Skip to content

fix(security): update dependencies [SECURITY] - #5111

Merged
ansibuddy merged 1 commit into
mainfrom
renovate/security
Jul 16, 2026
Merged

ansibuddy merged 1 commit into
mainfrom
renovate/security

Conversation

@renovate

@renovate renovate Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
setuptools (changelog) 82.0.1 → 83.0.0 age confidence

BIT-setuptools-2026-59890 / CVE-2026-59890 / GHSA-h35f-9h28-mq5c / PYSEC-2026-3447

More information

Details

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

References

This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).


Release Notes

pypa/setuptools (setuptools)

v83.0.0

Compare Source


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "before 4am"
  • Automerge
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/security branch from 4d3b6d6 to 598200a Compare July 16, 2026 04:25
@ansibuddy
ansibuddy merged commit cdb4fc6 into main Jul 16, 2026
22 checks passed
@ansibuddy
ansibuddy deleted the renovate/security branch July 16, 2026 06:24
ivanch added a commit to ivanch/haven that referenced this pull request Sep 27, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ansible-lint](https://github.com/ansible/ansible-lint) ([changelog](https://github.com/ansible/ansible-lint/releases)) | minor | `==26.6.0` → `==26.9.0` |

---

### Release Notes

<details>
<summary>ansible/ansible-lint (ansible-lint)</summary>

### [`v26.9.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.9.0)

[Compare Source](ansible/ansible-lint@v26.8.0...v26.9.0)

#### Features

- feat: support `example` section in file `meta/argument_specs.yml` ([#&#8203;5164](ansible/ansible-lint#5164)) [@&#8203;berndfinger](https://github.com/berndfinger)

#### Fixes

- fix: resolve short mock modules during syntax check ([#&#8203;5149](ansible/ansible-lint#5149)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: propagate `extra_vars` to `import_playbook` syntax check ([#&#8203;5148](ansible/ansible-lint#5148)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: resolve nested `include_tasks` relative paths ([#&#8203;5159](ansible/ansible-lint#5159)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: resolve `include_tasks` paths from playbook dir ([#&#8203;5184](ansible/ansible-lint#5184)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: apply profile-level skip list during linting ([#&#8203;5151](ansible/ansible-lint#5151)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: honor `warn_list` after `--fix` rewrites task names ([#&#8203;5085](ansible/ansible-lint#5085)) [@&#8203;santosh7676](https://github.com/santosh7676)
- fix: mock\_modules clobbering collections and args false positives ([#&#8203;5157](ansible/ansible-lint#5157)) [@&#8203;djdanielsson](https://github.com/djdanielsson)
- fix: inject plain-name mock roles path regardless of `--offline` ([#&#8203;5183](ansible/ansible-lint#5183)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: warn users when directory expansion discovers new files ([#&#8203;5158](ansible/ansible-lint#5158)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: skip auto-fix `no-jinja-when` on string-embedded jinja ([#&#8203;5103](ansible/ansible-lint#5103)) [@&#8203;f1047](https://github.com/f1047)
- fix: do not warn when Jinja block indent is only trim-marker noise ([#&#8203;5153](ansible/ansible-lint#5153)) [@&#8203;DSeaStar](https://github.com/DSeaStar)
- fix: preserve blank lines after flow collections ([#&#8203;5178](ansible/ansible-lint#5178)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: add `validate_argspec` to play schema ([#&#8203;5187](ansible/ansible-lint#5187)) [@&#8203;sameeralam3127](https://github.com/sameeralam3127)
- fix: use ThreadPoolExecutor for syntax check workers ([#&#8203;5173](ansible/ansible-lint#5173)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: drop ruamel.yaml.clib ([#&#8203;5163](ansible/ansible-lint#5163)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix(deps): upgrade gitpython 3.1.57 to 3.1.59 ([#&#8203;5152](ansible/ansible-lint#5152)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: upgrade black to >=25.2.0 to address CVE-2026-32274 ([#&#8203;5166](ansible/ansible-lint#5166)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: raise cryptography floor and bump js-yaml for Guardian prod vulns ([#&#8203;5174](ansible/ansible-lint#5174)) [@&#8203;rockygeekz](https://github.com/rockygeekz)

#### Performance

- perf: cache `get_deps_versions()` result ([#&#8203;5113](ansible/ansible-lint#5113)) [@&#8203;BlackDark](https://github.com/BlackDark)

#### Maintenance

- chore: Add `.github/SECURITY.md` ([#&#8203;5165](ansible/ansible-lint#5165)) [@&#8203;gundalow](https://github.com/gundalow)
- chore(deps): update all dependencies and pep621 ([#&#8203;5138](ansible/ansible-lint#5138), [#&#8203;5154](ansible/ansible-lint#5154), [#&#8203;5155](ansible/ansible-lint#5155), [#&#8203;5160](ansible/ansible-lint#5160), [#&#8203;5161](ansible/ansible-lint#5161), [#&#8203;5172](ansible/ansible-lint#5172), [#&#8203;5175](ansible/ansible-lint#5175), [#&#8203;5176](ansible/ansible-lint#5176)) @&#8203;[renovate\[bot\]](https://github.com/apps/renovate)

#### What's Changed

- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5138](ansible/ansible-lint#5138)
- fix: resolve short mock modules during syntax check by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5149](ansible/ansible-lint#5149)
- fix(deps): upgrade gitpython 3.1.57 to 3.1.59 by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5152](ansible/ansible-lint#5152)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5155](ansible/ansible-lint#5155)
- fix: propagate extra\_vars to import\_playbook syntax check by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5148](ansible/ansible-lint#5148)
- fix: warn users when directory expansion discovers new files by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5158](ansible/ansible-lint#5158)
- fix: resolve nested include\_tasks relative paths by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5159](ansible/ansible-lint#5159)
- fix: apply profile-level skip list during linting by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5151](ansible/ansible-lint#5151)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5154](ansible/ansible-lint#5154)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5160](ansible/ansible-lint#5160)
- fix: skip auto-fix no-jinja-when on string-embedded jinja by [@&#8203;f1047](https://github.com/f1047) in [#&#8203;5103](ansible/ansible-lint#5103)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5161](ansible/ansible-lint#5161)
- fix: do not warn when Jinja block indent is only trim-marker noise by [@&#8203;DSeaStar](https://github.com/DSeaStar) in [#&#8203;5153](ansible/ansible-lint#5153)
- chore: Add .github/SECURITY.md by [@&#8203;gundalow](https://github.com/gundalow) in [#&#8203;5165](ansible/ansible-lint#5165)
- fix: upgrade black to >=25.2.0 to address CVE-2026-32274 by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5166](ansible/ansible-lint#5166)
- Fix/drop ruamel yaml clib fresh by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5163](ansible/ansible-lint#5163)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5172](ansible/ansible-lint#5172)
- fix: honor warn\_list after --fix rewrites task names  by [@&#8203;santosh7676](https://github.com/santosh7676) in [#&#8203;5085](ansible/ansible-lint#5085)
- feat: support 'example' section in file meta/argument\_specs.yml by [@&#8203;berndfinger](https://github.com/berndfinger) in [#&#8203;5164](ansible/ansible-lint#5164)
- fix: use ThreadPoolExecutor for syntax check workers by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5173](ansible/ansible-lint#5173)
- fix: mock\_modules clobbering collections and args false positives by [@&#8203;djdanielsson](https://github.com/djdanielsson) in [#&#8203;5157](ansible/ansible-lint#5157)
- fix: raise cryptography floor and bump js-yaml for Guardian prod vulns by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5174](ansible/ansible-lint#5174)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5176](ansible/ansible-lint#5176)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5175](ansible/ansible-lint#5175)
- fix: preserve blank lines after flow collections by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5178](ansible/ansible-lint#5178)
- perf: cache get\_deps\_versions() result by [@&#8203;BlackDark](https://github.com/BlackDark) in [#&#8203;5113](ansible/ansible-lint#5113)
- fix: inject plain-name mock roles path regardless of --offline by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5183](ansible/ansible-lint#5183)
- fix: resolve include\_tasks paths from playbook dir by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5184](ansible/ansible-lint#5184)
- fix: add validate\_argspec to play schema by [@&#8203;sameeralam3127](https://github.com/sameeralam3127) in [#&#8203;5187](ansible/ansible-lint#5187)

#### New Contributors

- [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) made their first contribution in [#&#8203;5149](ansible/ansible-lint#5149)
- [@&#8203;f1047](https://github.com/f1047) made their first contribution in [#&#8203;5103](ansible/ansible-lint#5103)
- [@&#8203;DSeaStar](https://github.com/DSeaStar) made their first contribution in [#&#8203;5153](ansible/ansible-lint#5153)
- [@&#8203;berndfinger](https://github.com/berndfinger) made their first contribution in [#&#8203;5164](ansible/ansible-lint#5164)
- [@&#8203;BlackDark](https://github.com/BlackDark) made their first contribution in [#&#8203;5113](ansible/ansible-lint#5113)
- [@&#8203;sameeralam3127](https://github.com/sameeralam3127) made their first contribution in [#&#8203;5187](ansible/ansible-lint#5187)

**Full Changelog**: <ansible/ansible-lint@v26.8.0...v26.9.0>

### [`v26.8.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.8.0)

[Compare Source](ansible/ansible-lint@v26.6.0...v26.8.0)

#### What's Changed

- Fix/sonarcloud unbounded recursion complexity by [@&#8203;sathyapramod](https://github.com/sathyapramod) in [#&#8203;5098](ansible/ansible-lint#5098)
- feat: honor ANSIBLE\_VAULT\_PASSWORD\_FILE for vault decryption by [@&#8203;JohnLahr](https://github.com/JohnLahr) in [#&#8203;5019](ansible/ansible-lint#5019)
- fix: jinja\[spacing] rule creating invalid syntax for minus modifiers by [@&#8203;Dotify71](https://github.com/Dotify71) in [#&#8203;5102](ansible/ansible-lint#5102)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5081](ansible/ansible-lint#5081)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5082](ansible/ansible-lint#5082)
- fix: remove stale words from cspell dictionary by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5109](ansible/ansible-lint#5109)
- chore(deps): bump schemas npm packages for Dependabot CVEs by [@&#8203;sudhirverma](https://github.com/sudhirverma) in [#&#8203;5114](ansible/ansible-lint#5114)
- fix(security): update dependencies \[SECURITY] by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5111](ansible/ansible-lint#5111)
- fix: address SonarCloud new code violations by [@&#8203;sudhirverma](https://github.com/sudhirverma) in [#&#8203;5116](ansible/ansible-lint#5116)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5121](ansible/ansible-lint#5121)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5122](ansible/ansible-lint#5122)
- fix(deps): exclude ansible-core 2.17.x (CVE-2026-11332) by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5123](ansible/ansible-lint#5123)
- fix: expose ansible-galaxy on the uv tool-install path by [@&#8203;jeffcpullen](https://github.com/jeffcpullen) in [#&#8203;5124](ansible/ansible-lint#5124)
- fix: var-naming for register projections by [@&#8203;0xTaoZ](https://github.com/0xTaoZ) in [#&#8203;5110](ansible/ansible-lint#5110)
- chore: Adding OpenWrt 25.12 as platform by [@&#8203;sscheib](https://github.com/sscheib) in [#&#8203;5132](ansible/ansible-lint#5132)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5134](ansible/ansible-lint#5134)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5133](ansible/ansible-lint#5133)
- fix: add timeout to release-check urlopen() call by [@&#8203;cooperlees](https://github.com/cooperlees) in [#&#8203;5128](ansible/ansible-lint#5128)
- fix: respect ANSIBLE\_HOME env var for cache dir selection ([#&#8203;5806](https://github.com/ansible/ansible-lint/issues/5806)) by [@&#8203;Jkhall81](https://github.com/Jkhall81) in [#&#8203;5105](ansible/ansible-lint#5105)
- fix: deduplicate ANSIBLE\_HOME isolation check by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5140](ansible/ansible-lint#5140)
- fix(security): update dependencies \[SECURITY] by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5141](ansible/ansible-lint#5141)
- fix: do not require role prefix for ansible\_ connection variables by [@&#8203;Sanjays2402](https://github.com/Sanjays2402) in [#&#8203;5130](ansible/ansible-lint#5130)
- Adding missing FreeBSD versions. by [@&#8203;jmpalacios](https://github.com/jmpalacios) in [#&#8203;5143](ansible/ansible-lint#5143)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5139](ansible/ansible-lint#5139)
- fix: prepend runtime cache dir to collections paths ([#&#8203;5137](ansible/ansible-lint#5137)) by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5145](ansible/ansible-lint#5145)

#### New Contributors

- [@&#8203;sathyapramod](https://github.com/sathyapramod) made their first contribution in [#&#8203;5098](ansible/ansible-lint#5098)
- [@&#8203;JohnLahr](https://github.com/JohnLahr) made their first contribution in [#&#8203;5019](ansible/ansible-lint#5019)
- [@&#8203;jeffcpullen](https://github.com/jeffcpullen) made their first contribution in [#&#8203;5124](ansible/ansible-lint#5124)
- [@&#8203;0xTaoZ](https://github.com/0xTaoZ) made their first contribution in [#&#8203;5110](ansible/ansible-lint#5110)
- [@&#8203;cooperlees](https://github.com/cooperlees) made their first contribution in [#&#8203;5128](ansible/ansible-lint#5128)
- [@&#8203;Sanjays2402](https://github.com/Sanjays2402) made their first contribution in [#&#8203;5130](ansible/ansible-lint#5130)
- [@&#8203;jmpalacios](https://github.com/jmpalacios) made their first contribution in [#&#8203;5143](ansible/ansible-lint#5143)

**Full Changelog**: <ansible/ansible-lint@v26.6.0...v26.8.0>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuNyIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

---------

Co-authored-by: Renovate Bot <bot@renovateapp.com>
Reviewed-on: https://git.ivanch.me/ivanch/haven/pulls/17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants