Bump python-multipart from 0.0.20 to 0.0.26 in /playground/FoundryAgentBasic/app in the uv group across 1 directory#16216
Conversation
Bumps the uv group with 1 update in the /playground/FoundryAgentBasic/app directory: [python-multipart](https://github.com/Kludex/python-multipart). Updates `python-multipart` from 0.0.20 to 0.0.26 - [Release notes](https://github.com/Kludex/python-multipart/releases) - [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md) - [Commits](Kludex/python-multipart@0.0.20...0.0.26) --- updated-dependencies: - dependency-name: python-multipart dependency-version: 0.0.26 dependency-type: indirect dependency-group: uv ... Signed-off-by: dependabot[bot] <support@github.com>
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 16216Or
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 16216" |
|
🎬 CLI E2E Test Recordings — 71 recordings uploaded (commit View recordings
📹 Recordings uploaded automatically from CI run #24477365391 |
PR testing reportPR: #16216 - Bump python-multipart from 0.0.20 to 0.0.26 in /playground/FoundryAgentBasic/app in the uv group across 1 directory CLI version verificationThe PR dogfood installer was invoked, but the expected Windows CLI artifact could not be downloaded from the workflow run referenced by the dogfood instructions. Because the PR CLI could not be installed, the CLI version could not be verified against the PR head commit and no scenarios were executed.
Changes analyzedThis PR updates the python-multipart dependency in a FoundryAgentBasic uv.lock file:
Planned scenariosThese scenarios were selected based on the changed files, but were not executed because CLI installation failed first:
Overall: Not verified. Please rerun after the PR dogfood workflow publishes the expected |
IEvangelist
left a comment
There was a problem hiding this comment.
Approving this Dependabot security update for python-multipart (0.0.20 -> 0.0.26).
Verification:
- All CI checks are passing on this PR.
- Patch upgrade across multiple minor versions (0.0.20 -> 0.0.26) addresses bug fixes and the security/correctness changes documented in the changelog.
- Confined to /playground/FoundryAgentBasic/app, a sample app, so risk is contained.
LGTM. /cc @dependabot squash and merge
Bumps the uv group with 1 update in the /playground/FoundryAgentBasic/app directory: python-multipart.
Updates
python-multipartfrom 0.0.20 to 0.0.26Release notes
Sourced from python-multipart's releases.
... (truncated)
Changelog
Sourced from python-multipart's changelog.
Commits
28f4785Version 0.0.26 (#263)d4452a7Silently discard epilogue data after the closing boundary (#259)6a7b76dSkip preamble before first multipart boundary (#262)4addb60Version 0.0.25 (#261)d3a4698Add MIME content type info to File (#143)9a1ecbdHandle CTE values case-insensitively (#258)ef2a0b9Remove custom FormParser classes (#257)3a757d7Ignore local Claude state (#255)55e7396fuzz: Add cifuzz (#186)d6d1d11Bump the github-actions group with 2 updates (#249)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.