Dependency Dashboard #4

Open
opened 2025-05-20 04:31:59 -04:00 by Renovate · 0 comments
Collaborator

This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.

Repository Problems

Renovate tried to run on this repository, but found these problems.

  • ⚠️ WARN: Merging of PR failed

Abandoned Dependencies

The following dependencies have not received updates for an extended period and may be unmaintained.

View abandoned dependencies (1)

ℹ️ Note

Packages are marked as abandoned when they exceed the abandonmentThreshold since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity.

Datasource Package Last Updated
pep621 lxml-stubs 2024-01-10

Rate-Limited

The following updates are currently rate-limited. To force their creation now, click on a checkbox below.

  • Update dependency ruff to ~=0.16.1

Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

PR Closed (Blocked)

The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.

Vulnerabilities

Important

44/44 CVEs have Renovate fixes.

pep621
pyproject.toml
aiohttp

Detected Dependencies

github-actions (1)
.forgejo/workflows/actions.yaml (11)
  • actions/checkout v5@08c6903cd8c0fde910a37f88322edcfb5dd907a8 → [Updates: v7, v5]
  • actions/setup-uv v6@d9e0f98d3fc6adb07d1e3d37f3043649ddad06a1 → [Updates: v9.0.0, v6]
  • actions/upload-artifact v4@16871d9e8cfcf27ff31822cac382bbb5450f1e1e → [Updates: v5]
  • actions/checkout v5@08c6903cd8c0fde910a37f88322edcfb5dd907a8 → [Updates: v7, v5]
  • actions/setup-uv v6@d9e0f98d3fc6adb07d1e3d37f3043649ddad06a1 → [Updates: v9.0.0, v6]
  • actions/checkout v5@08c6903cd8c0fde910a37f88322edcfb5dd907a8 → [Updates: v7, v5]
  • actions/setup-uv v6@7edac99f961f18b581bbd960d59d049f04c0002f → [Updates: v9.0.0, v6]
  • actions/upload-artifact v4@16871d9e8cfcf27ff31822cac382bbb5450f1e1e → [Updates: v5]
  • catthehacker/ubuntu act-latest@sha256:ee77eaa905d10ad76345b58b0803d698ea63faa9a27047898530cbcd47f90eb9 → [Updates: act-latest]
  • catthehacker/ubuntu act-latest@sha256:ee77eaa905d10ad76345b58b0803d698ea63faa9a27047898530cbcd47f90eb9 → [Updates: act-latest]
  • catthehacker/ubuntu act-latest@sha256:ee77eaa905d10ad76345b58b0803d698ea63faa9a27047898530cbcd47f90eb9 → [Updates: act-latest]
pep621 (1)
pyproject.toml (16)
  • python <4.0,>=3.11
  • aiohttp ~=3.13 → [Updates: ~=3.13]
  • lxml ~=6.0
  • pydantic >=2.11.10
  • ruff ~=0.15.3 → [Updates: ~=0.16.1]
  • basedpyright ~=1.39.3
  • pytest ~=9.0.2 → [Updates: ~=9.1.1]
  • pytest-cov ~=7.1.0
  • zensical ~=0.0.16
  • mkdocstrings-python ~=2.0.1
  • ipython ~=9.13.0 → [Updates: ~=9.16.0]
  • rich ~=15.0.0
  • lxml-stubs >=0.5.1
  • typer ~=0.25.0 → [Updates: ~=0.27.0]
  • aiohttp ~=3.13 → [Updates: ~=3.13]
  • orjson ~=3.11
renovate-config (1)
renovate.json
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more. ## Repository Problems Renovate tried to run on this repository, but found these problems. - ⚠️ WARN: Merging of PR failed ## Abandoned Dependencies The following dependencies have not received updates for an extended period and may be unmaintained. <details> <summary>View abandoned dependencies (1)</summary> > ℹ️ **Note** > Packages are marked as abandoned when they exceed the [`abandonmentThreshold`](https://docs.renovatebot.com/configuration-options/#abandonmentthreshold) since their last release. Unlike deprecated packages with official notices, abandonment is detected by release inactivity. > | Datasource | Package | Last Updated | |------------|------|-------------| | pep621 | [lxml-stubs](https://github.com/lxml/lxml-stubs) | `2024-01-10` | </details> ## Rate-Limited The following updates are currently rate-limited. To force their creation now, click on a checkbox below. - [ ] <!-- unlimit-branch=renovate/ruff-0.x -->Update dependency ruff to ~=0.16.1 ## Open The following updates have all been created. To force a retry/rebase of any, click on a checkbox below. - [ ] <!-- rebase-branch=renovate/pypi-aiohttp-vulnerability -->[Update dependency aiohttp to v3.14.1 [SECURITY]](pulls/95) - [ ] <!-- rebase-branch=renovate/actions-checkout-digest -->[Update actions/checkout digest to fbc6f39](pulls/86) - [ ] <!-- rebase-branch=renovate/catthehacker-ubuntu-act-latest -->[Update catthehacker/ubuntu:act-latest Docker digest to 05207c9](pulls/92) - [ ] <!-- rebase-branch=renovate/ipython-9.x -->[Update dependency ipython to ~=9.16.0](pulls/94) - [ ] <!-- rebase-branch=renovate/pytest-9.x -->[Update dependency pytest to ~=9.1.1](pulls/96) - [ ] <!-- rebase-branch=renovate/typer-0.x -->[Update dependency typer to ~=0.27.0](pulls/93) - [ ] <!-- rebase-branch=renovate/actions-checkout-7.x -->[Update actions/checkout action to v7](pulls/97) - [ ] <!-- rebase-branch=renovate/actions-setup-uv-9.x -->[Update actions/setup-uv action to v9](pulls/98) - [ ] <!-- rebase-branch=renovate/major-github-artifact-actions -->[Update GitHub Artifact Actions to v5](pulls/90) - [ ] <!-- rebase-branch=renovate/lock-file-maintenance -->[Lock file maintenance](pulls/91) - [ ] <!-- rebase-all-open-prs -->**Click on this checkbox to rebase all open PRs at once** ## PR Closed (Blocked) The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below. - [ ] <!-- recreate-branch=renovate/actions-setup-uv-digest -->[Update actions/setup-uv digest to d0cc045](pulls/45) ## Vulnerabilities > ❗ **Important** > > `44`/`44` CVEs have Renovate fixes. <details><summary>pep621</summary> <blockquote> <details><summary>pyproject.toml</summary> <blockquote> <details><summary>aiohttp</summary> <blockquote> - [GHSA-2fqr-mr3j-6wp8](https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8) (fixed in >= 3.14.1) - [GHSA-4fvr-rgm6-gqmc](https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc) (fixed in >= 3.14.1) - [GHSA-4m7w-qmgq-4wj5](https://osv.dev/vulnerability/GHSA-4m7w-qmgq-4wj5) (fixed in >= 3.14.1) - [GHSA-63hw-fmq6-xxg2](https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2) (fixed in >= 3.14.1) - [GHSA-9x8q-7h8h-wcw9](https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9) (fixed in >= 3.14.1) - [GHSA-g3cq-j2xw-wf74](https://osv.dev/vulnerability/GHSA-g3cq-j2xw-wf74) (fixed in >= 3.14.1) - [GHSA-hg6j-4rv6-33pg](https://osv.dev/vulnerability/GHSA-hg6j-4rv6-33pg) (fixed in >= 3.14.0) - [GHSA-hpj7-wq8m-9hgp](https://osv.dev/vulnerability/GHSA-hpj7-wq8m-9hgp) (fixed in >= 3.14.1) - [GHSA-jg22-mg44-37j8](https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8) (fixed in >= 3.14.0) - [GHSA-m6qw-4cw2-hm4m](https://osv.dev/vulnerability/GHSA-m6qw-4cw2-hm4m) (fixed in >= 3.14.0) - [GHSA-xcgm-r5h9-7989](https://osv.dev/vulnerability/GHSA-xcgm-r5h9-7989) (fixed in >= 3.14.1) - [PYSEC-2026-2104](https://osv.dev/vulnerability/PYSEC-2026-2104) (fixed in >= 3.14.0) - [PYSEC-2026-2105](https://osv.dev/vulnerability/PYSEC-2026-2105) (fixed in >= 3.14.0) - [PYSEC-2026-2106](https://osv.dev/vulnerability/PYSEC-2026-2106) (fixed in >= 3.14.0) - [PYSEC-2026-2107](https://osv.dev/vulnerability/PYSEC-2026-2107) (fixed in >= 3.14.1) - [PYSEC-2026-2108](https://osv.dev/vulnerability/PYSEC-2026-2108) (fixed in >= 3.14.1) - [PYSEC-2026-2109](https://osv.dev/vulnerability/PYSEC-2026-2109) (fixed in >= 3.14.1) - [PYSEC-2026-2110](https://osv.dev/vulnerability/PYSEC-2026-2110) (fixed in >= 3.14.1) - [PYSEC-2026-2111](https://osv.dev/vulnerability/PYSEC-2026-2111) (fixed in >= 3.14.1) - [PYSEC-2026-2112](https://osv.dev/vulnerability/PYSEC-2026-2112) (fixed in >= 3.14.1) - [PYSEC-2026-2113](https://osv.dev/vulnerability/PYSEC-2026-2113) (fixed in >= 3.14.1) - [PYSEC-2026-237](https://osv.dev/vulnerability/PYSEC-2026-237) (fixed in >= 3.14.1) - [GHSA-2fqr-mr3j-6wp8](https://osv.dev/vulnerability/GHSA-2fqr-mr3j-6wp8) (fixed in >= 3.14.1) - [GHSA-4fvr-rgm6-gqmc](https://osv.dev/vulnerability/GHSA-4fvr-rgm6-gqmc) (fixed in >= 3.14.1) - [GHSA-4m7w-qmgq-4wj5](https://osv.dev/vulnerability/GHSA-4m7w-qmgq-4wj5) (fixed in >= 3.14.1) - [GHSA-63hw-fmq6-xxg2](https://osv.dev/vulnerability/GHSA-63hw-fmq6-xxg2) (fixed in >= 3.14.1) - [GHSA-9x8q-7h8h-wcw9](https://osv.dev/vulnerability/GHSA-9x8q-7h8h-wcw9) (fixed in >= 3.14.1) - [GHSA-g3cq-j2xw-wf74](https://osv.dev/vulnerability/GHSA-g3cq-j2xw-wf74) (fixed in >= 3.14.1) - [GHSA-hg6j-4rv6-33pg](https://osv.dev/vulnerability/GHSA-hg6j-4rv6-33pg) (fixed in >= 3.14.0) - [GHSA-hpj7-wq8m-9hgp](https://osv.dev/vulnerability/GHSA-hpj7-wq8m-9hgp) (fixed in >= 3.14.1) - [GHSA-jg22-mg44-37j8](https://osv.dev/vulnerability/GHSA-jg22-mg44-37j8) (fixed in >= 3.14.0) - [GHSA-m6qw-4cw2-hm4m](https://osv.dev/vulnerability/GHSA-m6qw-4cw2-hm4m) (fixed in >= 3.14.0) - [GHSA-xcgm-r5h9-7989](https://osv.dev/vulnerability/GHSA-xcgm-r5h9-7989) (fixed in >= 3.14.1) - [PYSEC-2026-2104](https://osv.dev/vulnerability/PYSEC-2026-2104) (fixed in >= 3.14.0) - [PYSEC-2026-2105](https://osv.dev/vulnerability/PYSEC-2026-2105) (fixed in >= 3.14.0) - [PYSEC-2026-2106](https://osv.dev/vulnerability/PYSEC-2026-2106) (fixed in >= 3.14.0) - [PYSEC-2026-2107](https://osv.dev/vulnerability/PYSEC-2026-2107) (fixed in >= 3.14.1) - [PYSEC-2026-2108](https://osv.dev/vulnerability/PYSEC-2026-2108) (fixed in >= 3.14.1) - [PYSEC-2026-2109](https://osv.dev/vulnerability/PYSEC-2026-2109) (fixed in >= 3.14.1) - [PYSEC-2026-2110](https://osv.dev/vulnerability/PYSEC-2026-2110) (fixed in >= 3.14.1) - [PYSEC-2026-2111](https://osv.dev/vulnerability/PYSEC-2026-2111) (fixed in >= 3.14.1) - [PYSEC-2026-2112](https://osv.dev/vulnerability/PYSEC-2026-2112) (fixed in >= 3.14.1) - [PYSEC-2026-2113](https://osv.dev/vulnerability/PYSEC-2026-2113) (fixed in >= 3.14.1) - [PYSEC-2026-237](https://osv.dev/vulnerability/PYSEC-2026-237) (fixed in >= 3.14.1) </blockquote> </details> </blockquote> </details> </blockquote> </details> ## Detected Dependencies <details><summary>github-actions (1)</summary> <blockquote> <details><summary>.forgejo/workflows/actions.yaml (11)</summary> - `actions/checkout v5@08c6903cd8c0fde910a37f88322edcfb5dd907a8` → [Updates: `v7`, `v5`] - `actions/setup-uv v6@d9e0f98d3fc6adb07d1e3d37f3043649ddad06a1` → [Updates: `v9.0.0`, `v6`] - `actions/upload-artifact v4@16871d9e8cfcf27ff31822cac382bbb5450f1e1e` → [Updates: `v5`] - `actions/checkout v5@08c6903cd8c0fde910a37f88322edcfb5dd907a8` → [Updates: `v7`, `v5`] - `actions/setup-uv v6@d9e0f98d3fc6adb07d1e3d37f3043649ddad06a1` → [Updates: `v9.0.0`, `v6`] - `actions/checkout v5@08c6903cd8c0fde910a37f88322edcfb5dd907a8` → [Updates: `v7`, `v5`] - `actions/setup-uv v6@7edac99f961f18b581bbd960d59d049f04c0002f` → [Updates: `v9.0.0`, `v6`] - `actions/upload-artifact v4@16871d9e8cfcf27ff31822cac382bbb5450f1e1e` → [Updates: `v5`] - `catthehacker/ubuntu act-latest@sha256:ee77eaa905d10ad76345b58b0803d698ea63faa9a27047898530cbcd47f90eb9` → [Updates: `act-latest`] - `catthehacker/ubuntu act-latest@sha256:ee77eaa905d10ad76345b58b0803d698ea63faa9a27047898530cbcd47f90eb9` → [Updates: `act-latest`] - `catthehacker/ubuntu act-latest@sha256:ee77eaa905d10ad76345b58b0803d698ea63faa9a27047898530cbcd47f90eb9` → [Updates: `act-latest`] </details> </blockquote> </details> <details><summary>pep621 (1)</summary> <blockquote> <details><summary>pyproject.toml (16)</summary> - `python <4.0,>=3.11` - `aiohttp ~=3.13` → [Updates: `~=3.13`] - `lxml ~=6.0` - `pydantic >=2.11.10` - `ruff ~=0.15.3` → [Updates: `~=0.16.1`] - `basedpyright ~=1.39.3` - `pytest ~=9.0.2` → [Updates: `~=9.1.1`] - `pytest-cov ~=7.1.0` - `zensical ~=0.0.16` - `mkdocstrings-python ~=2.0.1` - `ipython ~=9.13.0` → [Updates: `~=9.16.0`] - `rich ~=15.0.0` - `lxml-stubs >=0.5.1` - `typer ~=0.25.0` → [Updates: `~=0.27.0`] - `aiohttp ~=3.13` → [Updates: `~=3.13`] - `orjson ~=3.11` </details> </blockquote> </details> <details><summary>renovate-config (1)</summary> <blockquote> <details><summary>renovate.json</summary> </details> </blockquote> </details>
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
cswimr/PyFlowery#4
No description provided.