Commit graph

6584 commits

Author SHA1 Message Date
dependabot[bot]
e371cabdfa
build(deps): bump coverage[toml] in the dependencies group
Bumps the dependencies group with 1 update: [coverage[toml]](https://github.com/coveragepy/coveragepy).


Updates `coverage[toml]` from 7.10.7 to 7.13.1
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](https://github.com/coveragepy/coveragepy/compare/7.10.7...7.13.1)

---
updated-dependencies:
- dependency-name: coverage[toml]
  dependency-version: 7.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-13 10:01:30 +00:00
Lukas Pühringer
94d76ede05
Merge pull request #2897 from jku/bump-minimum-python-version
Bump minimum python version
2026-01-13 09:19:51 +01:00
Jussi Kukkonen
7ecb67d83e api: make the zip() usage clearer
We manually enforce matching lengths but there's no harm in doing this
too.

Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
2026-01-08 13:15:37 +02:00
Jussi Kukkonen
0785c78b33 Make linter happy after python upgrade
Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
2026-01-08 13:08:53 +02:00
Jussi Kukkonen
8513f46c2b Bump minimum Python version to 3.10
We could just stop testing with 3.9... but I think this will lead to
unintentionally breaking 3.9 anyway sooner or later.

Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
2026-01-08 13:08:47 +02:00
Jussi Kukkonen
b21206d3fa
Merge pull request #2893 from theupdateframework/dependabot/pip/build-and-release-dependencies-fdea254270
build(deps-dev): bump hatchling from 1.27.0 to 1.28.0 in the build-and-release-dependencies group
2026-01-07 13:27:59 +02:00
dependabot[bot]
89bc8bb1c1
build(deps-dev): bump hatchling
Bumps the build-and-release-dependencies group with 1 update: [hatchling](https://github.com/pypa/hatch).


Updates `hatchling` from 1.27.0 to 1.28.0
- [Release notes](https://github.com/pypa/hatch/releases)
- [Commits](https://github.com/pypa/hatch/compare/hatchling-v1.27.0...hatchling-v1.28.0)

---
updated-dependencies:
- dependency-name: hatchling
  dependency-version: 1.28.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: build-and-release-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-05 21:01:22 +00:00
Jussi Kukkonen
590a3b57cd
Merge pull request #2892 from theupdateframework/dependabot/pip/test-and-lint-dependencies-0ac1949946
build(deps): bump ruff from 0.14.9 to 0.14.10 in the test-and-lint-dependencies group
2025-12-30 10:34:23 +02:00
dependabot[bot]
10b47eba85
build(deps): bump ruff in the test-and-lint-dependencies group
Bumps the test-and-lint-dependencies group with 1 update: [ruff](https://github.com/astral-sh/ruff).


Updates `ruff` from 0.14.9 to 0.14.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.9...0.14.10)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-29 21:01:28 +00:00
Jussi Kukkonen
b47232175e
Merge pull request #2889 from theupdateframework/dependabot/pip/test-and-lint-dependencies-fb9c0f41fc
build(deps): bump the test-and-lint-dependencies group with 2 updates
2025-12-29 12:16:33 +02:00
Jussi Kukkonen
7c49931ac3
Merge pull request #2890 from theupdateframework/dependabot/pip/dependencies-3c63e8caab
build(deps): bump urllib3 from 2.6.1 to 2.6.2 in the dependencies group
2025-12-29 12:16:11 +02:00
Jussi Kukkonen
29d8afe284
Merge pull request #2891 from theupdateframework/dependabot/github_actions/action-dependencies-68077e0203
build(deps): bump the action-dependencies group with 2 updates
2025-12-29 12:15:44 +02:00
dependabot[bot]
9b497ce2c3
build(deps): bump the action-dependencies group with 2 updates
Bumps the action-dependencies group with 2 updates: [actions/upload-artifact](https://github.com/actions/upload-artifact) and [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `actions/upload-artifact` from 5.0.0 to 6.0.0
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](330a01c490...b7c566a772)

Updates `actions/download-artifact` from 6.0.0 to 7.0.0
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](018cc2cf5b...37930b1c2a)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: action-dependencies
- dependency-name: actions/download-artifact
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: action-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-22 21:03:20 +00:00
dependabot[bot]
63af1f0ea2
build(deps): bump urllib3 from 2.6.1 to 2.6.2 in the dependencies group
Bumps the dependencies group with 1 update: [urllib3](https://github.com/urllib3/urllib3).


Updates `urllib3` from 2.6.1 to 2.6.2
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.1...2.6.2)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-22 21:02:08 +00:00
dependabot[bot]
1cdeb605d1
build(deps): bump the test-and-lint-dependencies group with 2 updates
Bumps the test-and-lint-dependencies group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [mypy](https://github.com/python/mypy).


Updates `ruff` from 0.14.8 to 0.14.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.8...0.14.9)

Updates `mypy` from 1.19.0 to 1.19.1
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](https://github.com/python/mypy/compare/v1.19.0...v1.19.1)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
- dependency-name: mypy
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-22 21:01:40 +00:00
Jussi Kukkonen
0a5476e99d
Merge pull request #2886 from theupdateframework/dependabot/pip/test-and-lint-dependencies-a251ab4e33
build(deps): bump ruff from 0.14.7 to 0.14.8 in the test-and-lint-dependencies group
2025-12-16 11:36:30 +02:00
Jussi Kukkonen
74b395cb08
Merge pull request #2887 from theupdateframework/dependabot/pip/dependencies-9e0978b55f
build(deps): bump urllib3 from 2.5.0 to 2.6.1 in the dependencies group
2025-12-16 11:36:06 +02:00
Jussi Kukkonen
16bda29710
Merge pull request #2888 from theupdateframework/dependabot/github_actions/action-dependencies-2507bcfa80
build(deps): bump actions/checkout from 6.0.0 to 6.0.1 in the action-dependencies group
2025-12-16 11:35:25 +02:00
dependabot[bot]
53a8f11c20
build(deps): bump actions/checkout in the action-dependencies group
Bumps the action-dependencies group with 1 update: [actions/checkout](https://github.com/actions/checkout).


Updates `actions/checkout` from 6.0.0 to 6.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](1af3b93b68...8e8c483db8)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: action-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 21:03:18 +00:00
dependabot[bot]
6fd7d1b55a
build(deps): bump urllib3 from 2.5.0 to 2.6.1 in the dependencies group
Bumps the dependencies group with 1 update: [urllib3](https://github.com/urllib3/urllib3).


Updates `urllib3` from 2.5.0 to 2.6.1
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/2.5.0...2.6.1)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 21:02:04 +00:00
dependabot[bot]
4981e38591
build(deps): bump ruff in the test-and-lint-dependencies group
Bumps the test-and-lint-dependencies group with 1 update: [ruff](https://github.com/astral-sh/ruff).


Updates `ruff` from 0.14.7 to 0.14.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.7...0.14.8)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-15 21:01:36 +00:00
Jussi Kukkonen
d545e89387
Merge pull request #2885 from theupdateframework/dependabot/pip/test-and-lint-dependencies-fb5b970081
build(deps): bump the test-and-lint-dependencies group with 2 updates
2025-12-09 10:51:24 +02:00
dependabot[bot]
2b3dbc0fd1
build(deps): bump the test-and-lint-dependencies group with 2 updates
Bumps the test-and-lint-dependencies group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [mypy](https://github.com/python/mypy).


Updates `ruff` from 0.14.6 to 0.14.7
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.6...0.14.7)

Updates `mypy` from 1.18.2 to 1.19.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](https://github.com/python/mypy/compare/v1.18.2...v1.19.0)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
- dependency-name: mypy
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-08 21:01:32 +00:00
Lukas Pühringer
7244937111
Merge pull request #2883 from theupdateframework/dependabot/github_actions/action-dependencies-78e82347d6
build(deps): bump the action-dependencies group with 2 updates
2025-12-02 08:55:57 +01:00
Lukas Pühringer
8c61f1ea70
Merge pull request #2884 from theupdateframework/dependabot/pip/test-and-lint-dependencies-f86d19be86
build(deps): bump ruff from 0.14.5 to 0.14.6 in the test-and-lint-dependencies group
2025-12-02 08:53:38 +01:00
dependabot[bot]
990a5adb44
build(deps): bump ruff in the test-and-lint-dependencies group
Bumps the test-and-lint-dependencies group with 1 update: [ruff](https://github.com/astral-sh/ruff).


Updates `ruff` from 0.14.5 to 0.14.6
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.5...0.14.6)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-02 00:51:25 +00:00
dependabot[bot]
347f76fd68
build(deps): bump the action-dependencies group with 2 updates
Bumps the action-dependencies group with 2 updates: [actions/checkout](https://github.com/actions/checkout) and [actions/setup-python](https://github.com/actions/setup-python).


Updates `actions/checkout` from 5.0.0 to 6.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](08c6903cd8...1af3b93b68)

Updates `actions/setup-python` from 6.0.0 to 6.1.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](e797f83bcb...83679a892e)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: action-dependencies
- dependency-name: actions/setup-python
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: action-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-01 23:07:50 +00:00
Jussi Kukkonen
9fad786d4e
Merge pull request #2882 from theupdateframework/dependabot/pip/test-and-lint-dependencies-aac00a2214
build(deps): bump ruff from 0.14.4 to 0.14.5 in the test-and-lint-dependencies group
2025-11-25 11:05:40 +02:00
dependabot[bot]
209081e1b9
build(deps): bump ruff in the test-and-lint-dependencies group
Bumps the test-and-lint-dependencies group with 1 update: [ruff](https://github.com/astral-sh/ruff).


Updates `ruff` from 0.14.4 to 0.14.5
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.4...0.14.5)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-11-24 21:01:32 +00:00
Lukas Pühringer
af9e0b84b0
Merge pull request #2881 from theupdateframework/dependabot/pip/test-and-lint-dependencies-7b4d468bc7
build(deps): bump the test-and-lint-dependencies group with 2 updates
2025-11-18 08:46:59 +01:00
dependabot[bot]
586d4cda6e
build(deps): bump the test-and-lint-dependencies group with 2 updates
Bumps the test-and-lint-dependencies group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [zizmor](https://github.com/zizmorcore/zizmor).


Updates `ruff` from 0.14.3 to 0.14.4
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.3...0.14.4)

Updates `zizmor` from 1.16.2 to 1.16.3
- [Release notes](https://github.com/zizmorcore/zizmor/releases)
- [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md)
- [Commits](https://github.com/zizmorcore/zizmor/compare/v1.16.2...v1.16.3)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
- dependency-name: zizmor
  dependency-version: 1.16.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-11-17 21:01:55 +00:00
Jussi Kukkonen
f54248c61a
Merge pull request #2880 from theupdateframework/dependabot/pip/test-and-lint-dependencies-6187adf992
build(deps): bump the test-and-lint-dependencies group with 2 updates
2025-11-11 11:13:12 +02:00
dependabot[bot]
de72e7e7bc
build(deps): bump the test-and-lint-dependencies group with 2 updates
Bumps the test-and-lint-dependencies group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [zizmor](https://github.com/zizmorcore/zizmor).


Updates `ruff` from 0.14.2 to 0.14.3
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.2...0.14.3)

Updates `zizmor` from 1.16.0 to 1.16.2
- [Release notes](https://github.com/zizmorcore/zizmor/releases)
- [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md)
- [Commits](https://github.com/zizmorcore/zizmor/compare/v1.16.0...v1.16.2)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
- dependency-name: zizmor
  dependency-version: 1.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-11-10 21:05:48 +00:00
Lukas Pühringer
0f7fcd8263
Merge pull request #2879 from jku/schedule-conformance-run
conformance: bump version and schedule a weekly run
2025-11-04 08:54:24 +01:00
Jussi Kukkonen
64cacfc553 conformance: Bump version and schedule a weekly run
This way there is always an up-to-date result for the conformance
report (https://theupdateframework.github.io/tuf-conformance/)
to use

Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
2025-11-03 19:43:41 +02:00
Lukas Pühringer
d993961c80
Merge pull request #2876 from theupdateframework/dependabot/pip/test-and-lint-dependencies-6445124e3d
build(deps): bump the test-and-lint-dependencies group with 2 updates
2025-10-30 17:58:11 +01:00
Jussi Kukkonen
e8eecd6f9a dependabot: Set default cooldown of 7 days
Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
2025-10-28 10:49:42 +02:00
Jussi Kukkonen
e3ed0aa886
Merge pull request #2878 from theupdateframework/dependabot/github_actions/action-dependencies-6bbbe96356
build(deps): bump the action-dependencies group with 2 updates
2025-10-28 10:46:38 +02:00
dependabot[bot]
be63d5bf42
build(deps): bump the test-and-lint-dependencies group with 2 updates
Bumps the test-and-lint-dependencies group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [zizmor](https://github.com/zizmorcore/zizmor).


Updates `ruff` from 0.14.0 to 0.14.1
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.14.0...0.14.1)

Updates `zizmor` from 1.14.2 to 1.15.2
- [Release notes](https://github.com/zizmorcore/zizmor/releases)
- [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md)
- [Commits](https://github.com/zizmorcore/zizmor/compare/v1.14.2...v1.15.2)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: test-and-lint-dependencies
- dependency-name: zizmor
  dependency-version: 1.15.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-27 21:35:07 +00:00
dependabot[bot]
25cea25ec1
build(deps): bump the action-dependencies group with 2 updates
Bumps the action-dependencies group with 2 updates: [actions/upload-artifact](https://github.com/actions/upload-artifact) and [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `actions/upload-artifact` from 4.6.2 to 5.0.0
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](ea165f8d65...330a01c490)

Updates `actions/download-artifact` from 5.0.0 to 6.0.0
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](634f93cb29...018cc2cf5b)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: action-dependencies
- dependency-name: actions/download-artifact
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: action-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-27 21:32:00 +00:00
Lukas Pühringer
701dbe2b46
Merge pull request #2877 from theupdateframework/dependabot/pip/dependencies-fea7ec2d62
build(deps): bump cryptography from 46.0.2 to 46.0.3 in the dependencies group
2025-10-21 10:07:07 +02:00
dependabot[bot]
da16ea9667
build(deps): bump cryptography in the dependencies group
Bumps the dependencies group with 1 update: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 46.0.2 to 46.0.3
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.2...46.0.3)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-20 21:02:09 +00:00
Jussi Kukkonen
70ea8d09f8
Merge pull request #2874 from theupdateframework/dependabot/pip/test-and-lint-dependencies-fe79184b30
build(deps): bump ruff from 0.13.3 to 0.14.0 in the test-and-lint-dependencies group
2025-10-14 10:30:02 +03:00
Jussi Kukkonen
56d394efa2
Merge pull request #2875 from theupdateframework/dependabot/github_actions/action-dependencies-1893dd32ff
build(deps): bump github/codeql-action from 3 to 4 in the action-dependencies group
2025-10-14 10:29:11 +03:00
dependabot[bot]
81124032cf
build(deps): bump github/codeql-action in the action-dependencies group
Bumps the action-dependencies group with 1 update: [github/codeql-action](https://github.com/github/codeql-action).


Updates `github/codeql-action` from 3 to 4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v3...v4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: action-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-13 21:02:11 +00:00
dependabot[bot]
fa67367cc2
build(deps): bump ruff in the test-and-lint-dependencies group
Bumps the test-and-lint-dependencies group with 1 update: [ruff](https://github.com/astral-sh/ruff).


Updates `ruff` from 0.13.3 to 0.14.0
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.13.3...0.14.0)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: test-and-lint-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-13 21:01:38 +00:00
Jussi Kukkonen
2b90d607de
Merge pull request #2873 from theupdateframework/dependabot/pip/dependencies-9d213c3ead
build(deps): bump cryptography from 46.0.1 to 46.0.2 in the dependencies group
2025-10-10 13:47:37 +03:00
Lukas Pühringer
298f7f53a1
Merge pull request #2871 from theupdateframework/dependabot/pip/test-and-lint-dependencies-8afd51e63f
build(deps): bump ruff from 0.13.2 to 0.13.3 in the test-and-lint-dependencies group
2025-10-07 09:43:14 +02:00
Lukas Pühringer
88202a5818
Merge pull request #2872 from theupdateframework/dependabot/github_actions/action-dependencies-6ca8c082f8
build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 in the action-dependencies group
2025-10-07 09:43:00 +02:00
dependabot[bot]
8e641d75ca
build(deps): bump cryptography in the dependencies group
Bumps the dependencies group with 1 update: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 46.0.1 to 46.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.1...46.0.2)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-10-06 21:02:10 +00:00