Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 2, 2023

This PR contains the following updates:

Package Change Age Confidence
bandit (source, changelog) ==1.7.5 -> ==1.8.6 age confidence
black (changelog) ==23.9.1 -> ==25.9.0 age confidence
cssselect ==1.2.0 -> ==1.3.0 age confidence
django-configurations (source) ==2.4.1 -> ==2.5.1 age confidence
django-cors-headers (changelog) ==4.2.0 -> ==4.9.0 age confidence
dockerflow ==2022.8.0 -> ==2024.4.2 age confidence
factory-boy ==3.3.0 -> ==3.3.3 age confidence
flake8 (changelog) ==6.1.0 -> ==7.3.0 age confidence
gunicorn (changelog) ==21.2.0 -> ==23.0.0 age confidence
ipython ==8.15.0 -> ==9.6.0 age confidence
isort (changelog) ==5.12.0 -> ==6.1.0 age confidence
lxml (source, changelog) ==4.9.3 -> ==6.0.2 age confidence
msgpack (changelog) ==1.0.7 -> ==1.1.2 age confidence
mysqlclient ==2.2.0 -> ==2.2.7 age confidence
psycopg2-binary (source, changelog) ==2.9.8 -> ==2.9.10 age confidence
pylint (changelog) ==2.17.6 -> ==3.3.9 age confidence
pylint-django ==2.5.3 -> ==2.6.1 age confidence
pytest (changelog) ==7.4.2 -> ==8.4.2 age confidence
pytest-cov (changelog) ==4.1.0 -> ==7.0.0 age confidence
pytest-django (changelog) ==4.5.2 -> ==4.11.1 age confidence
pytz ==2023.3.post1 -> ==2025.2 age confidence
responses (changelog) ==0.23.3 -> ==0.25.8 age confidence
sentry-sdk (changelog) ==1.31.0 -> ==2.41.0 age confidence
time-machine (changelog) ==2.13.0 -> ==2.19.0 age confidence
twine ==4.0.2 -> ==6.2.0 age confidence

Release Notes

PyCQA/bandit (bandit)

v1.8.6

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.8.5...1.8.6

v1.8.5

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.8.4...1.8.5

v1.8.3

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.8.2...1.8.3

v1.8.2

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.8.1...1.8.2

v1.8.1

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.8.0...1.8.1

v1.8.0

Compare Source

What's Changed

Full Changelog: PyCQA/bandit@1.7.10...1.8.0

v1.7.10

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.9...1.7.10

v1.7.9

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.8...1.7.9

v1.7.8

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.7...1.7.8

v1.7.7

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.6...1.7.7

v1.7.6

Compare Source

What's Changed

New Contributors

Full Changelog: PyCQA/bandit@1.7.5...1.7.6

psf/black (black)

v25.9.0

Compare Source

Highlights
  • Remove support for pre-python 3.7 await/async as soft keywords/variable names
    (#​4676)
Stable style
  • Fix crash while formatting a long del statement containing tuples (#​4628)
  • Fix crash while formatting expressions using the walrus operator in complex with
    statements (#​4630)
  • Handle # fmt: skip followed by a comment at the end of file (#​4635)
  • Fix crash when a tuple appears in the as clause of a with statement (#​4634)
  • Fix crash when tuple is used as a context manager inside a with statement (#​4646)
  • Fix crash when formatting a \ followed by a \r followed by a comment (#​4663)
  • Fix crash on a \\r\n (#​4673)
  • Fix crash on await ... (where ... is a literal Ellipsis) (#​4676)
  • Fix crash on parenthesized expression inside a type parameter bound (#​4684)
  • Fix crash when using line ranges excluding indented single line decorated items
    (#​4670)
Preview style
  • Fix a bug where one-liner functions/conditionals marked with # fmt: skip would still
    be formatted (#​4552)
  • Improve multiline_string_handling with ternaries and dictionaries (#​4657)
  • Fix a bug where string_processing would not split f-strings directly after
    expressions (#​4680)
  • Wrap the in clause of comprehensions across lines if necessary (#​4699)
  • Remove parentheses around multiple exception types in except and except* without
    as. (#​4720)
  • Add \r style newlines to the potential newlines to normalize file newlines both from
    and to (#​4710)
Parser
  • Rewrite tokenizer to improve performance and compliance (#​4536)
  • Fix bug where certain unusual expressions (e.g., lambdas) were not accepted in type
    parameter bounds and defaults. (#​4602)
Performance
  • Avoid using an extra process when running with only one worker (#​4734)
Integrations
  • Fix the version check in the vim file to reject Python 3.8 (#​4567)
  • Enhance GitHub Action psf/black to read Black version from an additional section in
    pyproject.toml: [project.dependency-groups] (#​4606)
  • Build gallery docker image with python3-slim and reduce image size (#​4686)
Documentation
  • Add FAQ entry for windows emoji not displaying (#​4714)

v25.1.0

Compare Source

Highlights

This release introduces the new 2025 stable style (#​4558), stabilizing the following
changes:

  • Normalize casing of Unicode escape characters in strings to lowercase (#​2916)
  • Fix inconsistencies in whether certain strings are detected as docstrings (#​4095)
  • Consistently add trailing commas to typed function parameters (#​4164)
  • Remove redundant parentheses in if guards for case blocks (#​4214)
  • Add parentheses to if clauses in case blocks when the line is too long (#​4269)
  • Whitespace before # fmt: skip comments is no longer normalized (#​4146)
  • Fix line length computation for certain expressions that involve the power operator
    (#​4154)
  • Check if there is a newline before the terminating quotes of a docstring (#​4185)
  • Fix type annotation spacing between * and more complex type variable tuple (#​4440)

The following changes were not in any previous release:

  • Remove parentheses around sole list items (#​4312)
  • Generic function definitions are now formatted more elegantly: parameters are split
    over multiple lines first instead of type parameter definitions (#​4553)
Stable style
  • Fix formatting cells in IPython notebooks with magic methods and starting or trailing
    empty lines (#​4484)
  • Fix crash when formatting with statements containing tuple generators/unpacking
    (#​4538)
Preview style
  • Fix/remove string merging changing f-string quotes on f-strings with internal quotes
    (#​4498)
  • Collapse multiple empty lines after an import into one (#​4489)
  • Prevent string_processing and wrap_long_dict_values_in_parens from removing
    parentheses around long dictionary values (#​4377)
  • Move wrap_long_dict_values_in_parens from the unstable to preview style (#​4561)
Packaging
  • Store license identifier inside the License-Expression metadata field, see
    PEP 639. (#​4479)
Performance
  • Speed up the is_fstring_start function in Black's tokenizer (#​4541)
Integrations
  • If using stdin with --stdin-filename set to a force excluded path, stdin won't be
    formatted. (#​4539)

v24.10.0

Compare Source

Highlights
  • Black is now officially tested with Python 3.13 and provides Python 3.13
    mypyc-compiled wheels. (#​4436) (#​4449)
  • Black will issue an error when used with Python 3.12.5, due to an upstream memory
    safety issue in Python 3.12.5 that can cause Black's AST safety checks to fail. Please
    use Python 3.12.6 or Python 3.12.4 instead. (#​4447)
  • Black no longer supports running with Python 3.8 (#​4452)
Stable style
  • Fix crashes involving comments in parenthesised return types or X | Y style unions.
    (#​4453)
  • Fix skipping Jupyter cells with unknown %% magic (#​4462)
Preview style
  • Fix type annotation spacing between * and more complex type variable tuple (i.e. def fn(*args: *tuple[*Ts, T]) -> None: pass) (#​4440)
Caching
  • Fix bug where the cache was shared between runs with and without --unstable (#​4466)
Packaging
  • Upgrade version of mypyc used to 1.12 beta (#​4450) (#​4449)
  • blackd now requires a newer version of aiohttp. (#​4451)
Output
  • Added Python target version information on parse error (#​4378)
  • Add information about Black version to internal error messages (#​4457)

v24.8.0

Compare Source

Stable style
  • Fix crash when # fmt: off is used before a closing parenthesis or bracket. (#​4363)
Packaging
  • Packaging metadata updated: docs are explictly linked, the issue tracker is now also
    linked. This improves the PyPI listing for Black. (#​4345)
Parser
  • Fix regression where Black failed to parse a multiline f-string containing another
    multiline string (#​4339)
  • Fix regression where Black failed to parse an escaped single quote inside an f-string
    (#​4401)
  • Fix bug with Black incorrectly parsing empty lines with a backslash (#​4343)
  • Fix bugs with Black's tokenizer not handling \{ inside f-strings very well (#​4422)
  • Fix incorrect line numbers in the tokenizer for certain tokens within f-strings
    (#​4423)
Performance
  • Improve performance when a large directory is listed in .gitignore (#​4415)
Blackd
  • Fix blackd (and all extras installs) for docker container (#​4357)

v24.4.2

Compare Source

This is a bugfix release to fix two regressions in the new f-string parser introduced in
24.4.1.

Parser
  • Fix regression where certain complex f-strings failed to parse (#​4332)
Performance
  • Fix bad performance on certain complex string literals (#​4331)

v24.4.1

Compare Source

Highlights
  • Add support for the new Python 3.12 f-string syntax introduced by PEP 701 (#​3822)
Stable style
  • Fix crash involving indented dummy functions containing newlines (#​4318)
Parser
  • Add support for type parameter defaults, a new syntactic feature added to Python 3.13
    by PEP 696 (#​4327)
Integrations
  • Github Action now works even when git archive is skipped (#​4313)

v24.4.0

Compare Source

Stable style
  • Fix unwanted crashes caused by AST equivalency check (#​4290)
Preview style
  • if guards in case blocks are now wrapped in parentheses when the line is too long.
    (#​4269)
  • Stop moving multiline strings to a new line unless inside brackets (#​4289)
Integrations
  • Add a new option use_pyproject to the GitHub Action psf/black. This will read the
    Black version from pyproject.toml. (#​4294)

v24.3.0

Compare Source

Highlights

This release is a milestone: it fixes Black's first CVE security vulnerability. If you
run Black on untrusted input, or if you habitually put thousands of leading tab
characters in your docstrings, you are strongly encouraged to upgrade immediately to fix
CVE-2024-21503.

This release also fixes a bug in Black's AST safety check that allowed Black to make
incorrect changes to certain f-strings that are valid in Python 3.12 and higher.

Stable style
  • Don't move comments along with delimiters, which could cause crashes (#​4248)
  • Strengthen AST safety check to catch more unsafe changes to strings. Previous versions
    of Black would incorrectly format the contents of certain unusual f-strings containing
    nested strings with the same quote type. Now, Black will crash on such strings until
    support for the new f-string syntax is implemented. (#​4270)
  • Fix a bug where line-ranges exceeding the last code line would not work as expected
    (#​4273)
Performance
  • Fix catastrophic performance on docstrings that contain large numbers of leading tab
    characters. This fixes
    CVE-2024-21503.

Configuration

📅 Schedule: Branch creation - "before 7am on monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Dependency-related tasks. label Oct 2, 2023
@renovate renovate bot force-pushed the renovate/python-dependencies branch 4 times, most recently from 1058e73 to 6df49c1 Compare October 5, 2023 22:43
@renovate renovate bot force-pushed the renovate/python-dependencies branch 2 times, most recently from 31b5add to 36dc4e6 Compare October 17, 2023 17:16
@renovate renovate bot force-pushed the renovate/python-dependencies branch 6 times, most recently from d8f34d4 to af910e6 Compare October 24, 2023 21:33
@renovate renovate bot force-pushed the renovate/python-dependencies branch 6 times, most recently from 31c76bd to a49cd4f Compare November 3, 2023 16:33
@renovate renovate bot force-pushed the renovate/python-dependencies branch 5 times, most recently from f04cb9d to 7aca974 Compare November 15, 2023 00:43
@renovate renovate bot force-pushed the renovate/python-dependencies branch 4 times, most recently from 99b9ceb to c293ba1 Compare November 27, 2023 10:46
@renovate renovate bot force-pushed the renovate/python-dependencies branch from c293ba1 to 8113008 Compare November 29, 2023 13:57
@renovate renovate bot force-pushed the renovate/python-dependencies branch from 8113008 to d4bbfd9 Compare December 9, 2023 05:02
@renovate renovate bot force-pushed the renovate/python-dependencies branch from 57ca1d1 to 36188b4 Compare July 22, 2025 12:16
@renovate renovate bot force-pushed the renovate/python-dependencies branch 2 times, most recently from 6c37d2e to 3d69986 Compare July 30, 2025 13:04
@renovate renovate bot force-pushed the renovate/python-dependencies branch 2 times, most recently from d0aed82 to 3c17740 Compare August 10, 2025 07:41
@renovate renovate bot force-pushed the renovate/python-dependencies branch 3 times, most recently from c5384c0 to 42ea0de Compare August 19, 2025 19:49
@renovate renovate bot force-pushed the renovate/python-dependencies branch 2 times, most recently from 5eb4098 to 69318e6 Compare August 26, 2025 17:09
@renovate renovate bot force-pushed the renovate/python-dependencies branch 6 times, most recently from 5e095ae to ed76c59 Compare September 6, 2025 17:20
@renovate renovate bot force-pushed the renovate/python-dependencies branch 3 times, most recently from 08e57db to befd580 Compare September 9, 2025 17:00
@renovate renovate bot force-pushed the renovate/python-dependencies branch 3 times, most recently from 05ee962 to 965c1d6 Compare September 22, 2025 05:12
@renovate renovate bot force-pushed the renovate/python-dependencies branch 3 times, most recently from fd8af37 to c00a3bc Compare October 1, 2025 22:09
@renovate renovate bot force-pushed the renovate/python-dependencies branch 3 times, most recently from e50d149 to 41cf609 Compare October 8, 2025 11:38
@renovate renovate bot force-pushed the renovate/python-dependencies branch from 41cf609 to 51c0ad6 Compare October 9, 2025 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Dependency-related tasks.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants