vcert-python
vcert-python copied to clipboard
Bump bandit from 1.7.7 to 1.8.3
Bumps bandit from 1.7.7 to 1.8.3.
Release notes
Sourced from bandit's releases.
1.8.3
What's Changed
- Bump docker/build-push-action from 6.10.0 to 6.11.0 by
@dependabotin PyCQA/bandit#1220- Bump docker/build-push-action from 6.11.0 to 6.12.0 by
@dependabotin PyCQA/bandit#1221- Bump docker/build-push-action from 6.12.0 to 6.13.0 by
@dependabotin PyCQA/bandit#1222- [pre-commit.ci] pre-commit autoupdate by
@pre-commit-ciin PyCQA/bandit#1229- Update bug template to include latest released versions by
@ericwbin PyCQA/bandit#1218- Add markupsafe.Markup XSS plugin by
@Daverballin PyCQA/bandit#1225- Warn not error on an nonexistant test given by
@ericwbin PyCQA/bandit#1230- Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 by
@dependabotin PyCQA/bandit#1233- Bump docker/setup-buildx-action from 3.8.0 to 3.9.0 by
@dependabotin PyCQA/bandit#1234- B107: Skip None values in hardcoded password detection by
@lukehindsin PyCQA/bandit#1232- Pytorch fix by
@lukehindsin PyCQA/bandit#1231New Contributors
@Daverballmade their first contribution in PyCQA/bandit#1225Full Changelog: https://github.com/PyCQA/bandit/compare/1.8.2...1.8.3
1.8.2
What's Changed
- Revert "Start testing with 3.14 alphas" by
@ericwbin PyCQA/bandit#1217Full Changelog: https://github.com/PyCQA/bandit/compare/1.8.1...1.8.2
1.8.1
What's Changed
- Bump docker/build-push-action from 6.9.0 to 6.10.0 by
@dependabotin PyCQA/bandit#1209- Update the bug template with latest bandit version by
@ericwbin PyCQA/bandit#1208- Add Mercedes-Benz to sponsor list by
@ericwbin PyCQA/bandit#1210- Bump docker/setup-buildx-action from 3.7.1 to 3.8.0 by
@dependabotin PyCQA/bandit#1211- [pre-commit.ci] pre-commit autoupdate by
@pre-commit-ciin PyCQA/bandit#1213- Start testing with 3.14 alphas by
@ericwbin PyCQA/bandit#1189- Remove lxml (B320 & B410) from blacklist by
@djbrownin PyCQA/bandit#1212- Clarify "getting started" docs by
@Flimmin PyCQA/bandit#963New Contributors
@djbrownmade their first contribution in PyCQA/bandit#1212@Flimmmade their first contribution in PyCQA/bandit#963Full Changelog: https://github.com/PyCQA/bandit/compare/1.8.0...1.8.1
1.8.0
What's Changed
- Bump docker/build-push-action from 6.7.0 to 6.9.0 by
@dependabotin PyCQA/bandit#1178- Rename doc file to match proper bandit ID by
@ericwbin PyCQA/bandit#1183- Removal of Python 3.8 support by
@ericwbin PyCQA/bandit#1174- Add more insecure cryptography cipher algorithms by
@ericwbin PyCQA/bandit#1185- Bump docker/setup-buildx-action from 3.6.1 to 3.7.1 by
@dependabotin PyCQA/bandit#1186
... (truncated)
Commits
8ff25e0Pytorch fix (#1231)def123aB107: Skip None values in hardcoded password detection (#1232)00b1e95Bump docker/setup-buildx-action from 3.8.0 to 3.9.0 (#1234)a324f42Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 (#1233)affd4fdWarn not error on an nonexistant test given (#1230)5e3e694Add markupsafe.Markup XSS plugin (#1225)6133e08Update bug template to include latest released versions (#1218)7619cc4[pre-commit.ci] pre-commit autoupdate (#1229)3348781Bump docker/build-push-action from 6.12.0 to 6.13.0 (#1222)ef0090fBump docker/build-push-action from 6.11.0 to 6.12.0 (#1221)- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.