Skip to content

Bump modelaudit from 0.2.40 to 0.2.42 in /services/quarantine#18

Merged
SecAI-Hub merged 1 commit into
mainfrom
dependabot/pip/services/quarantine/modelaudit-0.2.42
Apr 28, 2026
Merged

Bump modelaudit from 0.2.40 to 0.2.42 in /services/quarantine#18
SecAI-Hub merged 1 commit into
mainfrom
dependabot/pip/services/quarantine/modelaudit-0.2.42

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 28, 2026

Bumps modelaudit from 0.2.40 to 0.2.42.

Changelog

Sourced from modelaudit's changelog.

0.2.42 (2026-04-27)

Bug Fixes

  • require latest picklescan release (a0237a7)

0.2.41 (2026-04-27)

Bug Fixes

  • ci: skip POSIX proof cases on Windows (#1072) (bfa17a3)
  • docker: add apt-get clean and pinned pip constraints to Dockerfile.tensorflow (#1079) (8d9f9b7)
  • harden picklescan call graph RCE detection (#1061) (19c4fc4)
  • harden picklescan stdlib callable detection (f0f57b4)
  • improve test isolation, reduce duplication, and fix command injection risk in test suite (#1078) (3867c83)
  • picklescan: avoid call-graph false positives for PyTorch storage IDs (#1069) (e75ed24)
  • silence stale CodeQL generated import alerts (#1080) (9530740)
  • telemetry: stabilize modelaudit identity (#1071) (592a656)

Documentation

Commits
  • b8d2ea9 chore: release main
  • 45f70a2 ci: verify published PyPI releases
  • 6f63cb5 ci: fail full docker image when ml deps are missing
  • 0c92c74 ci: wait for full docker image result
  • a0237a7 fix: require latest picklescan release
  • dca64f8 chore: release main (#1076)
  • 3867c83 fix: improve test isolation, reduce duplication, and fix command injection ri...
  • 9530740 fix: silence stale CodeQL generated import alerts (#1080)
  • 8d9f9b7 fix(docker): add apt-get clean and pinned pip constraints to Dockerfile.tenso...
  • d7c83ca test(telemetry): cover promptfoo identity edge cases (#1077)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Apr 28, 2026
@SecAI-Hub
Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/pip/services/quarantine/modelaudit-0.2.42 branch from ebfd6e1 to 983700f Compare April 28, 2026 22:30
@SecAI-Hub
Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot dependabot Bot force-pushed the dependabot/pip/services/quarantine/modelaudit-0.2.42 branch from 983700f to 9080c67 Compare April 28, 2026 22:37
@SecAI-Hub
Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [modelaudit](https://github.com/promptfoo/modelaudit) from 0.2.40 to 0.2.42.
- [Release notes](https://github.com/promptfoo/modelaudit/releases)
- [Changelog](https://github.com/promptfoo/modelaudit/blob/main/CHANGELOG.md)
- [Commits](promptfoo/modelaudit@v0.2.40...v0.2.42)

---
updated-dependencies:
- dependency-name: modelaudit
  dependency-version: 0.2.42
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/pip/services/quarantine/modelaudit-0.2.42 branch from 9080c67 to a8f48db Compare April 28, 2026 23:05
@SecAI-Hub SecAI-Hub merged commit 8f1deb0 into main Apr 28, 2026
28 checks passed
@SecAI-Hub SecAI-Hub deleted the dependabot/pip/services/quarantine/modelaudit-0.2.42 branch April 28, 2026 23:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant