-
Notifications
You must be signed in to change notification settings - Fork 54
build(deps): bump the dependencies group with 3 updates #1035
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Updates the requirements on [sigstore](https://github.com/sigstore/sigstore-python), [boto3](https://github.com/boto/boto3) and [botocore](https://github.com/boto/botocore) to permit the latest version. Updates `sigstore` from 3.6.6 to 4.1.0 - [Release notes](https://github.com/sigstore/sigstore-python/releases) - [Changelog](https://github.com/sigstore/sigstore-python/blob/main/CHANGELOG.md) - [Commits](sigstore/sigstore-python@v3.6.6...v4.1.0) Updates `boto3` to 1.40.51 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.40.49...1.40.51) Updates `botocore` to 1.40.51 - [Commits](boto/botocore@1.40.49...1.40.51) --- updated-dependencies: - dependency-name: sigstore dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: boto3 dependency-version: 1.40.51 dependency-type: direct:production dependency-group: dependencies - dependency-name: botocore dependency-version: 1.40.51 dependency-type: direct:production dependency-group: dependencies ... Signed-off-by: dependabot[bot] <[email protected]>
|
This needs a minor change to work with the new API. |
Signed-off-by: Jussi Kukkonen <[email protected]>
5ce8941 to
8e773d2
Compare
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
|
reopening, this has fixes for sigstoresigner upgrade |
This comment has been minimized.
This comment has been minimized.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
|
reopening, this has fixes for sigstoresigner upgrade |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
|
reopening, this has fixes for sigstoresigner upgrade |
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks, @jku!
|
FYI: I cross-checked changes with docs, which seem partially outdated (I need to double check the example for signing), but generally match the changes here. Merging... |
👍 there is an open issue about this, just not fixed yet |
Updates the requirements on sigstore, boto3 and botocore to permit the latest version.
Updates
sigstorefrom 3.6.6 to 4.1.0Release notes
Sourced from sigstore's releases.
... (truncated)
Changelog
Sourced from sigstore's changelog.
... (truncated)
Commits
3447f96Forward port entry kindversion error improvement, bump version to 4.1.0 (#1569)2dbe03abuild(deps): bump github/codeql-action in the actions group (#1572)02daa69build(deps): bump rich from 14.1.0 to 14.2.0 (#1571)1615939build(deps): bump the actions group with 2 updates (#1568)72b6581build(deps): update ruff requirement from <0.13.4 to <0.14.1 (#1567)64dbebacli: Support using other Sigstore instances (#1548)508b0e7build(deps): bump softprops/action-gh-release in the actions group (#1563)e31f481build(deps): update ruff requirement from <0.13.3 to <0.13.4 (#1562)dec897bbuild(deps): bump github/codeql-action in the actions group (#1561)0a54b4fbuild(deps): bump cryptography from 46.0.1 to 46.0.2 (#1558)Updates
boto3to 1.40.51Commits
9200717Merge branch 'release-1.40.51'1a2cda2Bumping version to 1.40.51b59d034Add changelog entries from botocore045a9afBump github/codeql-action from 3.30.0 to 4.30.8 (#4638)d8b4186Merge branch 'release-1.40.50'f6c0e66Merge branch 'release-1.40.50' into develop8fc5b24Bumping version to 1.40.50f4d0097Add changelog entries from botocorea5eec70Merge branch 'release-1.40.49' into developUpdates
botocoreto 1.40.51Commits
d275003Merge branch 'release-1.40.51'60c4c5bBumping version to 1.40.51e55cf7cUpdate to latest models36e4545Merge pull request #3576 from boto/dependabot/github_actions/github/codeql-ac...3dd950fBump github/codeql-action from 3.30.1 to 4.30.88d33050remove License Classifier Deprecation and use up to date license setup (#3575)c2ea08eMerge branch 'release-1.40.50'4fe0c4bMerge branch 'release-1.40.50' into developccf712aBumping version to 1.40.509eae5dfUpdate endpoints modelMost Recent Ignore Conditions Applied to This Pull Request
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions