From 662cddca9aabbd411a13c97121361d13e3beb285 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 9 Jul 2024 19:00:58 +0000 Subject: [PATCH 1/6] Bump zipp from 3.17.0 to 3.19.1 in /src Bumps [zipp](https://github.com/jaraco/zipp) from 3.17.0 to 3.19.1. - [Release notes](https://github.com/jaraco/zipp/releases) - [Changelog](https://github.com/jaraco/zipp/blob/main/NEWS.rst) - [Commits](https://github.com/jaraco/zipp/compare/v3.17.0...v3.19.1) --- updated-dependencies: - dependency-name: zipp dependency-type: indirect ... Signed-off-by: dependabot[bot] --- src/requirements-dev.txt | 6 ++---- src/requirements.txt | 2 +- 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/src/requirements-dev.txt b/src/requirements-dev.txt index 069d7838..ec9137c7 100644 --- a/src/requirements-dev.txt +++ b/src/requirements-dev.txt @@ -59,9 +59,7 @@ colorama==0.4.6 colorful==0.5.5 # via ray coverage[toml]==7.3.2 - # via - # coverage - # pytest-cov + # via pytest-cov cryptography==42.0.4 # via -r requirements.txt defusedxml==0.7.1 @@ -367,7 +365,7 @@ wcwidth==0.2.12 # via blessed yarl==1.9.4 # via aiohttp -zipp==3.17.0 +zipp==3.19.1 # via # -r requirements.txt # importlib-resources diff --git a/src/requirements.txt b/src/requirements.txt index ef77ffc2..4c478c08 100644 --- a/src/requirements.txt +++ b/src/requirements.txt @@ -173,5 +173,5 @@ urllib3==2.1.0 # via # -r requirements.in # requests -zipp==3.17.0 +zipp==3.19.1 # via importlib-resources From 28f6de3e43279adf8697c317303973100a0c53ee Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 9 Jul 2024 19:00:58 +0000 Subject: [PATCH 2/6] Bump zipp from 3.17.0 to 3.19.1 in /src Bumps [zipp](https://github.com/jaraco/zipp) from 3.17.0 to 3.19.1. - [Release notes](https://github.com/jaraco/zipp/releases) - [Changelog](https://github.com/jaraco/zipp/blob/main/NEWS.rst) - [Commits](https://github.com/jaraco/zipp/compare/v3.17.0...v3.19.1) --- updated-dependencies: - dependency-name: zipp dependency-type: indirect ... Signed-off-by: dependabot[bot] --- src/requirements-dev.txt | 6 ++---- src/requirements.txt | 2 +- 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/src/requirements-dev.txt b/src/requirements-dev.txt index 90f29504..1b6b689a 100644 --- a/src/requirements-dev.txt +++ b/src/requirements-dev.txt @@ -59,9 +59,7 @@ colorama==0.4.6 colorful==0.5.5 # via ray coverage[toml]==7.3.2 - # via - # coverage - # pytest-cov + # via pytest-cov cryptography==42.0.4 # via -r requirements.txt defusedxml==0.7.1 @@ -367,7 +365,7 @@ wcwidth==0.2.12 # via blessed yarl==1.9.4 # via aiohttp -zipp==3.17.0 +zipp==3.19.1 # via # -r requirements.txt # importlib-resources diff --git a/src/requirements.txt b/src/requirements.txt index 4a04fef1..be9005d7 100644 --- a/src/requirements.txt +++ b/src/requirements.txt @@ -175,5 +175,5 @@ urllib3==2.2.2 # via # -r requirements.in # requests -zipp==3.17.0 +zipp==3.19.1 # via importlib-resources From 0c31de012b0bbad41f1a1c2759d92cf0e78cbcf5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 9 Jul 2024 19:00:58 +0000 Subject: [PATCH 3/6] Bump zipp from 3.17.0 to 3.19.1 in /src Bumps [zipp](https://github.com/jaraco/zipp) from 3.17.0 to 3.19.1. - [Release notes](https://github.com/jaraco/zipp/releases) - [Changelog](https://github.com/jaraco/zipp/blob/main/NEWS.rst) - [Commits](https://github.com/jaraco/zipp/compare/v3.17.0...v3.19.1) --- updated-dependencies: - dependency-name: zipp dependency-type: indirect ... Signed-off-by: dependabot[bot] --- src/requirements-dev.txt | 6 ++---- src/requirements.txt | 2 +- 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/src/requirements-dev.txt b/src/requirements-dev.txt index 90f29504..1b6b689a 100644 --- a/src/requirements-dev.txt +++ b/src/requirements-dev.txt @@ -59,9 +59,7 @@ colorama==0.4.6 colorful==0.5.5 # via ray coverage[toml]==7.3.2 - # via - # coverage - # pytest-cov + # via pytest-cov cryptography==42.0.4 # via -r requirements.txt defusedxml==0.7.1 @@ -367,7 +365,7 @@ wcwidth==0.2.12 # via blessed yarl==1.9.4 # via aiohttp -zipp==3.17.0 +zipp==3.19.1 # via # -r requirements.txt # importlib-resources diff --git a/src/requirements.txt b/src/requirements.txt index 4a04fef1..be9005d7 100644 --- a/src/requirements.txt +++ b/src/requirements.txt @@ -175,5 +175,5 @@ urllib3==2.2.2 # via # -r requirements.in # requests -zipp==3.17.0 +zipp==3.19.1 # via importlib-resources From 7344243c066e979c510b14c0a7064db055743ff5 Mon Sep 17 00:00:00 2001 From: Anthony Romaniello Date: Thu, 25 Jul 2024 13:36:06 -0600 Subject: [PATCH 4/6] Update requirements.in and recompile requirements --- src/requirements-dev.txt | 4 +++- src/requirements.in | 1 + src/requirements.txt | 4 +++- 3 files changed, 7 insertions(+), 2 deletions(-) diff --git a/src/requirements-dev.txt b/src/requirements-dev.txt index 1b6b689a..aa9e3963 100644 --- a/src/requirements-dev.txt +++ b/src/requirements-dev.txt @@ -59,7 +59,9 @@ colorama==0.4.6 colorful==0.5.5 # via ray coverage[toml]==7.3.2 - # via pytest-cov + # via + # coverage + # pytest-cov cryptography==42.0.4 # via -r requirements.txt defusedxml==0.7.1 diff --git a/src/requirements.in b/src/requirements.in index 3013ded1..e70f4996 100644 --- a/src/requirements.in +++ b/src/requirements.in @@ -21,3 +21,4 @@ grpcio>=1.53.0 # CVE-2023-32732, CVE-2023-32731, CVE-2023-1428 pyyaml>=5.4.0 # CVE-2020-14343 sqlparse>=0.5.0 # CVE-2024-4340 urllib3>=2.2.2 # CVE-2024-37891 +zipp>=3.19.1 # CVE-2024-5569 diff --git a/src/requirements.txt b/src/requirements.txt index be9005d7..1e16bb40 100644 --- a/src/requirements.txt +++ b/src/requirements.txt @@ -176,4 +176,6 @@ urllib3==2.2.2 # -r requirements.in # requests zipp==3.19.1 - # via importlib-resources + # via + # -r requirements.in + # importlib-resources From dca2773219febe1b2dd24dd7bafa1eaea779c3ef Mon Sep 17 00:00:00 2001 From: Anthony Romaniello Date: Thu, 25 Jul 2024 13:39:07 -0600 Subject: [PATCH 5/6] Update all pre-commit hooks --- .pre-commit-config.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 09e02539..a7da6b86 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -3,7 +3,7 @@ default_language_version: python: python3.8 repos: - repo: https://github.com/pre-commit/pre-commit-hooks - rev: v4.5.0 + rev: v4.6.0 hooks: - id: check-ast types: [file, python] @@ -19,7 +19,7 @@ repos: - id: end-of-file-fixer - id: trailing-whitespace - repo: https://github.com/asottile/pyupgrade - rev: v3.15.2 + rev: v3.16.0 hooks: - id: pyupgrade args: ["--py38-plus"] @@ -31,12 +31,12 @@ repos: types: [file, python] args: ["--profile", "black", "--filter-files", "--gitignore"] - repo: https://github.com/psf/black - rev: 24.3.0 + rev: 24.4.2 hooks: - id: black types: [file, python] - repo: https://github.com/igorshubovych/markdownlint-cli - rev: v0.39.0 + rev: v0.41.0 hooks: - id: markdownlint types: [file, markdown] From 9048d9897803f78fca71492cede0d34928087409 Mon Sep 17 00:00:00 2001 From: Anthony Romaniello Date: Thu, 25 Jul 2024 13:39:28 -0600 Subject: [PATCH 6/6] Run pre-commit hooks on all files --- compose.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/compose.yaml b/compose.yaml index c2cf9e21..6a2bec6d 100644 --- a/compose.yaml +++ b/compose.yaml @@ -19,7 +19,7 @@ services: options: max-file: 20 max-size: 10m - + api: healthcheck: