Skip to content

build(deps): cherry-pick 16 dependabot updates from pick-me PRs onto main#44184

Closed
Copilot wants to merge 17 commits intomainfrom
copilot/pick-dependabot-prs-another-one
Closed

build(deps): cherry-pick 16 dependabot updates from pick-me PRs onto main#44184
Copilot wants to merge 17 commits intomainfrom
copilot/pick-dependabot-prs-another-one

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Mar 31, 2026

Cherry-picks commits from 17 open dependabot PRs labelled pick-me into a single branch rebased on main. Where multiple PRs touch the same file, commits are ordered by descending line number to minimize merge conflicts. 2 PRs conflicted and were skipped; 1 security fix was applied manually after its containing PR conflicted.

Applied (16/17)

tools/base/requirements.txt (ordered highest→lowest line):

Independent files:

Skipped (conflicts, left for next pass)

@repokitteh-read-only
Copy link
Copy Markdown

As a reminder, PRs marked as draft will not be automatically assigned reviewers,
or be handled by maintainer-oncall triage.

Please mark your PR as ready when you want it to be reviewed!

🐱

Caused by: #44184 was opened by Copilot.

see: more, trace.

Copilot AI and others added 15 commits March 31, 2026 13:19
…3861)

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
)

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
)

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
…44120)

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
#44112)

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
… go_modules group (#44016)

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
…5.0.0 (#43787)

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
….1 to 1.0.4 in /tools/base

Security fix: Black < 26.3.1 has a vulnerability allowing arbitrary file writes
from unsanitized user input in cache file name. Also updates pathspec to 1.0.4
as required by black 26.3.1.

Partially applies changes from PR #43978.

Co-authored-by: phlax <454682+phlax@users.noreply.github.com>
Copilot AI changed the title [WIP] Pick dependabot PR commits into single PR build(deps): cherry-pick 16 dependabot updates from pick-me PRs onto main Mar 31, 2026
Copilot AI requested a review from phlax March 31, 2026 13:30
@phlax phlax closed this Mar 31, 2026
@phlax phlax deleted the copilot/pick-dependabot-prs-another-one branch April 13, 2026 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants