Dependency Dashboard #4

Open
opened 2026-04-27 23:16:10 -04:00 by Renovate · 0 comments
Member

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

Abandoned Dependencies

The following dependencies have not received updates for an extended period and may be unmaintained.

ℹ️ Note

Packages are marked as abandoned when they exceed the abandonmentThreshold since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.

View abandoned dependencies (1)
Datasource Package Last Updated
pep621 diskcache 2023-08-31

Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

Vulnerabilities

Important

53/53 CVEs have Renovate fixes.

pep621
pyproject.toml
diskcache
gitpython

Detected Dependencies

github-actions (1)
.forgejo/workflows/actions.yaml (5)
  • actions/checkout v6@d23441a48e516b6c34aea4fa41551a30e30af803 → [Updates: v7]
  • actions/setup-uv v6@d0cc045d04ccac9d8b7881df0226f9e82c39688e → [Updates: v10.1.0]
  • actions/upload-artifact v4@16871d9e8cfcf27ff31822cac382bbb5450f1e1e → [Updates: v5]
  • actions/checkout v6@d23441a48e516b6c34aea4fa41551a30e30af803 → [Updates: v7]
  • actions/setup-uv v6@d0cc045d04ccac9d8b7881df0226f9e82c39688e → [Updates: v10.1.0]
pep621 (1)
pyproject.toml (9)
  • python ~=3.14.0
  • diskcache >=5.6.3
  • gitpython ~=3.1.45 → [Updates: ~=3.1.45]
  • pydantic >=2.13.2
  • pyforgejo ~=2.0.5
  • tomlkit ~=0.14.0 → [Updates: ~=0.15.1]
  • typer ~=0.25.0 → [Updates: ~=0.27.2]
  • basedpyright ~=1.39.3 → [Updates: ~=1.40.1]
  • ruff ~=0.15.12 → [Updates: ~=0.16.7]
renovate-config (1)
renovate.json
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more. ## Abandoned Dependencies The following dependencies have not received updates for an extended period and may be unmaintained. > ℹ️ **Note** > Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity. > <details> <summary>View abandoned dependencies (1)</summary> | Datasource | Package | Last Updated | |------------|------|-------------| | pep621 | [diskcache](https://github.com/grantjenks/python-diskcache) | `2023-08-31` | </details> ## Open The following updates have all been created. To force a retry/rebase of any, click on a checkbox below. - [ ] <!-- rebase-branch=renovate/pypi-gitpython-vulnerability -->[Update dependency gitpython to v3.1.59 [SECURITY]](pulls/15) - [ ] <!-- rebase-branch=renovate/basedpyright-1.x -->[Update dependency basedpyright to ~=1.40.1](pulls/23) - [ ] <!-- rebase-branch=renovate/ruff-0.x -->[Update dependency ruff to ~=0.16.7](pulls/21) - [ ] <!-- rebase-branch=renovate/tomlkit-0.x -->[Update dependency tomlkit to ~=0.15.1](pulls/16) - [ ] <!-- rebase-branch=renovate/typer-0.x -->[Update dependency typer to ~=0.27.2](pulls/17) - [ ] <!-- rebase-branch=renovate/actions-checkout-7.x -->[Update actions/checkout action to v7](pulls/19) - [ ] <!-- rebase-branch=renovate/actions-setup-uv-10.x -->[Update actions/setup-uv action to v10](pulls/22) - [ ] <!-- rebase-branch=renovate/major-github-artifact-actions -->[Update actions/upload-artifact action to v5](pulls/13) - [ ] <!-- rebase-branch=renovate/lock-file-maintenance -->[Lock file maintenance](pulls/14) - [ ] <!-- rebase-all-open-prs -->**Click on this checkbox to rebase all open PRs at once** ## Vulnerabilities > ❗ **Important** > > `53`/`53` CVEs have Renovate fixes. <details><summary>pep621</summary> <blockquote> <details><summary>pyproject.toml</summary> <blockquote> <details><summary>diskcache</summary> <blockquote> - [GHSA-w8v5-vhqr-4h9v](https://osv.dev/vulnerability/GHSA-w8v5-vhqr-4h9v) (fixed in > 5.6.3) - [PYSEC-2026-2447](https://osv.dev/vulnerability/PYSEC-2026-2447) (fixed in > 5.6.3) </blockquote> </details> <details><summary>gitpython</summary> <blockquote> - [GHSA-284h-m62q-gf8w](https://osv.dev/vulnerability/GHSA-284h-m62q-gf8w) (fixed in >= 3.1.59) - [GHSA-2f96-g7mh-g2hx](https://osv.dev/vulnerability/GHSA-2f96-g7mh-g2hx) (fixed in >= 3.1.51) - [GHSA-3f7w-8rr8-f37f](https://osv.dev/vulnerability/GHSA-3f7w-8rr8-f37f) (fixed in >= 3.1.57) - [GHSA-3rp5-jjmw-4wv2](https://osv.dev/vulnerability/GHSA-3rp5-jjmw-4wv2) (fixed in >= 3.1.53) - [GHSA-3wxw-xv34-2frg](https://osv.dev/vulnerability/GHSA-3wxw-xv34-2frg) (fixed in >= 3.1.59) - [GHSA-4gmw-gg2m-w46p](https://osv.dev/vulnerability/GHSA-4gmw-gg2m-w46p) (fixed in >= 3.1.58) - [GHSA-539m-9xh6-q6rr](https://osv.dev/vulnerability/GHSA-539m-9xh6-q6rr) (fixed in >= 3.1.57) - [GHSA-5xxx-qhh7-9287](https://osv.dev/vulnerability/GHSA-5xxx-qhh7-9287) (fixed in >= 3.1.59) - [GHSA-6p8h-3wgx-97gf](https://osv.dev/vulnerability/GHSA-6p8h-3wgx-97gf) (fixed in >= 3.1.54) - [GHSA-7545-fcxq-7j24](https://osv.dev/vulnerability/GHSA-7545-fcxq-7j24) (fixed in >= 3.1.48) - [GHSA-7833-fr7j-v32q](https://osv.dev/vulnerability/GHSA-7833-fr7j-v32q) (fixed in >= 3.1.59) - [GHSA-8mcc-hrx5-hvxc](https://osv.dev/vulnerability/GHSA-8mcc-hrx5-hvxc) (fixed in >= 3.1.59) - [GHSA-94p4-4cq8-9g67](https://osv.dev/vulnerability/GHSA-94p4-4cq8-9g67) (fixed in >= 3.1.55) - [GHSA-956x-8gvw-wg5v](https://osv.dev/vulnerability/GHSA-956x-8gvw-wg5v) (fixed in >= 3.1.51) - [GHSA-9rj7-rf2p-w77r](https://osv.dev/vulnerability/GHSA-9rj7-rf2p-w77r) (fixed in >= 3.1.58) - [GHSA-fjr4-x663-mwxc](https://osv.dev/vulnerability/GHSA-fjr4-x663-mwxc) (fixed in >= 3.1.54) - [GHSA-hh9p-6wh2-4mfc](https://osv.dev/vulnerability/GHSA-hh9p-6wh2-4mfc) (fixed in >= 3.1.58) - [GHSA-hmq2-w58f-27jc](https://osv.dev/vulnerability/GHSA-hmq2-w58f-27jc) (fixed in >= 3.1.58) - [GHSA-jm78-9fvv-mhgr](https://osv.dev/vulnerability/GHSA-jm78-9fvv-mhgr) (fixed in >= 3.1.58) - [GHSA-mv93-w799-cj2w](https://osv.dev/vulnerability/GHSA-mv93-w799-cj2w) (fixed in >= 3.1.50) - [GHSA-p538-c434-8v24](https://osv.dev/vulnerability/GHSA-p538-c434-8v24) (fixed in >= 3.1.56) - [GHSA-r9mr-m37c-5fr3](https://osv.dev/vulnerability/GHSA-r9mr-m37c-5fr3) (fixed in >= 3.1.54) - [GHSA-rpm5-65cw-6hj4](https://osv.dev/vulnerability/GHSA-rpm5-65cw-6hj4) (fixed in >= 3.1.47) - [GHSA-rwj8-pgh3-r573](https://osv.dev/vulnerability/GHSA-rwj8-pgh3-r573) (fixed in >= 3.1.52) - [GHSA-v87r-6q3f-2j67](https://osv.dev/vulnerability/GHSA-v87r-6q3f-2j67) (fixed in >= 3.1.49) - [GHSA-wvpp-8hx9-p66j](https://osv.dev/vulnerability/GHSA-wvpp-8hx9-p66j) (fixed in >= 3.1.58) - [GHSA-x2qx-6953-8485](https://osv.dev/vulnerability/GHSA-x2qx-6953-8485) (fixed in >= 3.1.47) - [PYSEC-2026-2160](https://osv.dev/vulnerability/PYSEC-2026-2160) (fixed in >= 3.1.47) - [PYSEC-2026-2161](https://osv.dev/vulnerability/PYSEC-2026-2161) (fixed in >= 3.1.47) - [PYSEC-2026-2162](https://osv.dev/vulnerability/PYSEC-2026-2162) (fixed in >= 3.1.48) - [PYSEC-2026-2163](https://osv.dev/vulnerability/PYSEC-2026-2163) (fixed in >= 3.1.49) - [PYSEC-2026-3783](https://osv.dev/vulnerability/PYSEC-2026-3783) (fixed in >= 3.1.58) - [PYSEC-2026-3784](https://osv.dev/vulnerability/PYSEC-2026-3784) (fixed in >= 3.1.58) - [PYSEC-2026-3785](https://osv.dev/vulnerability/PYSEC-2026-3785) (fixed in >= 3.1.59) - [PYSEC-2026-3786](https://osv.dev/vulnerability/PYSEC-2026-3786) (fixed in >= 3.1.59) - [PYSEC-2026-3787](https://osv.dev/vulnerability/PYSEC-2026-3787) (fixed in >= 3.1.59) - [PYSEC-2026-3788](https://osv.dev/vulnerability/PYSEC-2026-3788) (fixed in >= 3.1.59) - [PYSEC-2026-3836](https://osv.dev/vulnerability/PYSEC-2026-3836) (fixed in >= 3.1.51) - [PYSEC-2026-3837](https://osv.dev/vulnerability/PYSEC-2026-3837) (fixed in >= 3.1.59) - [PYSEC-2026-3838](https://osv.dev/vulnerability/PYSEC-2026-3838) (fixed in >= 3.1.58) - [PYSEC-2026-3839](https://osv.dev/vulnerability/PYSEC-2026-3839) (fixed in >= 3.1.51) - [PYSEC-2026-3840](https://osv.dev/vulnerability/PYSEC-2026-3840) (fixed in >= 3.1.58) - [PYSEC-2026-3841](https://osv.dev/vulnerability/PYSEC-2026-3841) (fixed in >= 3.1.58) - [PYSEC-2026-3842](https://osv.dev/vulnerability/PYSEC-2026-3842) (fixed in >= 3.1.52) - [PYSEC-2026-3843](https://osv.dev/vulnerability/PYSEC-2026-3843) (fixed in >= 3.1.58) - [PYSEC-2026-3948](https://osv.dev/vulnerability/PYSEC-2026-3948) (fixed in >= 3.1.57) - [PYSEC-2026-3949](https://osv.dev/vulnerability/PYSEC-2026-3949) (fixed in >= 3.1.57) - [PYSEC-2026-3950](https://osv.dev/vulnerability/PYSEC-2026-3950) (fixed in >= 3.1.56) - [PYSEC-2026-3951](https://osv.dev/vulnerability/PYSEC-2026-3951) (fixed in >= 3.1.55) - [PYSEC-2026-3952](https://osv.dev/vulnerability/PYSEC-2026-3952) (fixed in >= 3.1.54) - [PYSEC-2026-3953](https://osv.dev/vulnerability/PYSEC-2026-3953) (fixed in >= 3.1.54) </blockquote> </details> </blockquote> </details> </blockquote> </details> ## Detected Dependencies <details><summary>github-actions (1)</summary> <blockquote> <details><summary>.forgejo/workflows/actions.yaml (5)</summary> - `actions/checkout v6@d23441a48e516b6c34aea4fa41551a30e30af803` → [Updates: `v7`] - `actions/setup-uv v6@d0cc045d04ccac9d8b7881df0226f9e82c39688e` → [Updates: `v10.1.0`] - `actions/upload-artifact v4@16871d9e8cfcf27ff31822cac382bbb5450f1e1e` → [Updates: `v5`] - `actions/checkout v6@d23441a48e516b6c34aea4fa41551a30e30af803` → [Updates: `v7`] - `actions/setup-uv v6@d0cc045d04ccac9d8b7881df0226f9e82c39688e` → [Updates: `v10.1.0`] </details> </blockquote> </details> <details><summary>pep621 (1)</summary> <blockquote> <details><summary>pyproject.toml (9)</summary> - `python ~=3.14.0` - `diskcache >=5.6.3` - `gitpython ~=3.1.45` → [Updates: `~=3.1.45`] - `pydantic >=2.13.2` - `pyforgejo ~=2.0.5` - `tomlkit ~=0.14.0` → [Updates: `~=0.15.1`] - `typer ~=0.25.0` → [Updates: `~=0.27.2`] - `basedpyright ~=1.39.3` → [Updates: `~=1.40.1`] - `ruff ~=0.15.12` → [Updates: `~=0.16.7`] </details> </blockquote> </details> <details><summary>renovate-config (1)</summary> <blockquote> <details><summary>renovate.json</summary> </details> </blockquote> </details>
cswimr locked as Off-topic and limited conversation to collaborators 2026-04-27 23:17:33 -04:00
cswimr unlocked this conversation 2026-05-02 08:08:26 -04:00
cswimr locked as Comments unnecessary and limited conversation to collaborators 2026-05-02 08:08:30 -04:00
This discussion has been locked. Commenting is limited to contributors.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
GalacticFactory/GalacticFactoryUtils#4
No description provided.