Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump asteval from 0.9.32 to 0.9.33 #10269

Merged
merged 1 commit into from
May 30, 2024
Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 24, 2024

Bumps asteval from 0.9.32 to 0.9.33.

Release notes

Sourced from asteval's releases.

0.9.33

Fixes:

  • fixes for multiple list comprehensions (addressing #126)
  • add testing with optionally installed numpy_financial to CI
  • test existence of all numpy imports to better safeguard against missing functions (for safer numpy 2 transition)
  • update rendered doc to include PDF and zipped HTML
Commits
  • b9a9b64 update rendered doc to include PDF and zipped html
  • 28bbf58 add optional install of numpy_financial to CI tests
  • 2e86c28 add optional install of numpy_financial to CI tests
  • 8fe9e33 add optional install of numpy_financial to CI tests
  • f84958d add optional install of numpy_financial to CI tests
  • 22d9780 add optional install of numpy_financial to CI tests
  • 703b896 add install of numpy_financial to CI tests
  • 366028e add install of numpy_financial to CI tests
  • 5532396 add optional install of numpy_financial to CI tests
  • b8fe4d6 add optional install of numpy_financial to CI tests
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 24, 2024
Copy link

dryrunsecurity bot commented May 24, 2024

Hi there 👋, @DryRunSecurity here, below is a summary of our analysis and findings.

DryRun Security Status Findings
Configured Codepaths Analyzer 0 findings
Sensitive Files Analyzer 1 finding
AppSec Analyzer 0 findings
Authn/Authz Analyzer 0 findings
Secrets Analyzer 0 findings

Note

🟢 Risk threshold not exceeded.

Change Summary (click to expand)

The following is a summary of changes in this pull request made by me, your security buddy 🤖. Note that this summary is auto-generated and not meant to be a definitive list of security issues but rather a helpful summary from a security perspective.

Summary:

The provided code change is an update to the requirements.txt file for the DefectDojo project, which is an open-source web application for managing software vulnerabilities. The key changes include updating the asteval library, removing the django-multiselectfield and django-tagging libraries and replacing them with direct git references, and including several security-related libraries such as cryptography, argon2-cffi, and vulners.

From an application security perspective, the changes to the django-multiselectfield and django-tagging libraries are notable, as moving to direct git references suggests that the project is addressing security vulnerabilities or compatibility issues with the older versions of these libraries. This is a common practice to ensure that the project is using the most secure and up-to-date versions of its dependencies. Additionally, the inclusion of various security-related libraries indicates that the project is taking security seriously and incorporating security features and tools.

Overall, the changes appear to be focused on updating dependencies and addressing potential security concerns, which is a good practice for maintaining the security and stability of the DefectDojo application.

Files Changed:

  • requirements.txt: This file has been updated to include the following changes:
    1. The asteval library has been updated from version 0.9.32 to 0.9.33.
    2. The django-multiselectfield library has been removed and replaced with a direct git reference to the django-multiselectfield library from the DefectDojo repository.
    3. The django-tagging library has been removed and replaced with a direct git reference to the django-tagging library from the DefectDojo repository.
    4. Several security-related libraries, such as cryptography, argon2-cffi, and vulners, have been included in the requirements.

Powered by DryRun Security

Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

Bumps [asteval](https://github.com/lmfit/asteval) from 0.9.32 to 0.9.33.
- [Release notes](https://github.com/lmfit/asteval/releases)
- [Commits](lmfit/asteval@0.9.32...0.9.33)

---
updated-dependencies:
- dependency-name: asteval
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/pip/dev/asteval-0.9.33 branch from 392d478 to 127cbfb Compare May 30, 2024 16:46
@cneill cneill merged commit 25f5a7c into dev May 30, 2024
125 checks passed
@dependabot dependabot bot deleted the dependabot/pip/dev/asteval-0.9.33 branch May 30, 2024 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants