Repository navigation
fix(security): update dependencies [SECURITY] - #5111
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/security
branch
from
July 16, 2026 04:25
4d3b6d6 to
598200a
Compare
rockygeekz
approved these changes
Jul 16, 2026
1 task
ivanch
added a commit
to ivanch/haven
that referenced
this pull request
Sep 27, 2026
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ansible-lint](https://github.com/ansible/ansible-lint) ([changelog](https://github.com/ansible/ansible-lint/releases)) | minor | `==26.6.0` → `==26.9.0` | --- ### Release Notes <details> <summary>ansible/ansible-lint (ansible-lint)</summary> ### [`v26.9.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.9.0) [Compare Source](ansible/ansible-lint@v26.8.0...v26.9.0) #### Features - feat: support `example` section in file `meta/argument_specs.yml` ([#​5164](ansible/ansible-lint#5164)) [@​berndfinger](https://github.com/berndfinger) #### Fixes - fix: resolve short mock modules during syntax check ([#​5149](ansible/ansible-lint#5149)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: propagate `extra_vars` to `import_playbook` syntax check ([#​5148](ansible/ansible-lint#5148)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: resolve nested `include_tasks` relative paths ([#​5159](ansible/ansible-lint#5159)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: resolve `include_tasks` paths from playbook dir ([#​5184](ansible/ansible-lint#5184)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: apply profile-level skip list during linting ([#​5151](ansible/ansible-lint#5151)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: honor `warn_list` after `--fix` rewrites task names ([#​5085](ansible/ansible-lint#5085)) [@​santosh7676](https://github.com/santosh7676) - fix: mock\_modules clobbering collections and args false positives ([#​5157](ansible/ansible-lint#5157)) [@​djdanielsson](https://github.com/djdanielsson) - fix: inject plain-name mock roles path regardless of `--offline` ([#​5183](ansible/ansible-lint#5183)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: warn users when directory expansion discovers new files ([#​5158](ansible/ansible-lint#5158)) [@​rockygeekz](https://github.com/rockygeekz) - fix: skip auto-fix `no-jinja-when` on string-embedded jinja ([#​5103](ansible/ansible-lint#5103)) [@​f1047](https://github.com/f1047) - fix: do not warn when Jinja block indent is only trim-marker noise ([#​5153](ansible/ansible-lint#5153)) [@​DSeaStar](https://github.com/DSeaStar) - fix: preserve blank lines after flow collections ([#​5178](ansible/ansible-lint#5178)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: add `validate_argspec` to play schema ([#​5187](ansible/ansible-lint#5187)) [@​sameeralam3127](https://github.com/sameeralam3127) - fix: use ThreadPoolExecutor for syntax check workers ([#​5173](ansible/ansible-lint#5173)) [@​rockygeekz](https://github.com/rockygeekz) - fix: drop ruamel.yaml.clib ([#​5163](ansible/ansible-lint#5163)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix(deps): upgrade gitpython 3.1.57 to 3.1.59 ([#​5152](ansible/ansible-lint#5152)) [@​rockygeekz](https://github.com/rockygeekz) - fix: upgrade black to >=25.2.0 to address CVE-2026-32274 ([#​5166](ansible/ansible-lint#5166)) [@​shvenkat-rh](https://github.com/shvenkat-rh) - fix: raise cryptography floor and bump js-yaml for Guardian prod vulns ([#​5174](ansible/ansible-lint#5174)) [@​rockygeekz](https://github.com/rockygeekz) #### Performance - perf: cache `get_deps_versions()` result ([#​5113](ansible/ansible-lint#5113)) [@​BlackDark](https://github.com/BlackDark) #### Maintenance - chore: Add `.github/SECURITY.md` ([#​5165](ansible/ansible-lint#5165)) [@​gundalow](https://github.com/gundalow) - chore(deps): update all dependencies and pep621 ([#​5138](ansible/ansible-lint#5138), [#​5154](ansible/ansible-lint#5154), [#​5155](ansible/ansible-lint#5155), [#​5160](ansible/ansible-lint#5160), [#​5161](ansible/ansible-lint#5161), [#​5172](ansible/ansible-lint#5172), [#​5175](ansible/ansible-lint#5175), [#​5176](ansible/ansible-lint#5176)) @​[renovate\[bot\]](https://github.com/apps/renovate) #### What's Changed - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5138](ansible/ansible-lint#5138) - fix: resolve short mock modules during syntax check by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5149](ansible/ansible-lint#5149) - fix(deps): upgrade gitpython 3.1.57 to 3.1.59 by [@​rockygeekz](https://github.com/rockygeekz) in [#​5152](ansible/ansible-lint#5152) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5155](ansible/ansible-lint#5155) - fix: propagate extra\_vars to import\_playbook syntax check by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5148](ansible/ansible-lint#5148) - fix: warn users when directory expansion discovers new files by [@​rockygeekz](https://github.com/rockygeekz) in [#​5158](ansible/ansible-lint#5158) - fix: resolve nested include\_tasks relative paths by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5159](ansible/ansible-lint#5159) - fix: apply profile-level skip list during linting by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5151](ansible/ansible-lint#5151) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5154](ansible/ansible-lint#5154) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5160](ansible/ansible-lint#5160) - fix: skip auto-fix no-jinja-when on string-embedded jinja by [@​f1047](https://github.com/f1047) in [#​5103](ansible/ansible-lint#5103) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5161](ansible/ansible-lint#5161) - fix: do not warn when Jinja block indent is only trim-marker noise by [@​DSeaStar](https://github.com/DSeaStar) in [#​5153](ansible/ansible-lint#5153) - chore: Add .github/SECURITY.md by [@​gundalow](https://github.com/gundalow) in [#​5165](ansible/ansible-lint#5165) - fix: upgrade black to >=25.2.0 to address CVE-2026-32274 by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5166](ansible/ansible-lint#5166) - Fix/drop ruamel yaml clib fresh by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5163](ansible/ansible-lint#5163) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5172](ansible/ansible-lint#5172) - fix: honor warn\_list after --fix rewrites task names by [@​santosh7676](https://github.com/santosh7676) in [#​5085](ansible/ansible-lint#5085) - feat: support 'example' section in file meta/argument\_specs.yml by [@​berndfinger](https://github.com/berndfinger) in [#​5164](ansible/ansible-lint#5164) - fix: use ThreadPoolExecutor for syntax check workers by [@​rockygeekz](https://github.com/rockygeekz) in [#​5173](ansible/ansible-lint#5173) - fix: mock\_modules clobbering collections and args false positives by [@​djdanielsson](https://github.com/djdanielsson) in [#​5157](ansible/ansible-lint#5157) - fix: raise cryptography floor and bump js-yaml for Guardian prod vulns by [@​rockygeekz](https://github.com/rockygeekz) in [#​5174](ansible/ansible-lint#5174) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5176](ansible/ansible-lint#5176) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5175](ansible/ansible-lint#5175) - fix: preserve blank lines after flow collections by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5178](ansible/ansible-lint#5178) - perf: cache get\_deps\_versions() result by [@​BlackDark](https://github.com/BlackDark) in [#​5113](ansible/ansible-lint#5113) - fix: inject plain-name mock roles path regardless of --offline by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5183](ansible/ansible-lint#5183) - fix: resolve include\_tasks paths from playbook dir by [@​shvenkat-rh](https://github.com/shvenkat-rh) in [#​5184](ansible/ansible-lint#5184) - fix: add validate\_argspec to play schema by [@​sameeralam3127](https://github.com/sameeralam3127) in [#​5187](ansible/ansible-lint#5187) #### New Contributors - [@​shvenkat-rh](https://github.com/shvenkat-rh) made their first contribution in [#​5149](ansible/ansible-lint#5149) - [@​f1047](https://github.com/f1047) made their first contribution in [#​5103](ansible/ansible-lint#5103) - [@​DSeaStar](https://github.com/DSeaStar) made their first contribution in [#​5153](ansible/ansible-lint#5153) - [@​berndfinger](https://github.com/berndfinger) made their first contribution in [#​5164](ansible/ansible-lint#5164) - [@​BlackDark](https://github.com/BlackDark) made their first contribution in [#​5113](ansible/ansible-lint#5113) - [@​sameeralam3127](https://github.com/sameeralam3127) made their first contribution in [#​5187](ansible/ansible-lint#5187) **Full Changelog**: <ansible/ansible-lint@v26.8.0...v26.9.0> ### [`v26.8.