chore: bump the python-deps group in /app with 13 updates#638
Open
dependabot[bot] wants to merge 2 commits intomainfrom
Open
chore: bump the python-deps group in /app with 13 updates#638dependabot[bot] wants to merge 2 commits intomainfrom
dependabot[bot] wants to merge 2 commits intomainfrom
Conversation
Bumps the python-deps group in /app with 13 updates: | Package | From | To | | --- | --- | --- | | [django](https://github.com/django/django) | `4.2.27` | `5.2.11` | | [django-extensions](https://github.com/django-extensions/django-extensions) | `3.2.3` | `4.1` | | [django-linear-migrations](https://github.com/adamchainz/django-linear-migrations) | `2.16.0` | `2.19.0` | | [django-phonenumber-field[phonenumbers]](https://github.com/stefanfoulis/django-phonenumber-field) | `8.0.0` | `8.4.0` | | [django-timezone-field](https://github.com/mfogel/django-timezone-field) | `7.0` | `7.2.1` | | [djangorestframework](https://github.com/encode/django-rest-framework) | `3.15.2` | `3.16.1` | | [drf-spectacular](https://github.com/tfranzel/drf-spectacular) | `0.28.0` | `0.29.0` | | [markdown](https://github.com/Python-Markdown/markdown) | `3.7` | `3.10.2` | | [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.10` | `2.9.11` | | [pytest-cov](https://github.com/pytest-dev/pytest-cov) | `6.0.0` | `7.0.0` | | [pytest-django](https://github.com/pytest-dev/pytest-django) | `4.9.0` | `4.11.1` | | [pytest-xdist](https://github.com/pytest-dev/pytest-xdist) | `3.6.1` | `3.8.0` | | [tzdata](https://github.com/python/tzdata) | `2024.2` | `2025.3` | Updates `django` from 4.2.27 to 5.2.11 - [Commits](django/django@4.2.27...5.2.11) Updates `django-extensions` from 3.2.3 to 4.1 - [Release notes](https://github.com/django-extensions/django-extensions/releases) - [Changelog](https://github.com/django-extensions/django-extensions/blob/main/CHANGELOG.md) - [Commits](django-extensions/django-extensions@3.2.3...4.1) Updates `django-linear-migrations` from 2.16.0 to 2.19.0 - [Changelog](https://github.com/adamchainz/django-linear-migrations/blob/main/CHANGELOG.rst) - [Commits](adamchainz/django-linear-migrations@2.16.0...2.19.0) Updates `django-phonenumber-field[phonenumbers]` from 8.0.0 to 8.4.0 - [Release notes](https://github.com/stefanfoulis/django-phonenumber-field/releases) - [Changelog](https://github.com/django-phonenumber-field/django-phonenumber-field/blob/main/CHANGELOG.rst) - [Commits](django-phonenumber-field/django-phonenumber-field@8.0.0...8.4.0) Updates `django-timezone-field` from 7.0 to 7.2.1 - [Commits](mfogel/django-timezone-field@7.0...7.2.1) Updates `djangorestframework` from 3.15.2 to 3.16.1 - [Release notes](https://github.com/encode/django-rest-framework/releases) - [Commits](encode/django-rest-framework@3.15.2...3.16.1) Updates `drf-spectacular` from 0.28.0 to 0.29.0 - [Release notes](https://github.com/tfranzel/drf-spectacular/releases) - [Changelog](https://github.com/tfranzel/drf-spectacular/blob/master/CHANGELOG.rst) - [Commits](tfranzel/drf-spectacular@0.28.0...0.29.0) Updates `markdown` from 3.7 to 3.10.2 - [Release notes](https://github.com/Python-Markdown/markdown/releases) - [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md) - [Commits](Python-Markdown/markdown@3.7...3.10.2) Updates `psycopg2-binary` from 2.9.10 to 2.9.11 - [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS) - [Commits](psycopg/psycopg2@2.9.10...2.9.11) Updates `pytest-cov` from 6.0.0 to 7.0.0 - [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst) - [Commits](pytest-dev/pytest-cov@v6.0.0...v7.0.0) Updates `pytest-django` from 4.9.0 to 4.11.1 - [Release notes](https://github.com/pytest-dev/pytest-django/releases) - [Changelog](https://github.com/pytest-dev/pytest-django/blob/main/docs/changelog.rst) - [Commits](pytest-dev/pytest-django@v4.9.0...v4.11.1) Updates `pytest-xdist` from 3.6.1 to 3.8.0 - [Release notes](https://github.com/pytest-dev/pytest-xdist/releases) - [Changelog](https://github.com/pytest-dev/pytest-xdist/blob/master/CHANGELOG.rst) - [Commits](pytest-dev/pytest-xdist@v3.6.1...v3.8.0) Updates `tzdata` from 2024.2 to 2025.3 - [Release notes](https://github.com/python/tzdata/releases) - [Changelog](https://github.com/python/tzdata/blob/master/NEWS.md) - [Commits](python/tzdata@2024.2...2025.3) --- updated-dependencies: - dependency-name: django dependency-version: 5.2.11 dependency-type: direct:production update-type: version-update:semver-major dependency-group: pip - dependency-name: django-extensions dependency-version: '4.1' dependency-type: direct:production update-type: version-update:semver-major dependency-group: pip - dependency-name: django-linear-migrations dependency-version: 2.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: django-phonenumber-field[phonenumbers] dependency-version: 8.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: django-timezone-field dependency-version: 7.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: djangorestframework dependency-version: 3.16.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: drf-spectacular dependency-version: 0.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: markdown dependency-version: 3.10.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: psycopg2-binary dependency-version: 2.9.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: pip - dependency-name: pytest-cov dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: pip - dependency-name: pytest-django dependency-version: 4.11.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: pytest-xdist dependency-version: 3.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: tzdata dependency-version: '2025.3' dependency-type: direct:production update-type: version-update:semver-major dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-deps group in /app with 13 updates:
4.2.275.2.113.2.34.12.16.02.19.08.0.08.4.07.07.2.13.15.23.16.10.28.00.29.03.73.10.22.9.102.9.116.0.07.0.04.9.04.11.13.6.13.8.02024.22025.3Updates
djangofrom 4.2.27 to 5.2.11Commits
4a96a19[5.2.x] Bumped version for 5.2.11 release.ab0ad8d[5.2.x] Refs CVE-2026-1312 -- Raised ValueError when FilteredRelation aliases...e863ee2[5.2.x] Fixed CVE-2026-1312 -- Protected order_by() from SQL injection via al...3e68ccd[5.2.x] Fixed CVE-2026-1287 -- Protected against SQL injection in column alia...9f2ada8[5.2.x] Fixed CVE-2026-1285 -- Mitigated potential DoS in django.utils.text.T...17a1d64[5.2.x] Fixed CVE-2026-1207 -- Prevented SQL injections in RasterField lookup...1ba9006[5.2.x] Fixed CVE-2025-14550 -- Optimized repeated header parsing in ASGI req...184e38a[5.2.x] Fixed CVE-2025-13473 -- Standardized timing of check_password() in mo...d8c551d[5.2.x] Added stub release notes and release date for 5.2.11 and 4.2.28.3ea659d[5.2.x] Clarified regression nature of data loss bug in docs/releases/5.2.10....Updates
django-extensionsfrom 3.2.3 to 4.1Release notes
Sourced from django-extensions's releases.
... (truncated)
Changelog
Sourced from django-extensions's changelog.
Commits
ad01551v4.12c3e914update CHANGELOGfb5b2afruff format7e978d2graph_models style per app (#1848)067064eavoid trying to serialize expressions when serializing default valuesa886068update CHANGELOGd824501Add show_permissions management command (#1920)934f93fbumped version numberc4577dfv4.07cdb43apyproject formattingUpdates
django-linear-migrationsfrom 2.16.0 to 2.19.0Changelog
Sourced from django-linear-migrations's changelog.
Commits
07db9d0Version 2.19.0ab3ea75Correct testing of Django 6.0 (#400)9039aaaSupport Django 6.0 (#399)4dcb191Version 2.18.0ad214caSupport tuples for Migration.dependencies in rebase_migration (#398)4bf6d3dSupport Python 3.14 (#397)17c484f[pre-commit.ci] pre-commit autoupdate (#396)003a8b6Bump the github-actions group with 2 updates (#395)3f71f49Upgrade dependencies (#394)b494fefUse uvx to run tox on GitHub Actions (#393)Updates
django-phonenumber-field[phonenumbers]from 8.0.0 to 8.4.0Release notes
Sourced from django-phonenumber-field[phonenumbers]'s releases.
... (truncated)
Commits
7e7d0fcHandle empty values in SplitPhoneNumberField with max_lengthbb21997Bump actions/checkout from 5.0.1 to 6.0.03a29c91Pin GitHub actions to the commit hash82a6afaRemove Django 5.0 from metadata and test matrixb31ac84Update supported Python and Django versions7fa4ce8Bump actions/download-artifact from 5 to 6162b1afBump actions/upload-artifact from 4 to 5412517cSupport max_length argument for SplitPhoneNumberField3e11f80Allow configuring empty_value for SplitPhoneNumberFieldbb70de6translations: Remove line location from messages filesUpdates
django-timezone-fieldfrom 7.0 to 7.2.1Commits
8255408Release v7.2.1a09fd2fRelease v7.202be229Update lockfile of dev dependencies (#153)d7832deUpdate changelog83c1c90Support Django 6.0 (#150)4fb0dd1Run tests against Python 3.14 (#151)65401a3Officially support django 5.2 (#146)1bc5e7cAdd github FUNDING.yml31d7750Pin on poetry <2268095dRelease v7.1Updates
djangorestframeworkfrom 3.15.2 to 3.16.1Release notes
Sourced from djangorestframework's releases.
... (truncated)
Commits
de018dfPrepare 3.16.1 release (#9752)a7d050fTurkish Translation updates (#9749)853969cFix test with Django 5 when pytz is available (#9715)2ae8c11Add note to tutorial about required request in serializer context when using ...70e54f4Revert docs back to djangorestframework-guardian (#9734)3038494Document that unique constraints causerequired=Truein ModelSerializer (#9...4bb46c2Add Kazakh(kk) locale support (#9713)e454758Fix regression in unique_together validation with SerializerMethodField (#9712)33d59feUpdate Spanish translations (#9701)c0202a0Update Django documentation links to use stable version (#9698)Updates
drf-spectacularfrom 0.28.0 to 0.29.0Release notes
Sourced from drf-spectacular's releases.
... (truncated)
Changelog
Sourced from drf-spectacular's changelog.
Commits
7a7a1f2disable py3.8 target due to pyproject.toml issuesff7a62bfix docse58143bversion bumpe40b287Renovate project setup #116262fc98bMerge pull request #1467 from tfranzel/decimal_l18nd7247a5Add l18n handling for Decimal field #14665221afdMerge branch '#1392'88302faFix LogoutSerializer for JWT/dj_rest_auth #1392f7138e3fix: support token blacklist feature in rest_auth2c71a35[django-filter] Add null_label if set in ChoiceFilter (#1450)Updates
markdownfrom 3.7 to 3.10.2Release notes
Sourced from markdown's releases.
... (truncated)
Changelog
Sourced from markdown's changelog.
... (truncated)
Commits
e7a0efbBump version to 3.10.26301833Document HTML sanitation policy7f29f1aMore reliable fix for</c438647Fix regression of special commentse5fa5b8Bump version to 3.10.1