Santandersecurityresearch / DrHeader

drHEADer helps with the audit of security headers received in response to a single request or a list of requests.
MIT License
105 stars 26 forks source link

Bump tox from 4.13.0 to 4.21.1 #371

Closed dependabot[bot] closed 1 month ago

dependabot[bot] commented 1 month ago

Bumps tox from 4.13.0 to 4.21.1.

Release notes

Sourced from tox's releases.

4.21.1

What's Changed

Full Changelog: https://github.com/tox-dev/tox/compare/4.21.0...4.21.1

4.21.0

What's Changed

Full Changelog: https://github.com/tox-dev/tox/compare/4.20.0...4.21.0

4.20.0

What's Changed

Full Changelog: https://github.com/tox-dev/tox/compare/4.19.0...4.20.0

4.19.0

What's Changed

Full Changelog: https://github.com/tox-dev/tox/compare/4.18.1...4.19.0

4.18.1

What's Changed

New Contributors

... (truncated)

Changelog

Sourced from tox's changelog.

v4.21.1 (2024-10-02)

Bugfixes - 4.21.1

- Fix error when using ``requires`` within a TOML configuration file - by :user:`gaborbernat`. (:issue:`3386`)
- Fix error when using ``deps`` within a TOML configuration file - by :user:`gaborbernat`. (:issue:`3387`)
- Multiple fixes for the TOML configuration by :user:`gaborbernat`.:
  • Do not fail when there is an empty command within commands.
  • Allow references for set_env by accepting list of dictionaries for it.
  • Do not try to be smart about reference unrolling, instead allow the user to control it via the extend flag, available both for posargs and ref replacements.
  • The ref replacements raw key has been renamed to of. (:issue:3388)

v4.21.0 (2024-09-30)

Features - 4.21.0

  • Native TOML configuration support - by :user:gaborbernat. (:issue:999)

Improved Documentation - 4.21.0

- Update Loader docs - by :user:ziima (:issue:`3352`)

v4.20.0 (2024-09-18)

Features - 4.20.0

- Separate the list dependencies functionality to a separate abstract class allowing code reuse in plugins (such as
  ``tox-uv``) - by :gaborbernat`. (:issue:`3347`)

v4.19.0 (2024-09-17)
--------------------

Features - 4.19.0
  • Support pypy-<major>.<minor> environment names for PyPy environments - by :user:gaborbernat. (:issue:3346)

v4.18.1 (2024-09-07)

Bugfixes - 4.18.1

- Fix and test the string spec for the ``sys.executable`` interpreter (introduced in :pull:`3325`)
  - by :user:`hroncok` (:issue:`3327`)

Improved Documentation - 4.18.1
</tr></table> 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/tox-dev/tox/commit/434ac18d89a843b961c8544bf74e796191c940f0"><code>434ac18</code></a> release 4.21.1</li>
<li><a href="https://github.com/tox-dev/tox/commit/34d3adc0ed537de5d4803b4e244e43eed513c839"><code>34d3adc</code></a> Fix TOML configuration errors (<a href="https://redirect.github.com/tox-dev/tox/issues/3388">#3388</a>)</li>
<li><a href="https://github.com/tox-dev/tox/commit/719b3462b58bd5c4fc12d93cb978f824bc7a610b"><code>719b346</code></a> Update installation.rst</li>
<li><a href="https://github.com/tox-dev/tox/commit/46bef9eff54c53eeced031436d2d1a068b4bfb16"><code>46bef9e</code></a> release 4.21.0</li>
<li><a href="https://github.com/tox-dev/tox/commit/cea105b7007039c830c92ae92aa5792e819ee487"><code>cea105b</code></a> True TOML config support (<a href="https://redirect.github.com/tox-dev/tox/issues/3353">#3353</a>)</li>
<li><a href="https://github.com/tox-dev/tox/commit/a04b039fe0486752ec79733b993d73ecdf282795"><code>a04b039</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/tox-dev/tox/issues/3385">#3385</a>)</li>
<li><a href="https://github.com/tox-dev/tox/commit/f5eba31ed3aeedcb41db64fca5b624a75abff32d"><code>f5eba31</code></a> Update Loader docs (<a href="https://redirect.github.com/tox-dev/tox/issues/3352">#3352</a>)</li>
<li><a href="https://github.com/tox-dev/tox/commit/329db639b5573cf9b5990fe990a3e48789d1fc9a"><code>329db63</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/tox-dev/tox/issues/3350">#3350</a>)</li>
<li><a href="https://github.com/tox-dev/tox/commit/f4b3bd20f268e6da78c2a89b531f364cec35b90b"><code>f4b3bd2</code></a> Bump pypa/gh-action-pypi-publish from 1.10.1 to 1.10.2 (<a href="https://redirect.github.com/tox-dev/tox/issues/3349">#3349</a>)</li>
<li><a href="https://github.com/tox-dev/tox/commit/a04cc3afa08e4641ba8419eb320e738d4ef8180c"><code>a04cc3a</code></a> release 4.20.0</li>
<li>Additional commits viewable in <a href="https://github.com/tox-dev/tox/compare/4.13.0...4.21.1">compare view</a></li>
</ul>
</details>

<br />
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tox&package-manager=pip&previous-version=4.13.0&new-version=4.21.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 1 month ago

Dependabot tried to add @danielcuthbert, @javixeneize, @pealtrufo and @emilejq as reviewers to this PR, but received the following error from GitHub:

POST https://api.github.com/repos/Santandersecurityresearch/DrHeader/pulls/371/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the Santandersecurityresearch/DrHeader repository. // See: https://docs.github.com/rest/pulls/review-requests#request-reviewers-for-a-pull-request
dependabot[bot] commented 1 month ago

Superseded by #372.