Bump authlib from 1.6.8 to 1.7.0#75
Conversation
Bumps [authlib](https://github.com/authlib/authlib) from 1.6.8 to 1.7.0. - [Release notes](https://github.com/authlib/authlib/releases) - [Commits](authlib/authlib@v1.6.8...v1.7.0) --- updated-dependencies: - dependency-name: authlib dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
67553d8 to
806f09c
Compare
… etc. Rolls up the open dependabot PRs #65, #66, #69, #72, #73, #74, #75, #76 into a single commit. Each bump is a minor/patch release with no breaking changes relevant to this codebase; all chat.completions / Flask-SocketIO / pydantic-v1-validator usage continues to work. - Flask[async] 3.1.2 -> 3.1.3 (#65, #72) - Flask-SocketIO 5.6.0 -> 5.6.1 (#66) - Werkzeug 3.1.5 -> 3.1.8 (#73; supersedes master-targeting #67 which wanted 3.1.6) - python-dotenv 1.2.1 -> 1.2.2 (#69) - requests 2.32.5 -> 2.33.1 (#74) - pydantic 2.12.5 -> 2.13.2 (#76) - Authlib 1.6.8 -> 1.7.0 (#75) Doing this as one commit on dev because dev has diverged from master (Phase 0 + Phase 1 security/architectural work) and each dependabot PR has a requirements.txt conflict against the new pins we added — resolving 8 of those by hand is more churn than just bumping the versions directly.
|
Superseded by e7418eb on dev, which rolls this bump up with the rest of the open dependabot PRs into a single commit. Needed because dev has diverged from master with Phase 0 + Phase 1 work and resolving 8 individual requirements.txt conflicts is more churn than a direct bump. Thanks @dependabot 🤖 |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps authlib from 1.6.8 to 1.7.0.
Release notes
Sourced from authlib's releases.
Commits
5d2e603chore: release 1.7.0767f08bfix: CSRF issue with starlette cliente9aaef3Merge pull request #877 from authlib/merge/1.63c8ec9aMerge branch 'main' into merge/1.6ef09aebchore: release 1.6.103be0846fix: redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError4cf6f97Merge pull request #876 from guillett/patch-123f67b4Update README.md docs.authlib.org/en/latest => docs.authlib.org/en/stable1040163chore: prek autoupdate491209fMerge pull request #875 from azmeuk/doc