Repository navigation
build(deps): bump the python-security group across 1 directory with 8 updates - #45
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
This was referenced Sep 18, 2026
… updates Bumps the python-security group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [pillow](https://github.com/python-pillow/Pillow) | `10.4.0` | `12.3.0` | | [bleach](https://github.com/mozilla/bleach) | `6.3.0` | `6.4.0` | | [idna](https://github.com/kjd/idna) | `3.13` | `3.15` | | [jupyter-server](https://github.com/jupyter-server/jupyter_server) | `2.18.2` | `2.20.0` | | [jupyterlab](https://github.com/jupyterlab/jupyterlab) | `4.5.7` | `4.5.11` | | [mistune](https://github.com/lepture/mistune) | `3.2.1` | `3.3.3` | | [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.2` | `1.2.1` | | [soupsieve](https://github.com/facelessuser/soupsieve) | `2.8.3` | `2.9` | Updates `pillow` from 10.4.0 to 12.3.0 - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@10.4.0...12.3.0) Updates `bleach` from 6.3.0 to 6.4.0 - [Changelog](https://github.com/mozilla/bleach/blob/main/CHANGES) - [Commits](mozilla/bleach@v6.3.0...v6.4.0) Updates `idna` from 3.13 to 3.15 - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md) - [Commits](kjd/idna@v3.13...v3.15) Updates `jupyter-server` from 2.18.2 to 2.20.0 - [Release notes](https://github.com/jupyter-server/jupyter_server/releases) - [Changelog](https://github.com/jupyter-server/jupyter_server/blob/main/CHANGELOG.md) - [Commits](jupyter-server/jupyter_server@v2.18.2...v2.20.0) Updates `jupyterlab` from 4.5.7 to 4.5.11 - [Release notes](https://github.com/jupyterlab/jupyterlab/releases) - [Changelog](https://github.com/jupyterlab/jupyterlab/blob/main/RELEASE.md) - [Commits](https://github.com/jupyterlab/jupyterlab/compare/@jupyterlab/lsp@4.5.7...@jupyterlab/lsp@4.5.11) Updates `mistune` from 3.2.1 to 3.3.3 - [Release notes](https://github.com/lepture/mistune/releases) - [Changelog](https://github.com/lepture/mistune/blob/main/docs/changes.rst) - [Commits](lepture/mistune@v3.2.1...v3.3.3) Updates `msgpack` from 1.1.2 to 1.2.1 - [Release notes](https://github.com/msgpack/msgpack-python/releases) - [Changelog](https://github.com/msgpack/msgpack-python/blob/main/CHANGELOG.md) - [Commits](msgpack/msgpack-python@v1.1.2...v1.2.1) Updates `soupsieve` from 2.8.3 to 2.9 - [Release notes](https://github.com/facelessuser/soupsieve/releases) - [Commits](facelessuser/soupsieve@2.8.3...2.9) --- updated-dependencies: - dependency-name: bleach dependency-version: 6.4.0 dependency-type: direct:production dependency-group: python-security - dependency-name: idna dependency-version: '3.15' dependency-type: direct:production dependency-group: python-security - dependency-name: jupyter-server dependency-version: 2.20.0 dependency-type: direct:production dependency-group: python-security - dependency-name: jupyterlab dependency-version: 4.5.10 dependency-type: direct:production dependency-group: python-security - dependency-name: mistune dependency-version: 3.3.3 dependency-type: direct:production dependency-group: python-security - dependency-name: msgpack dependency-version: 1.2.1 dependency-type: direct:production dependency-group: python-security - dependency-name: pillow dependency-version: 12.3.0 dependency-type: direct:production dependency-group: python-security - dependency-name: soupsieve dependency-version: '2.9' dependency-type: direct:production dependency-group: python-security ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/pip/python-security-8da85bc318
branch
from
October 7, 2026 16:39
abf39f8 to
7985d0f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-security group with 8 updates in the / directory:
10.4.012.3.06.3.06.4.03.133.152.18.22.20.04.5.74.5.113.2.13.3.31.1.21.2.12.8.32.9Updates
pillowfrom 10.4.0 to 12.3.0Release notes
Sourced from pillow's releases.
... (truncated)
Changelog
Sourced from pillow's changelog.
... (truncated)
Commits
bb1d8e812.3.0 version bumpe63fc48Add release notes for SBOM and performance improvements (#9747)13b701bAdd release notes for #96795564ca7List methodsa0920fdSpeed up ImageChops operations (#9738)07e9a6cSpeed upImage.filter()(#9736)a94578cSpeed upImage.getchannel(),Image.merge(),Image.putalpha()and `Image...53e02c4Speed upImage.fill(),Image.linear_gradient()and `Image.radial_gradient...af03747Speed upImage.resample()(#9739)5c9ca56Speed upalpha_composite,matrix,negative,quantize(#9740)Updates
bleachfrom 6.3.0 to 6.4.0Changelog
Sourced from bleach's changelog.
Commits
f0355a7fix: fix last release date in CHANGESae4e8a2chore: bleach 6.4.0 and final release970df58fix: uri-sanitization in formaction attributes7c4867cfix: xss bypass in allowed protocol test using unicode invisible characters913ab75fix: reduce redundancy in workflow jobs218c15afix: rework pip caching4f0b097fix: fix tox platform restrictionse95a79dchore: update pytest91539d4Bump actions/cache from 5.0.3 to 5.0.4cd47b4cfix: handle left-angle-bracket that's not a tag (#733)Updates
idnafrom 3.13 to 3.15Changelog
Sourced from idna's changelog.
Commits
af30a09Release 3.1530314d4Pre-release 3.15rc005d4b21Merge pull request #237 from kjd/convert-docs-to-markdown2987fdbConvert README and HISTORY from reStructuredText to Markdown59fa800Merge pull request #236 from kjd/dependabot/github_actions/actions-f3e34333eadef6983Merge branch 'master' into dependabot/github_actions/actions-f3e34333eabbd8004Merge pull request #234 from StanFromIreland/patch-1edd07c0Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group5557db0Merge branch 'master' into patch-1f11746cMerge pull request #235 from StanFromIreland/patch-2Updates
jupyter-serverfrom 2.18.2 to 2.20.0Release notes
Sourced from jupyter-server's releases.
... (truncated)
Changelog
Sourced from jupyter-server's changelog.
... (truncated)
Commits
05a78adPublish 2.20.06cbee8dMerge commit from fork333e700Fixtest_authorizerhaving a spurious comma in params (#1664)cccd543Fix CI: explicitly pass base-setup inputs to avoid strict validation failurescd16d71Align docs for curve encryption with latest JEP version (#1660)e458061Add a toggle to enable curve encryption for all kernels that support it (#1638)0ceeb4fAdd note in RELEASE.mdb13f8a2Markdown does not work.e885b10Add GHSA reminder in prep-release0e28c90Exclude problematicpywinpty3.0.4 version (#1658)Updates
jupyterlabfrom 4.5.7 to 4.5.11Release notes
Sourced from jupyterlab's releases.
... (truncated)
Commits
ce3f734[ci skip] Publish 4.5.11f6341d1Merge pull request #19794 from krassowski/security-patches-4.5.xe5fab0eBackport #19193f9de43dFix for GHSA-3jqq-pw4j-pqcj0fc18abFix for GHSA-jwrc-gm9j-263p7f9f29eFix for GHSA-6966-vjj6-99xv9e1951eFix for GHSA-3325-v43h-43rvaf5f5b3[ci skip] Publish 4.5.10be9303fBackport of security patches to4.5.xbranch (#19186)a555fe1Reconfigure 4.5.x branch (4.6.x is new stable) (#19060)Updates
mistunefrom 3.2.1 to 3.3.3Release notes
Sourced from mistune's releases.
... (truncated)
Changelog
Sourced from mistune's changelog.
Commits
060f73achore: release 3.3.3ae7e9d5perf: improve for footnotes, ruby and spoilerc2228a2perf: improve performance for math and formatting pluginse001d51perf: improve link label parsing performancecca5ee6fix: add image max depth0938fb7fix: add max_emphasis_depth9946c92tests: update dealine time for pypy4009f67fix: use SAFE_PROTOCOLS instead of HARMFUL_PROTOCOLS3025549Merge pull request #462 from Sanjays2402/fix/markdown-renderer-escape-emphasisb042996fix: escape literal emphasis markers in MarkdownRendererUpdates
msgpackfrom 1.1.2 to 1.2.1Release notes
Sourced from msgpack's releases.
... (truncated)
Changelog
Sourced from msgpack's changelog.
Commits
448d43frelease v1.2.1 (#698)2c56ddbMerge commit from fork0f4f350Bump pypa/cibuildwheel from 4.0.0 to 4.1.0 in the all-dependencies group (#694)