From 2d3d02858adf397ac1010639e8a2b49533ef1840 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 26 Jan 2026 17:00:59 +0000 Subject: [PATCH] chore(deps)(deps): Bump the client-dependencies group across 1 directory with 14 updates --- updated-dependencies: - dependency-name: pyqt6 dependency-version: 6.10.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: pyqt6-qt6 dependency-version: 6.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: pyqt6-charts dependency-version: 6.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: pyqt6-charts-qt6 dependency-version: 6.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: pyqtgraph dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: requests dependency-version: 2.32.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: client-dependencies - dependency-name: aiohttp dependency-version: 3.13.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: scp dependency-version: 0.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: zeroconf dependency-version: 0.148.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: h5py dependency-version: 3.15.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: pydantic dependency-version: 2.12.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: pydantic-settings dependency-version: 2.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: python-dotenv dependency-version: 1.2.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies - dependency-name: python-dateutil dependency-version: 2.9.0.post0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: client-dependencies ... Signed-off-by: dependabot[bot] --- client/requirements.txt | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/client/requirements.txt b/client/requirements.txt index fc9e0cd..de851be 100644 --- a/client/requirements.txt +++ b/client/requirements.txt @@ -1,34 +1,34 @@ # GUI Framework -PyQt6==6.6.1 -PyQt6-Qt6==6.6.1 -PyQt6-Charts==6.6.0 -PyQt6-Charts-Qt6==6.6.0 -pyqtgraph==0.13.3 +PyQt6==6.10.2 +PyQt6-Qt6==6.10.1 +PyQt6-Charts==6.10.0 +PyQt6-Charts-Qt6==6.10.1 +pyqtgraph==0.14.0 # Networking -requests==2.32.4 # Security: Fixes CVE-2024-47081 (netrc leak), CVE-2024-35195 (verify=False persistence) +requests==2.32.5 # Security: Fixes CVE-2024-47081 (netrc leak), CVE-2024-35195 (verify=False persistence) websockets==12.0 -aiohttp==3.12.14 # Security: Fixes CVE-2024-23334 (directory traversal), CVE-2024-30251 (DoS), CVE-2024-52304 (request smuggling), CVE-2024-27306 (XSS), CVE-2024-23829 (HTTP parser), CVE-2025-53643 (smuggling) +aiohttp==3.13.3 # Security: Fixes CVE-2024-23334 (directory traversal), CVE-2024-30251 (DoS), CVE-2024-52304 (request smuggling), CVE-2024-27306 (XSS), CVE-2024-23829 (HTTP parser), CVE-2025-53643 (smuggling) # SSH and Deployment paramiko==3.4.0 -scp==0.14.5 +scp==0.15.0 # Network Discovery # scapy removed due to security vulnerability with no patch (pickle deserialization RCE, <=2.6.1) # Not used in codebase - was planned for network scanning but never implemented -zeroconf==0.132.2 +zeroconf==0.148.0 # Data Handling numpy==1.26.3 pandas==2.2.0 -h5py==3.10.0 +h5py==3.15.1 # Configuration -pydantic==2.5.3 -pydantic-settings==2.1.0 -python-dotenv==1.0.0 +pydantic==2.12.5 +pydantic-settings==2.12.0 +python-dotenv==1.2.1 # Utilities -python-dateutil==2.8.2 +python-dateutil==2.9.0.post0 qasync