Weasyl / weasyl

The website.
https://www.weasyl.com
Apache License 2.0
118 stars 33 forks source link

Bump pyotp from 2.3.0 to 2.8.0 in /etc #1280

Closed dependabot[bot] closed 7 months ago

dependabot[bot] commented 1 year ago

Bumps pyotp from 2.3.0 to 2.8.0.

Release notes

Sourced from pyotp's releases.

v2.8.0

  • Modify OTP generation to run in constant time (#148)

    • Documentation improvements

    • Drop Python 3.6 support; introduce Python 3.11 support

v2.7.0

  • Support Steam TOTP (#142)

    • Build, test, and documentation updates

v2.6.0

  • Raise default and minimum base32 secret length to 32, and hex secret length to 40 (160 bits as recommended by the RFC) (#115).

    • Fix issue where provisioning_uri would return invalid results after calling verify() (#115).

v2.5.1

  • parse_uri accepts and ignores optional image parameter (#114)

v2.5.0

  • Add optional image parameter to provisioning_uri (#113)

    • Support for 7-digit codes in 'parse_uri' (#111)

    • Raise default and minimum base32 secret length to 26

v2.4.1

  • parse_uri: Fix handling of period, counter (#108)

    • Add support for timezone aware datetime as argument to TOTP.timecode() (#107)

v2.4.0

  • Fix data type for at(for_time) (#85)

    • Add support for parsing provisioning URIs (#84)

    • Raise error when trying to generate secret that is too short (The secret must be at least 128 bits)

    • Add random_hex function (#82)

Changelog

Sourced from pyotp's changelog.

Changes for v2.8.0 (2022-12-13)

  • Modify OTP generation to run in constant time (#148)

  • Documentation improvements

  • Drop Python 3.6 support; introduce Python 3.11 support

Changes for v2.7.0 (2022-09-11)

  • Support Steam TOTP (#142)

  • Build, test, and documentation updates

Changes for v2.6.0 (2021-02-04)

  • Raise default and minimum base32 secret length to 32, and hex secret length to 40 (160 bits as recommended by the RFC) (#115).

  • Fix issue where provisioning_uri would return invalid results after calling verify() (#115).

Changes for v2.5.1 (2021-01-29)

  • parse_uri accepts and ignores optional image parameter (#114)

Changes for v2.5.0 (2021-01-29)

  • Add optional image parameter to provisioning_uri (#113)

  • Support for 7-digit codes in ‘parse_uri’ (#111)

  • Raise default and minimum base32 secret length to 26

Changes for v2.4.1 (2020-10-16)

  • parse_uri: Fix handling of period, counter (#108)

  • Add support for timezone aware datetime as argument to TOTP.timecode() (#107)

Changes for v2.4.0 (2020-07-29)

... (truncated)

Commits


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
dependabot[bot] commented 7 months ago

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.