Skip to content

MAINT: Bump the security-minor-and-patch group across 1 directory with 2 updates - #3034

Merged
Roman Lutz (romanlutz) merged 5 commits into
mainfrom
dependabot/uv/security-minor-and-patch-f122febbbc
Oct 8, 2026
Merged

Roman Lutz (romanlutz) merged 5 commits into
mainfrom
dependabot/uv/security-minor-and-patch-f122febbbc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the security-minor-and-patch group with 2 updates in the / directory: mako and werkzeug.

Updates mako from 1.3.12 to 1.4.2

Release notes

Sourced from mako's releases.

1.4.2

Released: Tue Sep 22 2026

bug

  • [bug] [tests] Adjusted the test suite to accommodate for a change in Pygments 2.21.0 where the HtmlFormatter now renders " and ' characters literally rather than as HTML entities, which caused failures in tests that assert against the rendered output of html_error_template().

    References: #440

  • [bug] [template] Fixed issue in TemplateLookup where a URI beginning with a drive designator (e.g. C:/../../secret.txt) could bypass the directory traversal check on Windows, allowing reads of arbitrary files outside of the template directory. The check in Template normalized the URI using os.path, which on Windows is ntpath; as ntpath splits the drive designator off and treats the remainder as rooted, the .. segments were absorbed before the check could inspect them. Normalization is now performed with posixpath, which is the same module used by TemplateLookup.get_template() to resolve the URI to a file.

    References: #441

1.4.1

Released: Wed Aug 5 2026

bug

  • [bug] [installation] Fixed issue in the 1.4.0 packaging where the repository's internal tools/ directory was detected by setuptools package discovery and installed as a top-level tools package into site-packages, shadowing unrelated tools packages belonging to other applications. Package discovery is now limited to the mako package explicitly.

    References: #438

1.4.0

Released: Tue Aug 4 2026

changed

  • [changed] [examples] The examples/bench folder has been removed as it used mostly

... (truncated)

Commits

Updates werkzeug from 3.1.6 to 3.1.9

Release notes

Sourced from werkzeug's releases.

3.1.9

This is the Werkzeug 3.1.9 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.9/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-9 Milestone: https://github.com/pallets/werkzeug/milestone/46?closed=1

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. GHSA-g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. #3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. #3189
  • Improve performance of parse_options_header. #3231
  • Improve performance of parse_etags. #3231
  • Improve performance of parse_cookie. #3231
  • get_host also checks that the port is in the valid range. #3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). #3237
  • Improve debugger PIN generation from cgroup data inside Podman. #3245
  • Authorization parsing basic auth disallows non-base64 characters. #3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. #3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. #3253
  • Rules with 10 or more converters in a single part assign matched values correctly. #3254
  • The invalid Range suffix length -0 is no longer accepted. #3255

3.1.8

This is the Werkzeug 3.1.8 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.8/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-8 Milestone: https://github.com/pallets/werkzeug/milestone/45?closed=1

  • Request.host and get_host return the empty string if the header is missing or has invalid characters. #3142

3.1.7

This is the Werkzeug 3.1.7 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.7/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-7 Milestone: https://github.com/pallets/werkzeug/milestone/44?closed=1

  • parse_list_header preserves partially quoted items, discards empty items, and returns empty for unclosed quoted values. #3128
  • WWWAuthenticate.to_header does not produce a trailing space when there are no parameters. #3127
  • Transfer-Encoding is parsed as a set. #3134
  • Request.host, get_host, and host_is_trusted validate the characters of the value. An empty value is no longer allowed. A Unix socket server address is ignored. The trusted_list argument to host_is_trusted is optional. #3113
  • Fix multipart form parser handling of newline at boundary. #3088
  • Response.make_conditional sets the Accept-Ranges header even if it is not a satisfiable range request. #3108
  • merge_slashes merges any number of consecutive slashes. #3121
Changelog

Sourced from werkzeug's changelog.

Version 3.1.9

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman. :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters. :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255

Version 3.1.8

Released 2026-04-02

  • Request.host and get_host return the empty string if the header is missing or has invalid characters. :issue:3142

Version 3.1.7

Released 2026-03-23

  • parse_list_header preserves partially quoted items, discards empty items, and returns empty for unclosed quoted values. :pr:3128
  • WWWAuthenticate.to_header does not produce a trailing space when there are no parameters. :issue:3127
  • Transfer-Encoding is parsed as a set. :pr:3134
  • Request.host, get_host, and host_is_trusted validate the

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

…h 2 updates

Bumps the security-minor-and-patch group with 2 updates in the / directory: [mako](https://github.com/sqlalchemy/mako) and [werkzeug](https://github.com/pallets/werkzeug).


Updates `mako` from 1.3.12 to 1.4.2
- [Release notes](https://github.com/sqlalchemy/mako/releases)
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/mako/commits)

Updates `werkzeug` from 3.1.6 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.6...3.1.9)

---
updated-dependencies:
- dependency-name: mako
  dependency-version: 1.4.2
  dependency-type: indirect
  dependency-group: security-minor-and-patch
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: indirect
  dependency-group: security-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.11, dev)

     1 files  ±0       1 suites  ±0   3m 14s ⏱️ -29s
24 088 tests ±0  23 771 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 169 runs  ±0  23 852 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.13, dev_all)

     1 files  ±0       1 suites  ±0   3m 54s ⏱️ - 2m 25s
24 418 tests ±0  24 412 ✅ ±0  6 💤 ±0  0 ❌ ±0 
24 499 runs  ±0  24 493 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.13, dev)

     1 files  ±0       1 suites  ±0   5m 8s ⏱️ -20s
24 088 tests ±0  23 771 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 169 runs  ±0  23 852 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.14, dev)

     1 files  ±0       1 suites  ±0   5m 17s ⏱️ -7s
24 088 tests ±0  23 771 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 169 runs  ±0  23 852 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.12, dev)

     1 files  ±0       1 suites  ±0   4m 6s ⏱️ - 1m 24s
24 088 tests ±0  23 771 ✅ ±0  317 💤 ±0  0 ❌ ±0 
24 169 runs  ±0  23 852 ✅ ±0  317 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.11, dev_all)

     1 files  ±0       1 suites  ±0   4m 22s ⏱️ -6s
24 418 tests ±0  24 412 ✅ ±0  6 💤 ±0  0 ❌ ±0 
24 499 runs  ±0  24 493 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.12, dev_all)

     1 files  ±0       1 suites  ±0   6m 2s ⏱️ -20s
24 418 tests ±0  24 412 ✅ ±0  6 💤 ±0  0 ❌ ±0 
24 499 runs  ±0  24 493 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Pytest (3.14, dev_all)

     1 files  ±0       1 suites  ±0   5m 13s ⏱️ +20s
24 418 tests ±0  24 412 ✅ ±0  6 💤 ±0  0 ❌ ±0 
24 499 runs  ±0  24 493 ✅ ±0  6 💤 ±0  0 ❌ ±0 

Results for commit 24bc50e. ± Comparison against base commit c8aa5bd.

♻️ This comment has been updated with latest results.

@romanlutz Roman Lutz (romanlutz) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the Mako and Werkzeug updates and the lockfile changes. The updates are compatible with the declared dependency constraints, and no blocking issues were found in the diff.

Roman Lutz (romanlutz) and others added 3 commits October 7, 2026 23:53
Keep network-weight comparisons exact while allowing normal rounding in the calibrated temperature.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@romanlutz Roman Lutz (romanlutz) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the final Mako and Werkzeug updates and the two test-only float32 tolerance changes. Model-weight comparisons remain exact. No blocking issues found.

@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit a5c07dd Oct 8, 2026
61 checks passed
@romanlutz
Roman Lutz (romanlutz) deleted the dependabot/uv/security-minor-and-patch-f122febbbc branch October 8, 2026 08:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant