Skip to content

fix(deps) Update all non-major dependencies#122

Open
renovate[bot] wants to merge 1 commit into
devfrom
renovate/all-minor-patch
Open

fix(deps) Update all non-major dependencies#122
renovate[bot] wants to merge 1 commit into
devfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Feb 11, 2024

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@semantic-release/npm 11.0.211.0.3 age confidence devDependencies patch
Flask-SQLAlchemy (changelog) 3.0.53.1.1 age confidence dev-dependencies minor
asottile/pyupgrade v3.15.0v3.21.2 age confidence repository minor
bandit (source, changelog) 1.7.51.9.4 age confidence dev-dependencies minor
boto3 1.33.131.43.36 age confidence dev-dependencies minor
cachelib (changelog) ^0.10.0^0.14.0 age confidence dependencies minor
coverage 7.2.77.14.3 age confidence dev-dependencies minor
elasticsearch 8.12.08.19.3 age confidence dev-dependencies minor
google-cloud-datastore (source) 2.19.02.25.0 age confidence dev-dependencies minor
google-cloud-firestore (source) 2.14.02.28.0 age confidence dev-dependencies minor
isort (changelog) 5.11.55.13.2 age confidence dev-dependencies minor
macisamuele/language-formatters-pre-commit-hooks v2.12.0v2.16.0 age confidence repository minor
myint/autoflake v2.2.1v2.3.3 age confidence repository minor
mypy (changelog) 1.4.11.20.2 age confidence dev-dependencies minor
peewee (changelog) 3.17.03.19.0 age confidence dev-dependencies minor
pre-commit/pre-commit-hooks v4.5.0v4.6.0 age confidence repository minor
pymongo 4.7.34.17.0 age confidence dev-dependencies minor
python 3.103.14 age confidence uses-with minor
redis (changelog) 5.0.15.3.1 age confidence dev-dependencies minor
semantic-release 23.0.023.1.1 age confidence devDependencies minor
supercharge/mongodb-github-action v1.10.01.12.1 age confidence action minor
supercharge/redis-github-action 1.8.01.8.1 age confidence action patch
tox (changelog) 4.8.04.56.1 age confidence dev-dependencies minor

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

semantic-release/npm (@​semantic-release/npm)

v11.0.3

Compare Source

Bug Fixes

even though our existing range allowed anyone to update as soon as the new npm version was available, this will encourage being on a version that does not report the ip vulnerability a bit more forcefully

asottile/pyupgrade (asottile/pyupgrade)

v3.21.2

Compare Source

v3.21.1

Compare Source

v3.21.0

Compare Source

v3.20.0

Compare Source

v3.19.1

Compare Source

v3.19.0

Compare Source

v3.18.0

Compare Source

v3.17.0

Compare Source

v3.16.0

Compare Source

v3.15.2

Compare Source

v3.15.1

Compare Source

PyCQA/bandit (bandit)

v1.9.4

Compare Source

What's Changed
New Contributors

Full Changelog: PyCQA/bandit@1.9.3...1.9.4

v1.9.3

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.9.2...1.9.3

v1.9.2

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.9.1...1.9.2

v1.9.1

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.9.0...1.9.1

v1.8.6

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.8.5...1.8.6

v1.8.5

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.8.4...1.8.5

v1.8.3

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.8.2...1.8.3

v1.8.2

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.8.1...1.8.2

v1.8.1

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.8.0...1.8.1

v1.8.0

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.7.10...1.8.0

v1.7.10

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.9...1.7.10

v1.7.9

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.8...1.7.9

v1.7.8

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.7...1.7.8

v1.7.7

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.6...1.7.7

v1.7.6

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.5...1.7.6

boto/boto3 (boto3)

v1.43.36

Compare Source

=======

  • api-change:kafka: [botocore] Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers.

v1.43.35

Compare Source

=======

  • api-change:application-signals: [botocore] Application Signals now supports dynamic instrumentation and Service Events telemetry. Add instrumentation at runtime without restarts, and use fine-grained profiling data to quickly pinpoint latency and error root causes.
  • api-change:bedrock-agentcore: [botocore] Adds an optional extractionMode field to CreateEvent. SKIP retains the event in short-term memory but excludes it from long-term memory extraction.
  • api-change:directconnect: [botocore] Added VIF rate limiting support for AWS Direct Connect, allowing customers to set bandwidth allocations on virtual interfaces to manage traffic on dedicated connections.
  • api-change:ec2: [botocore] This release adds support for AMI Watermark and Allowed AMIs integration
  • api-change:endpoint-rules: [botocore] Update endpoint-rules client to latest version
  • api-change:guardduty: [botocore] Added AI-powered investigations that automatically analyze security findings, correlate related activity, and produce structured summaries with risk assessment, confidence scoring, MITRE technique classification, and actionable next steps.
  • api-change:kafka: [botocore] Amazon MSK Replicator now supports mTLS authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require mutual TLS for client authentication. This capability is supported when replicating to Amazon MSK Express brokers.
  • api-change:lambda: [botocore] Add support for tagging Network Connector resources in AWS Lambda.
  • api-change:lambda-core: [botocore] Initial release of the AWS Lambda Core SDK with APIs to create, manage, and tag network connectors that enable Lambda compute resources to access private resources in your Amazon VPC.
  • api-change:lambda-microvms: [botocore] Lambda MicroVMs GA launch. Lambda MicroVMs enable isolated and highly responsive execution of user-supplied or LLM-generated code.
  • api-change:logs: [botocore] CloudWatch Logs Updates - New APIs introduced to support syslog ingestion to a log group. For more information, see CloudWatch Logs API documentation.
  • api-change:mediaconnect: [botocore] AWS MediaConnect now supports Content Quality Analysis for Router Inputs, enabling detection of black frames, frozen frames, and silent audio with configurable thresholds.
  • api-change:omics: [botocore] Adds support for scratch ephemeral storage mounted at tmp
  • api-change:quicksight: [botocore] Updated the Amazon Quick Spaces API to remove unsupported SPACE and ARTIFACT values from the SpaceQuickSightResourceType enum.

v1.43.34

Compare Source

=======

  • api-change:appstream: [botocore] Amazon WorkSpaces Agent Access now supports domain-joined fleets for enterprise identity integration, real-time agent observation with instant stop controls, and MCP tool forwarding for lower-latency, cost-effective desktop tool access.
  • api-change:bedrock-agent: [botocore] Add support for metadata-only retrieval on GetFlow, GetFlowVersion, and GetPrompt APIs.
  • api-change:connect: [botocore] This is the release for point based scoring system and the evaluation form validation project
  • api-change:glue: [botocore] Adds the SearchAssets operation for discovering assets in the AWS Glue Data Catalog using full-text search and filters. Minor naming refinements across the Glossary Terms and Attachment APIs for consistency.
  • api-change:opensearch: [botocore] This release introduces data source attachment APIs, enabling users to attach and detach Amazon OpenSearch Service domains and Amazon OpenSearch Serverless collections to an OpenSearch application.

v1.43.33

Compare Source

=======

  • api-change:application-autoscaling: [botocore] Adds support for ECS high-resolution predefined scaling metrics (ECSServiceAverageCPUUtilizationHighResolution, ECSServiceAverageMemoryUtilizationHighResolution) enabling 20-second metric periods for faster scaling
  • api-change:batch: [botocore] Adds Support for ordered allocation strategies- BEST-FIT-PROGRESSIVE-ORDERED or SPOT-CAPACITY-OPTIMIZED-PRIORITIZED
  • api-change:cognito-idp: [botocore] In order to support the new TLS Self-Service feature, this change adds SecurityPolicyType to CustomDomainConfigType. During CreateUserPoolDomain and UpdateUserPoolDomain this is used to select a custom domain's TLS enforcement, and for DescribeUserPoolDomain it informs users about the current TLS.
  • api-change:compute-optimizer: [botocore] This release surfaces two new metrics Volume IOPS Exceeded and Volume Throughput Exceeded into EBS volume rightsizing recommendations.
  • api-change:ec2: [botocore] Documentation updates clarifying CancelCapacityReservation cancellable states
  • api-change:ecs: [botocore] Amazon ECS services now support high resolution (20 second) CloudWatch metrics for CPUUtilization and MemoryUtilization. Use these metrics for faster service auto scaling.
  • api-change:eks: [botocore] Adds support for configurable control plane egress routing in Amazon EKS, allowing you to route control plane egress traffic through your VPC and control how the control plane reaches resources in your network such as webhook servers and OIDC providers.
  • api-change:gamelift: [botocore] Amazon GameLift Servers has launched support for customizing Linux capabilities in container fleets. You can now specify additional Linux capabilities for containers in a container group definition, giving you finer control over the default Docker capabilities available to your containers.
  • api-change:healthlake: [botocore] Adding New Configurations to the FHIR Create Datastore. The new configurations include NLP Configuration, AnalyticsConfiguration, ProfileConfiguration
  • api-change:lambda: [botocore] Converging and fixing existing documentation gaps in Lambda SDK
  • api-change:logs: [botocore] Added optional startFromHead parameter to FilterLogEvents enabling descending timestamp order (newest first) when set to false. Default true preserves existing ascending order. Reverse sorting requires a startTime on or after Jan 1, 2024.
  • api-change:sagemaker: [botocore] Adds support for automatic AMI patching on HyperPod clusters. Customers can configure patching strategies to automatically apply security patch with zero job termination. Customers can also specify an AMI version at instance group level and update cluster software to a certain AMI version.
  • api-change:synthetics: [botocore] CloudWatch Synthetics adds support for multi-location canaries. Customers can now monitor their endpoints from multiple locations with centralized management from a primary location. The SDK includes new parameters for configuring multiple locations and tracking their state.

v1.43.32

Compare Source

=======

  • api-change:bedrock-agent: [botocore] Launching Bedrock Managed Knowledge Bases. Added support for

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Chicago)

  • Branch creation
    • "before 10pm on Sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Feb 11, 2024

Copy link
Copy Markdown
Author

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: poetry.lock
Updating dependencies
Resolving dependencies...

Creating virtualenv flask-session2-hlBlwS4--py3.12 in /home/ubuntu/.cache/pypoetry/virtualenvs

The current project's Python requirement (>=3.7.2,<4.0.0) is not compatible with some of the required packages Python requirement:
  - cachelib requires Python >=3.8, so it will not be satisfied for Python >=3.7.2,<3.8

Because no versions of cachelib match >0.13.0,<0.14.0
 and cachelib (0.13.0) requires Python >=3.8, cachelib is forbidden.
So, because flask-session2 depends on cachelib (^0.13.0), version solving failed.

  • Check your dependencies Python requirement: The Python requirement can be specified via the `python` or `markers` properties
    
    For cachelib, a possible solution would be to set the `python` property to ">=3.8,<4.0.0"

    https://python-poetry.org/docs/dependency-specification/#python-restricted-dependencies,
    https://python-poetry.org/docs/dependency-specification/#using-environment-markers

@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 7 times, most recently from f711d1f to 9999140 Compare February 17, 2024 04:19
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from 8f12b36 to 6a5e71e Compare February 25, 2024 11:43
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 113102d to 63b8c12 Compare March 1, 2024 21:29
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from b35674f to c43db40 Compare March 6, 2024 01:55
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 10 times, most recently from 935cb6b to d9c204f Compare March 22, 2024 17:23
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 9828dc2 to 8c00cb7 Compare March 29, 2024 20:07
@renovate renovate Bot force-pushed the renovate/all-minor-patch branch 7 times, most recently from aee391f to 049be56 Compare April 6, 2024 21:43
@renovate

renovate Bot commented May 10, 2024

Copy link
Copy Markdown
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: poetry.lock
Updating dependencies
Resolving dependencies...

Creating virtualenv flask-session2-hlBlwS4--py3.14 in /home/ubuntu/.cache/pypoetry/virtualenvs

The current project's Python requirement (>=3.7.2,<4.0.0) is not compatible with some of the required packages Python requirement:
  - cachelib requires Python >=3.8, so it will not be satisfied for Python >=3.7.2,<3.8

Because no versions of cachelib match >0.14.0,<0.15.0
 and cachelib (0.14.0) requires Python >=3.8, cachelib is forbidden.
So, because flask-session2 depends on cachelib (^0.14.0), version solving failed.

  • Check your dependencies Python requirement: The Python requirement can be specified via the `python` or `markers` properties
    
    For cachelib, a possible solution would be to set the `python` property to ">=3.8,<4.0.0"

    https://python-poetry.org/docs/dependency-specification/#python-restricted-dependencies,
    https://python-poetry.org/docs/dependency-specification/#using-environment-markers

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants