chore(deps): bump virtualenv from 21.2.0 to 21.7.13 - #1926
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.2.0 to 21.7.13. - [Release notes](https://github.com/pypa/virtualenv/releases) - [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst) - [Commits](pypa/virtualenv@21.2.0...21.7.13) --- updated-dependencies: - dependency-name: virtualenv dependency-version: 21.7.13 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM, a routine uv.lock dependency bump.
What was reviewed: the exclude-newer metadata normalization, the python-discovery version bump (1.2.0 to 1.6.1, dropping its platformdirs dependency), the virtualenv bump (21.2.0 to 21.7.13), and the relaxed exceptiongroup→typing-extensions marker — all mechanical lockfile changes with matching hashes, no application code touched.
Extended reasoning...
The only changed file is uv.lock: a dependabot-driven bump of virtualenv and its transitive python-discovery dependency, plus a normalized exclude-newer timestamp and a loosened version marker on typing-extensions for exceptiongroup. No source, test, or doc files changed; the surface touched is dev/build tooling resolution, not runtime or security-sensitive application code. The version/hash pairs in the diff are internally consistent and the virtualenv release notes describe security fixes, not new risk, so this is a safe, mechanical bump.
Bumps virtualenv from 21.2.0 to 21.7.13.
Release notes
Sourced from virtualenv's releases.
... (truncated)
Changelog
Sourced from virtualenv's changelog.
... (truncated)
Commits
0c295ffrelease 21.7.134d5a105🐛 fix(activation): stop path command injection in bash and fish (#3252)0525dce👷 ci: scope the nushell apt key to its own repo (#3253)aa8323a🔧 chore: drop misc as a changelog fragment type (#3255)a435477👷 ci: correct a stale checkout pin comment (#3254)9666b42release 21.7.12a01ed3e🐛 fix(seed): verify downloaded wheel digests (#3251)d721ff1🐛 fix(activation): escape batch quote() against injection (#3250)087a2ef🔧 chore(changelog): drop dead CVE-2026-24049 fragment (#3249)73e352arelease 21.7.11You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.