diff --git a/.github/workflows/qt-ci.yml b/.github/workflows/qt-ci.yml index 2855894..e7570aa 100644 --- a/.github/workflows/qt-ci.yml +++ b/.github/workflows/qt-ci.yml @@ -130,7 +130,7 @@ jobs: env: CALLEE_REPOSITORY: ${{ job.workflow_repository }} CALLEE_SHA: ${{ job.workflow_sha }} - LOCK_SHA256: e8fd018f0ce1d2f8f23d1fe9ce674e384e98e3fc1ac34386e2fa769fede16185 + LOCK_SHA256: 4ee004df4493864cc2af167273833df756dac83bd4163f5a5e38de46c85b02bc PYTHON_VERSION: '3.13' run: | set -euo pipefail diff --git a/CHANGELOG.md b/CHANGELOG.md index d3fd3f0..05e033e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,9 @@ The project follows Semantic Versioning. ## [Unreleased] +- **Bump urllib3 to 2.8.0 in `requirements-qt.txt`** (recompiled via + `uv pip compile --upgrade-package urllib3`): the osv-scan runtime fixture + flagged PYSEC-2026-4176 and PYSEC-2026-4177 on the pinned 2.7.0. - **Fix the dependabot-catalog-convergence update-branch guard.** A bound pull request already current with the base made the API answer `no new commits`, which matched neither the success pattern nor a real diff --git a/catalog/tools.yml b/catalog/tools.yml index 8d96d04..985f1b6 100644 --- a/catalog/tools.yml +++ b/catalog/tools.yml @@ -18,7 +18,7 @@ tools: rather than resolved at run time. Pinning the two top-level names left everything they pull unbounded. lock: requirements-qt.txt - lock_sha256: "e8fd018f0ce1d2f8f23d1fe9ce674e384e98e3fc1ac34386e2fa769fede16185" + lock_sha256: "4ee004df4493864cc2af167273833df756dac83bd4163f5a5e38de46c85b02bc" - id: py7zr name: py7zr homepage: https://github.com/miurahr/py7zr @@ -30,7 +30,7 @@ tools: last_verified: "2026-09-21" notes: aqtinstall's archive backend; locked in the same closure. lock: requirements-qt.txt - lock_sha256: "e8fd018f0ce1d2f8f23d1fe9ce674e384e98e3fc1ac34386e2fa769fede16185" + lock_sha256: "4ee004df4493864cc2af167273833df756dac83bd4163f5a5e38de46c85b02bc" - id: actionlint name: actionlint homepage: "https://github.com/rhysd/actionlint" diff --git a/requirements-qt.txt b/requirements-qt.txt index 034dfbd..d84e077 100644 --- a/requirements-qt.txt +++ b/requirements-qt.txt @@ -1,7 +1,5 @@ -# GENERATED by `uv pip compile --generate-hashes --universal --python-version 3.13 -o requirements-qt.txt requirements-qt.in` -# Do not hand-edit. See requirements-qt.in for why this file exists. # This file was autogenerated by uv via the following command: -# uv pip compile --generate-hashes --universal --python-version 3.13 -o /tmp/qt2.txt requirements-qt.in +# uv pip compile --generate-hashes --universal --python-version 3.13 -o requirements-qt.txt requirements-qt.in aqtinstall==3.3.0 \ --hash=sha256:9c7d85fbe7258be2d7d23fda33f8aff2e8b7536817255eaeaaf4226da8546a31 \ --hash=sha256:e88dbd87226f276fdd5d05347a44578d390d93a7f176e9476fbda0a7c9635f69 @@ -812,7 +810,7 @@ typing-extensions==4.16.0 \ --hash=sha256:481caa481374e813c1b176ada14e97f1f67a4539ce9cfeb3f350d78d6370c2e8 \ --hash=sha256:dc983d19a509c94dba722ee6abd33940f7c05a89e243c47e907eb4db6f1a43e5 # via beautifulsoup4 -urllib3==2.7.0 \ - --hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \ - --hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897 +urllib3==2.8.0 \ + --hash=sha256:0cf3cae568d36aa9576b28dfb35f11328f1cb974ca7647d9475ebb86c75ac6e3 \ + --hash=sha256:63bf2ead4c879426ebf22ef2a781eeb4aa3b4ae798a0435506f8687fd5bb9b63 # via requests