chore(deps): update bandit requirement from >=1.8.0 to >=1.9.4#171
chore(deps): update bandit requirement from >=1.8.0 to >=1.9.4#171dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [bandit](https://github.com/PyCQA/bandit) to permit the latest version. - [Release notes](https://github.com/PyCQA/bandit/releases) - [Commits](PyCQA/bandit@1.8.0...1.9.4) --- updated-dependencies: - dependency-name: bandit dependency-version: 1.9.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
π File Changes AnalysisChange AnalysisSource Code Changes
Configuration Changes
Analysis
|
|
π¦ Dependabot β Dependency update detected. This PR will be auto-merged if CI passes and it receives the |
|
π€ Hi @dependabot[bot], I've received your request, and I'm working on it now! You can track my progress in the logs for more details. |
|
π€ I'm sorry @dependabot[bot], but I was unable to process your request. Please see the logs for more details. |
π Security Scan Resultsπ Comprehensive Security ReportGenerated on: Mon Apr 13 10:02:13 UTC 2026 SummaryDependency SecurityCurrent DependenciesVulnerability Scan ResultsNo vulnerabilities found or scan failed Safety Scan ResultsStatic Security Analysis (Bandit)Bandit Security Analysis ReportGenerated on: Mon Apr 13 10:01:09 UTC 2026 SummaryKey Metrics475 assert "Total Issues" in content License ComplianceLicense Compliance ReportGenerated on: Mon Apr 13 09:54:03 UTC 2026 Dependencies and Their LicensesLicense SummaryRecommendations
|
Updates the requirements on bandit to permit the latest version.
Release notes
Sourced from bandit's releases.
Commits
92ae8b8Fix B106 reporting wrong line number on multiline function calls (#1360)c8c8a55Lower version guard in check_ast_node to Python 3.12 (#1355)8f2f928Fix B615 false positive when revision is set via variable (#1358)e27493fInclude filename in nosec 'no failed test' warning (#1363)b69b336Fix B613 crash when reading from stdin (#1361)e418b79Bump docker/build-push-action from 6.18.0 to 6.19.2 (#1357)ff646fdBump docker/login-action from 3.6.0 to 3.7.0 (#1353)c0def6cchore: fixed some typos in comments (#1351)765f00dLimit B614 to torch.load deserializers (#1348)06fbbabBump docker/setup-buildx-action from 3.11.1 to 3.12.0 (#1347)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)