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.8.0) [Compare Source](ansible/ansible-lint@v26.6.0...v26.8.0) #### What's Changed - Fix/sonarcloud unbounded recursion complexity by [@​sathyapramod](https://github.com/sathyapramod) in [#​5098](ansible/ansible-lint#5098) - feat: honor ANSIBLE\_VAULT\_PASSWORD\_FILE for vault decryption by [@​JohnLahr](https://github.com/JohnLahr) in [#​5019](ansible/ansible-lint#5019) - fix: jinja\[spacing] rule creating invalid syntax for minus modifiers by [@​Dotify71](https://github.com/Dotify71) in [#​5102](ansible/ansible-lint#5102) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5081](ansible/ansible-lint#5081) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5082](ansible/ansible-lint#5082) - fix: remove stale words from cspell dictionary by [@​rockygeekz](https://github.com/rockygeekz) in [#​5109](ansible/ansible-lint#5109) - chore(deps): bump schemas npm packages for Dependabot CVEs by [@​sudhirverma](https://github.com/sudhirverma) in [#​5114](ansible/ansible-lint#5114) - fix(security): update dependencies \[SECURITY] by [@​renovate](https://github.com/renovate)\[bot] in [#​5111](ansible/ansible-lint#5111) - fix: address SonarCloud new code violations by [@​sudhirverma](https://github.com/sudhirverma) in [#​5116](ansible/ansible-lint#5116) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5121](ansible/ansible-lint#5121) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5122](ansible/ansible-lint#5122) - fix(deps): exclude ansible-core 2.17.x (CVE-2026-11332) by [@​rockygeekz](https://github.com/rockygeekz) in [#​5123](ansible/ansible-lint#5123) - fix: expose ansible-galaxy on the uv tool-install path by [@​jeffcpullen](https://github.com/jeffcpullen) in [#​5124](ansible/ansible-lint#5124) - fix: var-naming for register projections by [@​0xTaoZ](https://github.com/0xTaoZ) in [#​5110](ansible/ansible-lint#5110) - chore: Adding OpenWrt 25.12 as platform by [@​sscheib](https://github.com/sscheib) in [#​5132](ansible/ansible-lint#5132) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5134](ansible/ansible-lint#5134) - chore(deps): update all dependencies by [@​renovate](https://github.com/renovate)\[bot] in [#​5133](ansible/ansible-lint#5133) - fix: add timeout to release-check urlopen() call by [@​cooperlees](https://github.com/cooperlees) in [#​5128](ansible/ansible-lint#5128) - fix: respect ANSIBLE\_HOME env var for cache dir selection ([#​5806](https://github.com/ansible/ansible-lint/issues/5806)) by [@​Jkhall81](https://github.com/Jkhall81) in [#​5105](ansible/ansible-lint#5105) - fix: deduplicate ANSIBLE\_HOME isolation check by [@​rockygeekz](https://github.com/rockygeekz) in [#​5140](ansible/ansible-lint#5140) - fix(security): update dependencies \[SECURITY] by [@​renovate](https://github.com/renovate)\[bot] in [#​5141](ansible/ansible-lint#5141) - fix: do not require role prefix for ansible\_ connection variables by [@​Sanjays2402](https://github.com/Sanjays2402) in [#​5130](ansible/ansible-lint#5130) - Adding missing FreeBSD versions. by [@​jmpalacios](https://github.com/jmpalacios) in [#​5143](ansible/ansible-lint#5143) - chore(deps): update all dependencies pep621 by [@​renovate](https://github.com/renovate)\[bot] in [#​5139](ansible/ansible-lint#5139) - fix: prepend runtime cache dir to collections paths ([#​5137](ansible/ansible-lint#5137)) by [@​rockygeekz](https://github.com/rockygeekz) in [#​5145](ansible/ansible-lint#5145) #### New Contributors - [@​sathyapramod](https://github.com/sathyapramod) made their first contribution in [#​5098](ansible/ansible-lint#5098) - [@​JohnLahr](https://github.com/JohnLahr) made their first contribution in [#​5019](ansible/ansible-lint#5019) - [@​jeffcpullen](https://github.com/jeffcpullen) made their first contribution in [#​5124](ansible/ansible-lint#5124) - [@​0xTaoZ](https://github.com/0xTaoZ) made their first contribution in [#​5110](ansible/ansible-lint#5110) - [@​cooperlees](https://github.com/cooperlees) made their first contribution in [#​5128](ansible/ansible-lint#5128) - [@​Sanjays2402](https://github.com/Sanjays2402) made their first contribution in [#​5130](ansible/ansible-lint#5130) - [@​jmpalacios](https://github.com/jmpalacios) made their first contribution in [#​5143](ansible/ansible-lint#5143) **Full Changelog**: <ansible/ansible-lint@v26.6.0...v26.8.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuNyIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> --------- Co-authored-by: Renovate Bot <bot@renovateapp.com> Reviewed-on: https://git.ivanch.me/ivanch/haven/pulls/17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
82.0.1→83.0.0BIT-setuptools-2026-59890 / CVE-2026-59890 / GHSA-h35f-9h28-mq5c / PYSEC-2026-3447
More information
Details
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
Release Notes
pypa/setuptools (setuptools)
v83.0.0Compare Source
Configuration
📅 Schedule: (in timezone UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.