From 68e409c7a1944b7a6db0fb08de48184ac39b86cf Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 25 Jun 2026 08:08:40 +0000 Subject: [PATCH] Bump the python-test-dependencies group in /tests with 2 updates Updates the requirements on [pytest](https://github.com/pytest-dev/pytest) and [requests](https://github.com/psf/requests) to permit the latest version. Updates `pytest` to 9.1.1 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](https://github.com/pytest-dev/pytest/compare/9.0.3...9.1.1) Updates `requests` to 2.34.2 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](https://github.com/psf/requests/compare/v2.33.0...v2.34.2) --- updated-dependencies: - dependency-name: pytest dependency-version: 9.1.1 dependency-type: direct:production dependency-group: python-test-dependencies - dependency-name: requests dependency-version: 2.34.2 dependency-type: direct:production dependency-group: python-test-dependencies ... Signed-off-by: dependabot[bot] --- tests/requirements.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/tests/requirements.txt b/tests/requirements.txt index 195e94fb..22db77e1 100644 --- a/tests/requirements.txt +++ b/tests/requirements.txt @@ -1,6 +1,6 @@ ## Used to run the tests: -pytest>=9.0.3 # CVE-2025-71176 (vulnerable <= 9.0.2) +pytest>=9.1.1 # CVE-2025-71176 (vulnerable <= 9.0.2) pytest-xdist pytest-cov pytest-timeout @@ -18,7 +18,7 @@ django flask gevent numpy -requests>=2.33.0 # CVE-2026-25645 (vulnerable < 2.33.0) +requests>=2.34.2 # CVE-2026-25645 (vulnerable < 2.33.0) # urllib3 is pulled in transitively by requests; pin a secure floor for # CVE-2026-44431 and CVE-2026-44432 (vulnerable 2.6.0 <= x < 2.7.0). urllib3>=2.7.0