.20.06cbee8dMerge commit from fork333e700Fixtest_authorizerhaving a spurious comma in params (#1664)cccd543Fix CI: explicitly pass base-setup inputs to avoid strict validation failurescd16d71Align docs for curve encryption with latest JEP version (#1660)e458061Add a toggle to enable curve encryption for all kernels that support it (#1638)0ceeb4fAdd note in RELEASE.mdb13f8a2Markdown does not work.e885b10Add GHSA reminder in prep-release0e28c90Exclude problematicpywinpty3.0.4 version (#1658)Updates
jupyterlabfrom 3.3.4 to 2.3.2Commits
4e21b13New versionc0022abupdate canvas version to allow build7546105Merge pull request from GHSA-4952-p58q-6crxb991019Backport PR #10353: Fix codemirror options updating (#10362)77f544fMerge pull request #10229 from goanpeca/fix/css0f52afetestd0a2775testc49e49fRevert display block back to flex to fix cell width and input prompt location238ae64Use getattr for optional attributes (#10064)8291cc1Publish 2.3.1Updates
protobuffrom 3.20.3 to 6.33.6Release notes
Sourced from protobuf's releases.
... (truncated)
Commits
Updates
pymdown-extensionsfrom 10.21.3 to 11.0Release notes
Sourced from pymdown-extensions's releases.
Commits
6d0097bUpdate changelogf4808eaBump version and update changeloga290074Update JS doc depsedce355Merge commit from fork9fb9643Update Python type deps299a129Docs: Update JS deps367d965Drop Python 3.9 (#2902)19ec936Fix issue with empty titles and Tabbed (#2901)4868783Fix npm option18a21f5zensical config should be stored in sdistUpdates
requestsfrom 2.15.1 to 2.32.5Release notes
Sourced from requests's releases.
... (truncated)
Changelog
Sourced from requests's changelog.
... (truncated)
Commits
b25c87dv2.32.5131e506Merge pull request #7010 from psf/dependabot/github_actions/actions/checkout-...b336cb2Bump actions/checkout from 4.2.0 to 5.0.046e939bUpdate publish workflow to useartifact-idinstead ofname4b9c546Merge pull request #6999 from psf/dependabot/github_actions/step-security/har...7618dbeBump step-security/harden-runner from 2.12.0 to 2.13.02edca11Add support for Python 3.14 and drop support for Python 3.8 (#6993)fec96cdUpdate Makefile rules (#6996)d58d8aadocs: clarify timeout parameter uses seconds in Session.request (#6994)91a3eabBump github/codeql-action from 3.28.5 to 3.29.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.