Skip to content

Update dependencies to their latest releases#1333

Merged
greenbonebot merged 1 commit intomainfrom
dependecy-updates
Apr 23, 2026
Merged

Update dependencies to their latest releases#1333
greenbonebot merged 1 commit intomainfrom
dependecy-updates

Conversation

@bjoernricks
Copy link
Copy Markdown
Contributor

What

Update dependencies to their latest releases

Why

Fixes a vulnerability in lxml

@bjoernricks bjoernricks requested a review from a team as a code owner April 22, 2026 10:01
@greenbonebot greenbonebot enabled auto-merge (rebase) April 22, 2026 10:01
@github-actions
Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 5 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 7c76100.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

uv.lock

PackageVersionLicenseIssue Type
idna3.12NullUnknown License
lxml6.1.0NullUnknown License
mypy1.20.2NullUnknown License
pontos26.4.1NullUnknown License
ruff0.15.11NullUnknown License
Allowed Licenses: 0BSD, AGPL-3.0-or-later, Apache-2.0, BlueOak-1.0.0, BSD-2-Clause, BSD-3-Clause-Clear, BSD-3-Clause, BSL-1.0, bzip2-1.0.6, CAL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-4.0, CC0-1.0, EPL-2.0, GPL-1.0-or-later, GPL-2.0-only, GPL-2.0-or-later, GPL-2.0, GPL-3.0-only, GPL-3.0-or-later, GPL-3.0, ISC, LGPL-2.0-only, LGPL-2.0-or-later, LGPL-2.1-only, LGPL-2.1-or-later, LGPL-2.1, LGPL-3.0-only, LGPL-3.0, LGPL-3.0-or-later, MIT, MIT-CMU, MPL-1.1, MPL-2.0, OFL-1.1, PSF-2.0, Python-2.0, Python-2.0.1, Unicode-3.0, Unicode-DFS-2016, Unlicense, Zlib, ZPL-2.1

OpenSSF Scorecard

PackageVersionScoreDetails
pip/idna 3.12 UnknownUnknown
pip/lxml 6.1.0 UnknownUnknown
pip/mypy 1.20.2 UnknownUnknown
pip/pontos 26.4.1 UnknownUnknown
pip/ruff 0.15.11 UnknownUnknown

Scanned Files

  • uv.lock

@github-actions
Copy link
Copy Markdown

Conventional Commits Report

Type Number
Dependencies 1

🚀 Conventional commits found.

@greenbonebot greenbonebot merged commit 32caa62 into main Apr 23, 2026
26 checks passed
@greenbonebot greenbonebot deleted the dependecy-updates branch April 23, 2026 05:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants