greenbone / ospd-openvas

ospd-openvas is an OSP server implementation to allow GVM to remotely control an OpenVAS Scanner
GNU Affero General Public License v3.0
68 stars 58 forks source link

Build(deps): Bump the python-packages group with 3 updates #983

Closed dependabot[bot] closed 7 months ago

dependabot[bot] commented 7 months ago

Bumps the python-packages group with 3 updates: lxml, rope and pontos.

Updates lxml from 5.1.0 to 5.2.1

Changelog

Sourced from lxml's changelog.

5.2.1 (2024-04-02)

Bugs fixed

  • LP#2059910: The minimum CPU architecture for the Linux x86 binary wheels was set back to "core2", but with SSE 4.2 enabled.

  • LP#2059977: Element.iterfind("//absolute_path") failed with a SyntaxError where it should have issued a warning.

  • GH#416: The documentation build was using the non-standard which command. Patch by Michał Górny.

5.2.0 (2024-03-30)

Other changes

  • LP#1958539: The lxml.html.clean implementation suffered from several (only if used) security issues in the past and was now extracted into a separate library:

    https://github.com/fedora-python/lxml_html_clean

    Projects that use lxml without "lxml.html.clean" will not notice any difference, except that they won't have potentially vulnerable code installed. The module is available as an "extra" setuptools dependency "lxml[html_clean]", so that Projects that need "lxml.html.clean" will need to switch their requirements from "lxml" to "lxml[html_clean]", or install the new library themselves.

  • The minimum CPU architecture for the Linux x86 binary wheels was upgraded to "sandybridge" (launched 2011), and glibc 2.28 / gcc 12 (manylinux_2_28) wheels were added.

  • Built with Cython 3.0.10.

5.1.2 (2024-??-??)

Bugs fixed

  • LP#2059977: Element.iterfind("//absolute_path") failed with a SyntaxError where it should have issued a warning.

5.1.1 (2024-03-28)

... (truncated)

Commits
  • 47f94ff Update changelog.
  • 932a41e Update macOS build isntructions.
  • 888153a Merge branch 'lxml-5.1'
  • fcf00fb Update changelog.
  • 76fd4f9 Fix SyntaxError in Element.iterfind() that should have been a warning.
  • 4faebe3 Fix test.
  • 9b8e36d Fix SyntaxError in Element.iterfind() that should have been a warning.
  • 175c66a Build: Reduce the number of build jobs by disabling some old targets.
  • 06ad31c Prepare release of 5.2.1.
  • 24dafd3 Build: Fix Makefile to work on systems without which(1) (GH-416)
  • Additional commits viewable in compare view


Updates rope from 1.12.0 to 1.13.0

Release notes

Sourced from rope's releases.

1.13.0

What's Changed

Date: 2024-03-25

New Contributors

Full Changelog: https://github.com/python-rope/rope/compare/1.12.0...1.13.0

Changelog

Sourced from rope's changelog.

Release 1.13.0

Commits
  • 5409da0 Update CHANGELOG.md
  • 186f2ed Update python-publish.yml workflow to publish to actual PyPI
  • f720159 Update release-process.txt to follow new GHA-based publishing procedure
  • 32a8a7d Update CHANGELOG.md
  • b93ee0e Update CHANGELOG.md
  • e261463 Merge pull request #783 from python-rope/lieryan-781-venv-isolate
  • aa0ffa6 Merge branch 'master' into lieryan-781-venv-isolate
  • 1489d32 Update main.yml
  • 6bbef1e Update CHANGELOG.md
  • 67edcd7 Fix venv Lib path for Windows
  • Additional commits viewable in compare view


Updates pontos from 24.3.1 to 24.3.2

Release notes

Sourced from pontos's releases.

pontos 24.3.2

24.3.2 - 2024-03-19

Added

Dependencies

  • Bump the python-packages group with 4 updates 176ad88
  • Bump the python-packages group with 5 updates 341cfc4
Commits
  • 2268422 Automatic release to 24.3.2
  • f27c0cb Add: delete_all on labels
  • 176ad88 Deps: Bump the python-packages group with 4 updates
  • 341cfc4 Deps: Bump the python-packages group with 5 updates
  • e1732b4 Automatic adjustments after release [skip ci]
  • See full diff in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
dependabot[bot] commented 7 months ago

Looks like these dependencies are updatable in another way, so this is no longer needed.