Bump aieng-platform-onboard from 0.4.0 to 0.6.5#101
Conversation
Bumps [aieng-platform-onboard](https://github.com/VectorInstitute/aieng-platform) from 0.4.0 to 0.6.5. - [Release notes](https://github.com/VectorInstitute/aieng-platform/releases) - [Commits](VectorInstitute/aieng-platform@v0.4.0...v0.6.5) --- updated-dependencies: - dependency-name: aieng-platform-onboard dependency-version: 0.6.5 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because the vulnerable package version is pinned by an upstream dependency that has not yet released a fix:
Why this cannot be auto-fixedA patched version of Upgrading Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no compatible patched version is available:
Why this cannot be auto-fixed
A fix requires the Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
Override aieng-platform-onboard's exact authlib==1.6.9 pin using uv override-dependencies to resolve the CSRF vulnerability in authlib's OAuth cache feature. Authlib resolved to 1.7.0. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
Bumps aieng-platform-onboard from 0.4.0 to 0.6.5.
Release notes
Sourced from aieng-platform-onboard's releases.
... (truncated)
Commits
c6b9eb0ci: switch to PyPI Trusted Publishers and bump to v0.6.59b28fcb[pre-commit.ci] pre-commit autoupdate (#85)84078e8[pre-commit.ci] pre-commit autoupdate (#84)6a8e906Bump up package to 0.6.498574a2Add offboard cmd for coder as well (#83)79bf027[pre-commit.ci] pre-commit autoupdate (#82)418ab80[pre-commit.ci] pre-commit autoupdate (#81)b8a27abStyle template icons in analytics dashboardbc44333Fetch template icons (#80)8c3b6a4Merge branch 'main' of github.com:VectorInstitute/aieng-platformDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)