chore(deps): bump the python-dependencies group with 4 updates - #235
github-actions[bot] merged 2 commits into
Conversation
Bumps the python-dependencies group with 4 updates: [pyjwt](https://github.com/jpadilla/pyjwt), [boto3](https://github.com/boto/boto3), [botocore](https://github.com/boto/botocore) and [pylint](https://github.com/pylint-dev/pylint). Updates `pyjwt` from 2.14.0 to 2.15.0 - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.14.0...2.15.0) Updates `boto3` from 1.43.97 to 1.43.102 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.43.97...1.43.102) Updates `botocore` from 1.43.97 to 1.43.102 - [Commits](boto/botocore@1.43.97...1.43.102) Updates `pylint` from 4.0.8 to 4.0.9 - [Release notes](https://github.com/pylint-dev/pylint/releases) - [Commits](pylint-dev/pylint@v4.0.8...v4.0.9) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-dependencies - dependency-name: boto3 dependency-version: 1.43.102 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: botocore dependency-version: 1.43.102 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-dependencies - dependency-name: pylint dependency-version: 4.0.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. WalkthroughThe pull request updates the pinned versions of ChangesDependency Pin Updates
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to No regression is established in the supplied dependency updates or their described authentication path; no merge-blocking impact is identified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The token-verification dependency is being updated, but the application retains its signature check and authorization gates. No new bypass was established. The exact behavior of the new library version has not been fully verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
A rabbit checks the pins in place Comment |
Pull Request is not mergeable
Bumps the python-dependencies group with 4 updates: pyjwt, boto3, botocore and pylint.
Updates
pyjwtfrom 2.14.0 to 2.15.0Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.