Skip to content

ytm: bump the all-packages group across 1 directory with 2 updates#172

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/ytm/master/all-packages-6b99584873
Open

ytm: bump the all-packages group across 1 directory with 2 updates#172
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/ytm/master/all-packages-6b99584873

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 13, 2026

Bumps the all-packages group with 2 updates in the /ytm directory: ytmusicapi and idna.

Updates ytmusicapi from 1.11.5 to 1.12.0

Release notes

Sourced from ytmusicapi's releases.

v1.12.0

✨ Features

🐞 Fixes

📖 Docs

New Contributors

Full Changelog: sigma67/ytmusicapi@1.11.5...1.12.0

Commits
  • 878d0b6 get_song_credits: normalize section keys across locales (#914)
  • cdbe6c1 feat - add support for votes in edit playlist (#913)
  • b79d799 pytest: show durations for test cases (#918)
  • 001f644 Fixing branch name in readme links (#915)
  • 29eda05 get_playlist: support continuations for playlists sorted by "Top voted" (#909)
  • 86bcd5d feat - add playlist community vote to get_playlist (#896)
  • 676fe40 fix: album year parsing in .get_artist (#899) (#910)
  • 416b5d9 feature: add get_song_credits (#883) (#884)
  • 1aa15cd Handle albums without subtitle metadata (#907)
  • 279e10c edit_playlist: support collaboration (#879)
  • Additional commits viewable in compare view

Updates idna from 3.13 to 3.14

Changelog

Sourced from idna's changelog.

3.14 (2026-05-10)

  • Removed opportunity to process long inputs into quadratic time by rejecting oversize inputs up-front. Closes a bypass of the CVE-2024-3651 mitigation. [CVE-2026-45409]

Thanks to Stan Ulbrych for reporting the issue.

Commits

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
ytmusicapi [>= 1.8.2.dev0, < 1.8.3]

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 13, 2026
Bumps the all-packages group with 2 updates in the /ytm directory: [ytmusicapi](https://github.com/sigma67/ytmusicapi) and [idna](https://github.com/kjd/idna).


Updates `ytmusicapi` from 1.11.5 to 1.12.0
- [Release notes](https://github.com/sigma67/ytmusicapi/releases)
- [Commits](sigma67/ytmusicapi@1.11.5...1.12.0)

Updates `idna` from 3.13 to 3.14
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.13...v3.14)

---
updated-dependencies:
- dependency-name: idna
  dependency-version: '3.14'
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: all-packages
- dependency-name: ytmusicapi
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-packages
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/pip/ytm/master/all-packages-6b99584873 branch from 3aa35d3 to 2dfdb0a Compare May 13, 2026 12:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants