Skip to content

Dependabot Group Update#1465

Open
Thomas-Boyle wants to merge 2 commits intomasterfrom
security-quality-dependabot-group-updates
Open

Dependabot Group Update#1465
Thomas-Boyle wants to merge 2 commits intomasterfrom
security-quality-dependabot-group-updates

Conversation

@Thomas-Boyle
Copy link
Copy Markdown
Contributor

  • Bump brace-expansion from 5.0.3 to 5.0.5 and 2.0.2 to 2.1.0 in package-lock.json.
  • Update yaml from 1.10.2 to 1.10.3 in multiple dependencies within package-lock.json.
  • Upgrade postcss from 8.4.49 to 8.5.14 in package-lock.json.
  • Add overrides for postcss in package.json.
  • Upgrade requests from 2.32.5 to 2.33.1 in multiple poetry.lock files.
  • Update cryptography from 46.0.5 to 46.0.7 in multiple poetry.lock files.
  • Bump boto3 from 1.42.73 to 1.42.97 in tests/perf_tests/poetry.lock.
  • Update pyjwt from 2.11.0 to 2.12.1 in tests/perf_tests/poetry.lock.

These updates enhance security and compatibility with the latest versions of dependencies.

image

- Bump `brace-expansion` from 5.0.3 to 5.0.5 and 2.0.2 to 2.1.0 in `package-lock.json`.
- Update `yaml` from 1.10.2 to 1.10.3 in multiple dependencies within `package-lock.json`.
- Upgrade `postcss` from 8.4.49 to 8.5.14 in `package-lock.json`.
- Add `overrides` for `postcss` in `package.json`.
- Upgrade `requests` from 2.32.5 to 2.33.1 in multiple `poetry.lock` files.
- Update `cryptography` from 46.0.5 to 46.0.7 in multiple `poetry.lock` files.
- Bump `boto3` from 1.42.73 to 1.42.97 in `tests/perf_tests/poetry.lock`.
- Update `pyjwt` from 2.11.0 to 2.12.1 in `tests/perf_tests/poetry.lock`.

These updates enhance security and compatibility with the latest versions of dependencies.
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented May 7, 2026

@Thomas-Boyle Thomas-Boyle temporarily deployed to internal-dev-sandbox May 7, 2026 14:53 — with GitHub Actions Inactive
@Thomas-Boyle Thomas-Boyle temporarily deployed to internal-dev-sandbox May 7, 2026 14:53 — with GitHub Actions Inactive
@Thomas-Boyle Thomas-Boyle temporarily deployed to internal-dev-sandbox May 7, 2026 14:54 — with GitHub Actions Inactive
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant