Skip to content

chore(deps): bump the uv group across 1 directory with 2 updates#54

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/uv/uv-3c1733fbba
Open

chore(deps): bump the uv group across 1 directory with 2 updates#54
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/uv/uv-3c1733fbba

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 8, 2026

Bumps the uv group with 2 updates in the / directory: cryptography and lupa.

Updates cryptography from 46.0.6 to 46.0.7

Changelog

Sourced from cryptography's changelog.

46.0.7 - 2026-04-07


* **SECURITY ISSUE**: Fixed an issue where non-contiguous buffers could be
  passed to APIs that accept Python buffers, which could lead to buffer
  overflow. **CVE-2026-39892**
* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.5.6.

.. _v46-0-6:

Commits

Updates lupa from 2.6 to 2.7

Changelog

Sourced from lupa's changelog.

2.7 (2026-04-07)

  • In Lua 5.5, the string hash seed can be configured for each LuaRuntime.

  • The bundled LuaJIT versions were updated to the latest git branches.

  • Lua 5.5 is included in the binary wheels.

  • Lupa can be built as abi3 wheel.

  • Some lesser used platforms are served with abi3 wheels.

  • Built with Cython 3.2.4.

Commits
  • 6e08760 Build: Set minimum supported Python version in package metadata.
  • c02b105 Build: Revert adding project metadata section to pyproject.toml because it br...
  • 5a7b58b Build: List dynamically provided project metadata fields in pyproject.toml.
  • b8ff709 Build: Minor modernisation in setup.py.
  • 721f217 Build: Update project metadata.
  • 53c0bce Prepare release of 2.7.
  • 29fa097 Build: Fix left-over variable references in workflow.
  • b1da49e Build: Reverse build setup to increase the parallelism.
  • a0f2972 Update changelog.
  • 6b05ad4 Build: Do not build redundant Windows wheels that already have an abi3 wheel.
  • Additional commits viewable in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Apr 8, 2026
Bumps the uv group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography) and [lupa](https://github.com/scoder/lupa).


Updates `cryptography` from 46.0.6 to 46.0.7
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.6...46.0.7)

Updates `lupa` from 2.6 to 2.7
- [Release notes](https://github.com/scoder/lupa/releases)
- [Changelog](https://github.com/scoder/lupa/blob/master/CHANGES.rst)
- [Commits](scoder/lupa@lupa-2.6...lupa-2.7)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: indirect
  dependency-group: uv
- dependency-name: lupa
  dependency-version: '2.7'
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/uv/uv-3c1733fbba branch from 5c51e83 to 982fe3f Compare April 14, 2026 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants