Skip to content

chore(deps): lock file maintenance - #611

Merged
n24q02m merged 1 commit into
mainfrom
renovate/lock-file-maintenance
May 22, 2026
Merged

chore(deps): lock file maintenance#611
n24q02m merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@renovate

@renovate renovate Bot commented May 19, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone Asia/Ho_Chi_Minh)

  • Branch creation
    • "before 5am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from n24q02m as a code owner May 19, 2026 18:08
@github-actions

github-actions Bot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 9 package(s) with unknown licenses.
See the Details below.

License Issues

uv.lock

PackageVersionLicenseIssue Type
click8.4.0NullUnknown License
filelock3.29.0NullUnknown License
fsspec2026.4.0NullUnknown License
hf-xet1.5.0NullUnknown License
idna3.16NullUnknown License
onnxruntime1.26.0NullUnknown License
protobuf7.35.0NullUnknown License
typer0.25.1NullUnknown License
certifi2026.5.20NullUnknown License

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
pip/anyio 4.13.0 UnknownUnknown
pip/certifi 2026.5.20 🟢 6.4
Details
CheckScoreReason
Code-Review🟢 5Found 1/2 approved changesets -- score normalized to 5
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 88 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 8
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
License🟢 9license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Packaging🟢 10packaging workflow detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
pip/charset-normalizer 3.4.7 UnknownUnknown
pip/click 8.4.0 UnknownUnknown
pip/coverage 7.14.0 UnknownUnknown
pip/filelock 3.29.0 UnknownUnknown
pip/fsspec 2026.4.0 UnknownUnknown
pip/hf-xet 1.5.0 UnknownUnknown
pip/idna 3.16 UnknownUnknown
pip/markdown-it-py 4.2.0 UnknownUnknown
pip/onnxruntime 1.26.0 UnknownUnknown
pip/packaging 26.2 UnknownUnknown
pip/protobuf 7.35.0 UnknownUnknown
pip/pygments 2.20.0 UnknownUnknown
pip/rich 15.0.0 UnknownUnknown
pip/tomli 2.4.1 UnknownUnknown
pip/typer 0.25.1 UnknownUnknown
pip/urllib3 2.7.0 UnknownUnknown

Scanned Files

  • uv.lock

@socket-security

socket-security Bot commented May 19, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedonnxruntime@​1.24.4 ⏵ 1.26.074 +110010010070

View full report

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from d78f74a to 8ad8b1d Compare May 22, 2026 03:12
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Potentially malicious package (AI signal): pypi pygments is 80.0% likely malicious

Notes: This dependency fragment is security-unsafe: it contains multiple high-impact capabilities including dynamic eval-based code execution, OS command execution (backticks/IO.popen), sensitive local file disclosure (/etc/passwd and dictionary file processing), environment variable printing (possible secret leakage), and direct process termination driven by user-supplied PID. Unless the surrounding package guarantees these paths are never executed in production (e.g., test-only, unreachable, or removed), it should be treated as maliciously capable and rejected or tightly sandboxed.

Confidence: 0.80

Severity: 0.95

From: uv.lockpypi/pytest@9.0.3pypi/huggingface-hub@1.16.1pypi/pygments@2.20.0

ℹ Read more on: This package | This alert | What is AI-detected potential malware?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Given the AI system's identification of this package as malware, extreme caution is advised. It is recommended to avoid downloading or installing this package until the threat is confirmed or flagged as a false positive.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/pygments@2.20.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@n24q02m
n24q02m merged commit 9977e93 into main May 22, 2026
24 checks passed
@n24q02m
n24q02m deleted the renovate/lock-file-maintenance branch May 22, 2026 07:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant