From 9b93d1f2dd850a5b1ba2d4129e17eb0bc5323530 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 5 Jan 2021 05:25:10 +0000 Subject: [PATCH 1/3] Bump idna from 3.0 to 3.1 in /requirements Bumps [idna](https://github.com/kjd/idna) from 3.0 to 3.1. - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.rst) - [Commits](https://github.com/kjd/idna/compare/v3.0...v3.1) Signed-off-by: dependabot[bot] --- requirements/system.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements/system.txt b/requirements/system.txt index 6bcbe7ccb598..e44b102675fa 100644 --- a/requirements/system.txt +++ b/requirements/system.txt @@ -66,9 +66,9 @@ cryptography==3.3.1 \ --hash=sha256:0e85aaae861d0485eb5a79d33226dd6248d2a9f133b81532c8f5aae37de10ff7 \ --hash=sha256:7e177e4bea2de937a584b13645cab32f25e3d96fc0bc4a4cf99c27dc77682be6 # idna is required by cryptography -idna==3.0 \ - --hash=sha256:320229aadbdfc597bc28876748cc0c9d04d476e0fe6caacaaddea146365d9f63 \ - --hash=sha256:c9a26e10e5558412384fac891eefb41957831d31be55f1e2c98ed97a70abb969 +idna==3.1 \ + --hash=sha256:5205d03e7bcbb919cc9c19885f9920d622ca52448306f2377daede5cf3faac16 \ + --hash=sha256:c5b02147e01ea9920e6b0a3f1f7bb833612d507592c837a6c49552768f4054e1 # ipaddress is required by cryptography, docker-py ipaddress==1.0.23 \ --hash=sha256:6e0f4a39e66cb5bb9a137b00276a2eff74f93b71dcbdad6f10ff7df9d3557fcc \ From dc8783cc373aa3fc4a9f979c5967be064e85ac9e Mon Sep 17 00:00:00 2001 From: Andrew Williamson Date: Mon, 11 Jan 2021 17:34:17 +0000 Subject: [PATCH 2/3] roll idna back to 2.10 because requests :roll_eyes: --- requirements/system.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements/system.txt b/requirements/system.txt index e44b102675fa..dde12d8762f4 100644 --- a/requirements/system.txt +++ b/requirements/system.txt @@ -66,9 +66,9 @@ cryptography==3.3.1 \ --hash=sha256:0e85aaae861d0485eb5a79d33226dd6248d2a9f133b81532c8f5aae37de10ff7 \ --hash=sha256:7e177e4bea2de937a584b13645cab32f25e3d96fc0bc4a4cf99c27dc77682be6 # idna is required by cryptography -idna==3.1 \ - --hash=sha256:5205d03e7bcbb919cc9c19885f9920d622ca52448306f2377daede5cf3faac16 \ - --hash=sha256:c5b02147e01ea9920e6b0a3f1f7bb833612d507592c837a6c49552768f4054e1 +idna==2.10 \ + --hash=sha256:b97d804b1e9b523befed77c48dacec60e6dcb0b5391d57af6a65a312a90648c0 \ + --hash=sha256:b307872f855b18632ce0c21c5e45be78c0ea7ae4c15c828c20788b26921eb3f6 # ipaddress is required by cryptography, docker-py ipaddress==1.0.23 \ --hash=sha256:6e0f4a39e66cb5bb9a137b00276a2eff74f93b71dcbdad6f10ff7df9d3557fcc \ From 7121eb6e770c6f470b6847b801d85c173912a3bd Mon Sep 17 00:00:00 2001 From: Andrew Williamson Date: Mon, 11 Jan 2021 17:36:33 +0000 Subject: [PATCH 3/3] add idna 3 to dependabot's ignore list --- .github/dependabot.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 8e10ec9b584f..2bee314fea67 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -33,3 +33,6 @@ updates: - dependency-name: vine versions: - ">= 5" + - dependency-name: idna + versions: + - ">= 3"