Skip to content
This repository was archived by the owner on Sep 29, 2026. It is now read-only.

Bump black, pytest, idna, and urllib3 for Dependabot alerts - #565

Merged
rbailey-godaddy merged 2 commits into
mainfrom
fix/dependabot-security-bumps
Sep 22, 2026
Merged

rbailey-godaddy merged 2 commits into
mainfrom
fix/dependabot-security-bumps

Conversation

@rbailey-godaddy

Copy link
Copy Markdown
Contributor

To help us get this pull request reviewed and merged quickly, please be sure to include the following items:

  • Tests (if applicable)
  • Documentation (if applicable)
  • Changelog entry
  • A full explanation here in the PR description of the work done

PR Type

What kind of change does this PR introduce?

  • Bugfix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • CI related changes
  • Documentation content changes
  • Tests
  • Other

Backward Compatibility

Is this change backward compatible with the most recently released version? Does it introduce changes which might change the user experience in any way? Does it alter the API in any way?

  • Yes (backward compatible)
  • No (breaking changes)

Issue Linking

Closes Dependabot alerts for black, pytest, idna, and urllib3.

What's new?

  • Bump direct/dev constraints: black>=26.3.1, pytest>=9.0.3
  • Refresh poetry.lock to resolve security alerts:
    • black 25.9.0 → 26.5.1
    • pytest 8.4.2 → 9.1.1
    • idna 3.11 → 3.20
    • urllib3 2.6.3 → 2.8.0
  • Run the black tox/CI jobs on Python 3.14 so Black's py314 target-version safety check succeeds
  • Apply Black 26 reformatting to the files it flagged

Test plan

  • poetry run pytest (212 passed, 1 skipped)
  • tox -e black

Made with Cursor

Also run the black tox/CI jobs on Python 3.14 so Black's py314
target-version safety check succeeds, and apply its reformats.

Co-authored-by: Cursor <cursoragent@cursor.com>
CI only installs 3.14 for linting; mypy/pylint/vulture/docs still
required 3.13 and were skipped, failing the job.

Co-authored-by: Cursor <cursoragent@cursor.com>
@rbailey-godaddy
rbailey-godaddy merged commit b844f50 into main Sep 22, 2026
24 checks passed
@rbailey-godaddy
rbailey-godaddy deleted the fix/dependabot-security-bumps branch September 22, 2026 22:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants