chore(deps-dev): Update bandit requirement from 1.8.5 to 1.8.6 by dependabot[bot] · Pull Request #932 · CycloneDX/cyclonedx-python
Updates the requirements on bandit to permit the latest version.
Release notes
Sourced from bandit's releases.
1.8.6
What's Changed
- Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 by
@dependabotin PyCQA/bandit#1279- Bump docker/setup-buildx-action from 3.10.0 to 3.11.1 by
@dependabotin PyCQA/bandit#1278- added hint to FreeBSD package in doc/source/integrations.rst by
@daniel-mohrin PyCQA/bandit#1282- Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 by
@dependabotin PyCQA/bandit#1284- Huggingface revision pinning by
@lukehindsin PyCQA/bandit#1281New Contributors
@daniel-mohrmade their first contribution in PyCQA/bandit#1282Full Changelog: PyCQA/bandit@1.8.5...1.8.6
Commits
2d0b675Huggingface revision pinning (#1281)4cd1337Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 (#1284)ffed1bbadded hint to FreeBSD package in doc/source/integrations.rst (#1282)090ba0fBump docker/setup-buildx-action from 3.10.0 to 3.11.1 (#1278)33c6789Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 (#1279)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)