Skip to content

Commit c334cba

Browse files
chore(deps)(deps): Bump the production-dependencies group with 23 updates
--- updated-dependencies: - dependency-name: requests dependency-version: 2.32.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-dependencies - dependency-name: httpx dependency-version: 0.28.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: uvicorn[standard] dependency-version: 0.38.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyvisa dependency-version: 1.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyvisa-py dependency-version: 0.8.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyusb dependency-version: 1.3.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pandas dependency-version: 2.3.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: h5py dependency-version: 3.15.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: scipy dependency-version: 1.16.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pydantic dependency-version: 2.12.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pydantic-settings dependency-version: 2.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: python-dotenv dependency-version: 1.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: email-validator dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: python-dateutil dependency-version: 2.9.0.post0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: apscheduler dependency-version: 3.11.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: zeroconf dependency-version: 0.148.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyqt6 dependency-version: 6.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyqt6-qt6 dependency-version: 6.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyqt6-charts dependency-version: 6.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyqt6-charts-qt6 dependency-version: 6.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: pyqtgraph dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: aiohttp dependency-version: 3.13.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies - dependency-name: scp dependency-version: 0.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 8655c3e commit c334cba

File tree

3 files changed

+33
-33
lines changed

3 files changed

+33
-33
lines changed

client/requirements.txt

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,34 +1,34 @@
11
# GUI Framework
2-
PyQt6==6.6.1
3-
PyQt6-Qt6==6.6.1
4-
PyQt6-Charts==6.6.0
5-
PyQt6-Charts-Qt6==6.6.0
6-
pyqtgraph==0.13.3
2+
PyQt6==6.10.1
3+
PyQt6-Qt6==6.10.1
4+
PyQt6-Charts==6.10.0
5+
PyQt6-Charts-Qt6==6.10.1
6+
pyqtgraph==0.14.0
77

88
# Networking
9-
requests==2.32.4 # Security: Fixes CVE-2024-47081 (netrc leak), CVE-2024-35195 (verify=False persistence)
9+
requests==2.32.5 # Security: Fixes CVE-2024-47081 (netrc leak), CVE-2024-35195 (verify=False persistence)
1010
websockets==12.0
11-
aiohttp==3.12.14 # Security: Fixes CVE-2024-23334 (directory traversal), CVE-2024-30251 (DoS), CVE-2024-52304 (request smuggling), CVE-2024-27306 (XSS), CVE-2024-23829 (HTTP parser), CVE-2025-53643 (smuggling)
11+
aiohttp==3.13.2 # Security: Fixes CVE-2024-23334 (directory traversal), CVE-2024-30251 (DoS), CVE-2024-52304 (request smuggling), CVE-2024-27306 (XSS), CVE-2024-23829 (HTTP parser), CVE-2025-53643 (smuggling)
1212

1313
# SSH and Deployment
1414
paramiko==3.4.0
15-
scp==0.14.5
15+
scp==0.15.0
1616

1717
# Network Discovery
1818
# scapy removed due to security vulnerability with no patch (pickle deserialization RCE, <=2.6.1)
1919
# Not used in codebase - was planned for network scanning but never implemented
20-
zeroconf==0.132.2
20+
zeroconf==0.148.0
2121

2222
# Data Handling
2323
numpy==1.26.3
24-
pandas==2.2.0
25-
h5py==3.10.0
24+
pandas==2.3.3
25+
h5py==3.15.1
2626

2727
# Configuration
28-
pydantic==2.5.3
29-
pydantic-settings==2.1.0
30-
python-dotenv==1.0.0
28+
pydantic==2.12.5
29+
pydantic-settings==2.12.0
30+
python-dotenv==1.2.1
3131

3232
# Utilities
33-
python-dateutil==2.8.2
33+
python-dateutil==2.9.0.post0
3434
qasync

server/requirements.txt

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,35 +1,35 @@
11
# Web Framework
22
fastapi>=0.115.0 # Security: Fixes PYSEC-2024-38 (ReDoS), upgrades starlette to fix GHSA-f96h-pmfr-66vw, GHSA-2c2j-9gv5-cj73
3-
uvicorn[standard]==0.27.0
3+
uvicorn[standard]==0.38.0
44
websockets==12.0
55
python-multipart>=0.0.18 # Required for FastAPI file uploads (Form/File parameters). Security: Fixes GHSA-2jv5-9r88-3w3p (ReDoS), GHSA-59g5-xgcq-4qw3 (DoS)
66

77
# Equipment Communication
8-
pyvisa==1.14.1
9-
pyvisa-py==0.7.1
8+
pyvisa==1.15.0
9+
pyvisa-py==0.8.1
1010
pyserial==3.5
1111

1212
# USB/Device Access
13-
pyusb==1.2.1
13+
pyusb==1.3.1
1414

1515
# Data Handling
1616
numpy==1.26.3
17-
pandas==2.2.0
18-
h5py==3.10.0
19-
scipy==1.11.4
17+
pandas==2.3.3
18+
h5py==3.15.1
19+
scipy==1.16.3
2020

2121
# Configuration
22-
pydantic==2.5.3
23-
pydantic-settings==2.1.0
24-
python-dotenv==1.0.0
25-
email-validator==2.1.0
22+
pydantic==2.12.5
23+
pydantic-settings==2.12.0
24+
python-dotenv==1.2.1
25+
email-validator==2.3.0
2626

2727
# Utilities
28-
python-dateutil==2.8.2
28+
python-dateutil==2.9.0.post0
2929
psutil==5.9.8
30-
apscheduler==3.10.4
31-
zeroconf==0.132.2
32-
requests==2.32.4 # HTTP library for Pi discovery. Security: Fixes GHSA-9wx4-h78v-vm56 (cert verification), GHSA-9hjg-9r4m-mvj7 (netrc leak)
30+
apscheduler==3.11.1
31+
zeroconf==0.148.0
32+
requests==2.32.5 # HTTP library for Pi discovery. Security: Fixes GHSA-9wx4-h78v-vm56 (cert verification), GHSA-9hjg-9r4m-mvj7 (netrc leak)
3333
docker==7.1.0 # Docker Python API for running Pi diagnostics on host
3434

3535
# Testing
@@ -38,7 +38,7 @@ pytest-asyncio==0.23.3
3838

3939
# Security & Authentication
4040
bcrypt==4.1.3 # Password hashing
41-
httpx==0.27.0 # Async HTTP client for OAuth2
41+
httpx==0.28.1 # Async HTTP client for OAuth2
4242
PyJWT==2.10.1 # JWT token handling
4343
pyotp==2.9.0 # TOTP multi-factor authentication
4444
qrcode[pil]==8.2 # QR code generation with PIL support

shared/requirements.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
11
# Shared dependencies between client and server
2-
pydantic==2.5.3
3-
python-dateutil==2.8.2
2+
pydantic==2.12.5
3+
python-dateutil==2.9.0.post0

0 commit comments

Comments
 (0)