From a2b422512d690d4ab040edb201c546898b3c2b9b Mon Sep 17 00:00:00 2001 From: twangboy Date: Mon, 13 Jan 2025 14:38:57 -0700 Subject: [PATCH] Update requirements to address security issues --- .pre-commit-config.yaml | 2 +- requirements/release.txt | 65 +++++++++++++++++++++++----------------- 2 files changed, 38 insertions(+), 29 deletions(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 04a74c1..2235e19 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -30,7 +30,7 @@ repos: - actionlint - repo: https://github.com/jazzband/pip-tools - rev: 7.3.0 + rev: 7.4.1 hooks: - id: pip-compile files: ^requirements/release\.(in|txt)$ diff --git a/requirements/release.txt b/requirements/release.txt index b009f47..78fa61c 100644 --- a/requirements/release.txt +++ b/requirements/release.txt @@ -4,27 +4,31 @@ # # pip-compile requirements/release.in # -attrs==23.1.0 +annotated-types==0.7.0 + # via pydantic +attrs==24.3.0 # via python-tools-scripts -boto3==1.28.79 +boto3==1.35.98 # via -r requirements/release.in -botocore==1.31.79 +botocore==1.35.98 # via # boto3 # s3transfer -certifi==2023.7.22 +certifi==2024.12.14 # via requests cfgv==3.4.0 # via pre-commit -charset-normalizer==3.3.2 +charset-normalizer==3.4.1 # via requests -distlib==0.3.7 +distlib==0.3.9 # via virtualenv -filelock==3.13.1 - # via virtualenv -identify==2.5.31 +filelock==3.16.1 + # via + # python-tools-scripts + # virtualenv +identify==2.6.5 # via pre-commit -idna==3.4 +idna==3.10 # via requests jmespath==1.0.1 # via @@ -34,36 +38,41 @@ markdown-it-py==3.0.0 # via rich mdurl==0.1.2 # via markdown-it-py -nodeenv==1.8.0 +nodeenv==1.9.1 # via pre-commit -platformdirs==3.11.0 +platformdirs==4.3.6 # via virtualenv -pre-commit==3.5.0 +pre-commit==4.0.1 # via -r requirements/release.in -pygments==2.16.1 +pydantic==2.10.5 + # via python-tools-scripts +pydantic-core==2.27.2 + # via pydantic +pygments==2.19.1 # via rich -python-dateutil==2.8.2 +python-dateutil==2.9.0.post0 # via botocore -python-tools-scripts==0.18.6 +python-tools-scripts==0.20.5 # via -r requirements/release.in -pyyaml==6.0.1 +pyyaml==6.0.2 # via pre-commit -requests==2.31.0 +requests==2.32.3 # via python-tools-scripts -rich==13.6.0 +rich==13.9.4 # via python-tools-scripts -s3transfer==0.7.0 +s3transfer==0.10.4 # via boto3 -six==1.16.0 +six==1.17.0 # via python-dateutil -typing-extensions==4.8.0 - # via python-tools-scripts -urllib3==2.0.7 +typing-extensions==4.12.2 + # via + # pydantic + # pydantic-core + # python-tools-scripts + # rich +urllib3==2.3.0 # via # botocore # requests -virtualenv==20.24.6 +virtualenv==20.28.1 # via pre-commit - -# The following packages are considered to be unsafe in a requirements file: -# setuptools