Skip to content

Bump idna from 3.13 to 3.15 in the uv group across 1 directory#2726

Merged
filmor merged 1 commit into
masterfrom
dependabot/uv/uv-d665ee01e3
May 20, 2026
Merged

Bump idna from 3.13 to 3.15 in the uv group across 1 directory#2726
filmor merged 1 commit into
masterfrom
dependabot/uv/uv-d665ee01e3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Bumps the uv group with 1 update in the / directory: idna.

Updates idna from 3.13 to 3.15

Changelog

Sourced from idna's changelog.

3.15 (2026-05-12)

  • Enforce DNS-length cap on individual labels early in check_label, short-circuiting contextual-rule processing for oversized input while staying compatible with UTS 46 usage.
  • Tidy core helpers: hoist bidi category sets to module-level frozensets (avoiding per-codepoint list construction), simplify length checks, and reuse the shared _unicode_dots_re from idna.core in the codec module.
  • Use raise ... from err for proper exception chaining and switch internal string formatting to f-strings.
  • Allow flit_core 4.x in the build backend.
  • Expand the ruff lint set (flake8-bugbear, flake8-simplify, pyupgrade, perflint) and apply the surfaced fixes; pin lint CI to Python 3.14.
  • Add Dependabot configuration for GitHub Actions.
  • Convert README and HISTORY from reStructuredText to Markdown.
  • Reference CVE-2026-45409 for the 3.14 advisory in place of the initial GHSA identifier.

Thanks to Felix Yan, Stan Ulbrych, and metsw24-max for contributions to this release.

3.14 (2026-05-10)

  • Removed opportunity to process long inputs into quadratic time by rejecting oversize inputs up-front. Closes a bypass of the CVE-2024-3651 mitigation. [CVE-2026-45409]

Thanks to Stan Ulbrych for reporting the issue.

Commits
  • af30a09 Release 3.15
  • 30314d4 Pre-release 3.15rc0
  • 05d4b21 Merge pull request #237 from kjd/convert-docs-to-markdown
  • 2987fdb Convert README and HISTORY from reStructuredText to Markdown
  • 59fa800 Merge pull request #236 from kjd/dependabot/github_actions/actions-f3e34333ea
  • def6983 Merge branch 'master' into dependabot/github_actions/actions-f3e34333ea
  • bbd8004 Merge pull request #234 from StanFromIreland/patch-1
  • edd07c0 Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group
  • 5557db0 Merge branch 'master' into patch-1
  • f11746c Merge pull request #235 from StanFromIreland/patch-2
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the uv group with 1 update in the / directory: [idna](https://github.com/kjd/idna).


Updates `idna` from 3.13 to 3.15
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.13...v3.15)

---
updated-dependencies:
- dependency-name: idna
  dependency-version: '3.15'
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels May 19, 2026
@filmor filmor merged commit 4a83446 into master May 20, 2026
58 of 59 checks passed
@filmor filmor deleted the dependabot/uv/uv-d665ee01e3 branch May 20, 2026 14:56
CurtHagenlocher pushed a commit to apache/arrow-dotnet that referenced this pull request May 25, 2026
Updated [pythonnet](https://github.com/pythonnet/pythonnet) from 3.0.5
to 3.1.0.

<details>
<summary>Release notes</summary>

_Sourced from [pythonnet's
releases](https://github.com/pythonnet/pythonnet/releases)._

## 3.1.0

## What's Changed
* ci: properly exclude job by @​RobPasMue in
pythonnet/pythonnet#2542
* `__delitem__` for `IList<T>` and `IDictionary<K,V>` by @​lostmsu in
pythonnet/pythonnet#2533
* Fix docs workflow by @​filmor in
pythonnet/pythonnet#2584
* Drop EOLd Python versions by @​filmor in
pythonnet/pythonnet#2632
* Bump setuptools and adjust license information by @​filmor in
pythonnet/pythonnet#2633
* Minimal .NET 8 usage changes by @​filmor in
pythonnet/pythonnet#2634
* Drop performance tests by @​filmor in
pythonnet/pythonnet#2636
* Properly detect availability of BinaryFormatter by @​filmor in
pythonnet/pythonnet#2639
* Use last compiler toolset version that support .NET 8 by @​filmor in
pythonnet/pythonnet#2640
* Add dependabot file by @​filmor in
pythonnet/pythonnet#2642
* Use official ARM runners by @​filmor in
pythonnet/pythonnet#2641
* Bump actions/upload-pages-artifact from 3 to 4 by @​dependabot[bot] in
pythonnet/pythonnet#2644
* Bump actions/setup-python from 2 to 6 by @​dependabot[bot] in
pythonnet/pythonnet#2646
* Bump actions/checkout from 2 to 5 by @​dependabot[bot] in
pythonnet/pythonnet#2648
* Bump actions/setup-dotnet from 1 to 5 by @​dependabot[bot] in
pythonnet/pythonnet#2645
* Use uv and derive as much as possible from the environment, if
available by @​filmor in
pythonnet/pythonnet#2652
* Fixes for the uv CI by @​filmor in
pythonnet/pythonnet#2654
* Bump astral-sh/setup-uv from 6 to 7 by @​dependabot[bot] in
pythonnet/pythonnet#2656
* Bump actions/checkout from 5 to 6 by @​dependabot[bot] in
pythonnet/pythonnet#2663
* Ensure that the tests work even if BinaryFormatter is not available by
@​filmor in pythonnet/pythonnet#2638
* Bump NUnit3TestAdapter from 5.2.0 to 6.0.0 by @​dependabot[bot] in
pythonnet/pythonnet#2667
* Fix line endings by @​filmor in
pythonnet/pythonnet#2668
* Switch to .NET SDK 10 by @​lostmsu in
pythonnet/pythonnet#2684
* Python 3.14 by @​filmor in
pythonnet/pythonnet#2611
* CI Improvements by @​filmor in
pythonnet/pythonnet#2669
* Bump System.Reflection.Emit from 4.3.0 to 4.7.0 by @​dependabot[bot]
in pythonnet/pythonnet#2694
* Bump pytest from 9.0.2 to 9.0.3 in the uv group across 1 directory by
@​dependabot[bot] in pythonnet/pythonnet#2705
* CI Improvements by @​filmor in
pythonnet/pythonnet#2707
* Fix method memleak test by @​filmor in
pythonnet/pythonnet#2708
* Bump actions/upload-pages-artifact from 4 to 5 by @​dependabot[bot] in
pythonnet/pythonnet#2709
* Update furo requirement from >=2022.9.15 to >=2025.12.19 by
@​dependabot[bot] in pythonnet/pythonnet#2711
* Move documentation deps to pyproject.toml by @​filmor in
pythonnet/pythonnet#2714
* Support .NET Framework 4.6.1 by @​Metadorius in
pythonnet/pythonnet#2701
* Fix wheel tags by @​filmor in
pythonnet/pythonnet#2716
* Name missing from __all__ on re-import by @​filmor in
pythonnet/pythonnet#2717
* Add context manager protocol for .NET IDisposable types by
@​den-run-ai in pythonnet/pythonnet#2568
* Fix MethodBinding/OverloadMapper memory leak (#​691) by
@​greateggsgreg in pythonnet/pythonnet#2719
* Bump urllib3 from 2.6.3 to 2.7.0 in the uv group across 1 directory by
@​dependabot[bot] in pythonnet/pythonnet#2723
* Update NUnit by @​filmor in
pythonnet/pythonnet#2724
* Silence compile-time warnings by @​filmor in
pythonnet/pythonnet#2725
* Implement support for DLR get/set by @​filmor in
pythonnet/pythonnet#2706
* Bump idna from 3.13 to 3.15 in the uv group across 1 directory by
@​dependabot[bot] in pythonnet/pythonnet#2726

## New Contributors
* @​RobPasMue made their first contribution in
pythonnet/pythonnet#2542
* @​dependabot[bot] made their first contribution in
pythonnet/pythonnet#2644
* @​Metadorius made their first contribution in
pythonnet/pythonnet#2701

**Full Changelog**:
pythonnet/pythonnet@v3.0.5...v3.1.0

## 3.1.0-rc1

## What's Changed
* CI Improvements by @​filmor in
pythonnet/pythonnet#2669
* Bump System.Reflection.Emit from 4.3.0 to 4.7.0 by @​dependabot[bot]
in pythonnet/pythonnet#2694
* Bump pytest from 9.0.2 to 9.0.3 in the uv group across 1 directory by
@​dependabot[bot] in pythonnet/pythonnet#2705
* CI Improvements by @​filmor in
pythonnet/pythonnet#2707
* Fix method memleak test by @​filmor in
pythonnet/pythonnet#2708
* Bump actions/upload-pages-artifact from 4 to 5 by @​dependabot[bot] in
pythonnet/pythonnet#2709
* Update furo requirement from >=2022.9.15 to >=2025.12.19 by
@​dependabot[bot] in pythonnet/pythonnet#2711
* Move documentation deps to pyproject.toml by @​filmor in
pythonnet/pythonnet#2714
* Support .NET Framework 4.6.1 by @​Metadorius in
pythonnet/pythonnet#2701
* Fix wheel tags by @​filmor in
pythonnet/pythonnet#2716
* Name missing from __all__ on re-import by @​filmor in
pythonnet/pythonnet#2717
* Add context manager protocol for .NET IDisposable types by
@​den-run-ai in pythonnet/pythonnet#2568
* Fix MethodBinding/OverloadMapper memory leak (#​691) by
@​greateggsgreg in pythonnet/pythonnet#2719
* Bump urllib3 from 2.6.3 to 2.7.0 in the uv group across 1 directory by
@​dependabot[bot] in pythonnet/pythonnet#2723
* Update NUnit by @​filmor in
pythonnet/pythonnet#2724
* Silence compile-time warnings by @​filmor in
pythonnet/pythonnet#2725
* Implement support for DLR get/set by @​filmor in
pythonnet/pythonnet#2706

## New Contributors
* @​Metadorius made their first contribution in
pythonnet/pythonnet#2701

**Full Changelog**:
pythonnet/pythonnet@v3.1.0-rc0...v3.1.0-rc1

## 3.1.0-rc0

## What's Changed
* ci: properly exclude job by @​RobPasMue in
pythonnet/pythonnet#2542
* `__delitem__` for `IList<T>` and `IDictionary<K,V>` by @​lostmsu in
pythonnet/pythonnet#2533
* Fix docs workflow by @​filmor in
pythonnet/pythonnet#2584
* Drop EOLd Python versions by @​filmor in
pythonnet/pythonnet#2632
* Bump setuptools and adjust license information by @​filmor in
pythonnet/pythonnet#2633
* Minimal .NET 8 usage changes by @​filmor in
pythonnet/pythonnet#2634
* Drop performance tests by @​filmor in
pythonnet/pythonnet#2636
* Properly detect availability of BinaryFormatter by @​filmor in
pythonnet/pythonnet#2639
* Use last compiler toolset version that support .NET 8 by @​filmor in
pythonnet/pythonnet#2640
* Add dependabot file by @​filmor in
pythonnet/pythonnet#2642
* Use official ARM runners by @​filmor in
pythonnet/pythonnet#2641
* Use uv and derive as much as possible from the environment, if
available by @​filmor in
pythonnet/pythonnet#2652
* Fixes for the uv CI by @​filmor in
pythonnet/pythonnet#2654
* Ensure that the tests work even if BinaryFormatter is not available by
@​filmor in pythonnet/pythonnet#2638
* Fix line endings by @​filmor in
pythonnet/pythonnet#2668
* Switch to .NET SDK 10 by @​lostmsu in
pythonnet/pythonnet#2684
* Python 3.14 by @​filmor in
pythonnet/pythonnet#2611

## New Contributors
* @​RobPasMue made their first contribution in
pythonnet/pythonnet#2542
* @​dependabot[bot] made their first contribution in
pythonnet/pythonnet#2644

**Full Changelog**:
pythonnet/pythonnet@v3.0.5...v3.1.0-rc0

Commits viewable in [compare
view](pythonnet/pythonnet@v3.0.5...v3.1.0).
</details>

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pythonnet&package-manager=nuget&previous-version=3.0.5&new-version=3.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant