Skip to content

Bump the pip group across 1 directory with 2 updates - #4

Open
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/pip/pip-c0303a9b52
Open

dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/pip/pip-c0303a9b52

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown

Bumps the pip group with 2 updates in the / directory: sqladmin and web3.

Updates sqladmin from 0.22.0 to 0.27.1

Release notes

Sourced from sqladmin's releases.

0.27.1

Security

ModelView.sort_query() did not check the attacker-controlled sortBy query parameter against the configured column_sortable_list allow-list, so a request could sort by any column of the model (including ones hidden from column_list) and by related-model columns via a dotted path — turning row order into an information-exposure ordering oracle. sortBy is now rejected with HTTP 400 unless it is present in the configured sortable columns.

Full Changelog: smithyhq/sqladmin@0.27.0...0.27.1

0.27.0

What's Changed

New Contributors

Full Changelog: smithyhq/sqladmin@0.26.0...0.27.0

0.26.0

What's Changed

Full Changelog: smithyhq/sqladmin@0.25.1...0.26.0

0.25.1

Verion 0.25.1 - 2026-05-16

Fixed

New Contributors

Full Changelog: smithyhq/sqladmin@0.25.0...0.25.1

... (truncated)

Changelog

Sourced from sqladmin's changelog.

Version 0.27.1: 2026-06-05

Security

  • Fix advisory GHSA-ccg5-9c8w-xh6v: restrict ModelView.sort_query() to the configured column_sortable_list allow-list (self._sort_fields) and reject invalid sortBy values with HTTP 400, preventing attacker-controlled ordering across arbitrary model and related-model columns and avoiding uncaught AttributeError (HTTP 500) by @​aminalaee.

Full Changelog: 0.27.0...0.27.1

Version 0.27.0: 2026-05-29

Added

Fixed

  • fix(list): fix the list view to limit the page width to viewport size by @​CHC383 in #1056
  • fix: forward kwargs to SessionMiddleware in AuthenticationBackend by @​vahidzhe in #1036
  • Fixed overriding form_args in forms.py and widgets.py by @​mmzeynalli in #1044

Docs

New Contributors

Full Changelog: 0.26.0...0.27.0

Version 0.26.0: 2025-05-16

Fixed

Full Changelog: 0.25.1...0.26.0

Version 0.25.1: 2026-05-16

Fixed

  • fix: authenticate ajax lookup endpoint by @​vahidzhe in #1035
  • fix: Authorization bypass on ajax_lookup

... (truncated)

Commits

Updates web3 from 7.14.0 to 7.15.0

Changelog

Sourced from web3's changelog.

web3.py v7.15.0 (2026-04-02)

Features


- Added configurations for CCIP-Read, defaulting to a more secure configuration based on the EIP recommendations. (`[#3818](https://github.com/ApeWorX/web3.py/issues/3818) <https://github.com/ethereum/web3.py/issues/3818>`__)

web3.py v7.14.1 (2026-02-03)

Bugfixes

  • Wrap timeout in ClientTimeout for AsyncBeacon post request ([#3784](https://github.com/ApeWorX/web3.py/issues/3784) <https://github.com/ethereum/web3.py/issues/3784>__)
  • Fix HTTPProvider to share an explicitly provided session across all threads, rather than only the creating thread. ([#3800](https://github.com/ApeWorX/web3.py/issues/3800) <https://github.com/ethereum/web3.py/issues/3800>__)
  • Fix TypedDict field names to use camelCase (validatorIndex, yParity) matching JSON-RPC conventions and formatter outputs. ([#3801](https://github.com/ApeWorX/web3.py/issues/3801) <https://github.com/ethereum/web3.py/issues/3801>__)
  • Exclude type checking in Sphinx module and submodules ([#3803](https://github.com/ApeWorX/web3.py/issues/3803) <https://github.com/ethereum/web3.py/issues/3803>__)

Improved Documentation


- Added documentation for formatters explaining how they work, what the default formatters do, and how to customize them. (`[#2994](https://github.com/ApeWorX/web3.py/issues/2994) <https://github.com/ethereum/web3.py/issues/2994>`__)

Internal Changes - for web3.py Contributors

  • Upgrade geth version in CI ([#3787](https://github.com/ApeWorX/web3.py/issues/3787) <https://github.com/ethereum/web3.py/issues/3787>__)
Commits
  • cf051a7 Bump version: 7.14.1 → 7.15.0
  • 10fe633 Compile release notes for v7.15.0
  • b45343d fix: linting related to backporting from main (py38 and py39)
  • fe17ccb update newsfragment for v7 PR
  • d2e5294 doc: add documentation for CCIP-Read updates
  • d62e67d feat: added restrictions on CCIP read durin calls
  • ea5e072 Bump version: 7.14.0 → 7.14.1
  • 8396964 Compile release notes for v7.14.1
  • 1864c89 minor nit for release notes
  • 555aec6 backport commits from main to v7 (#3809)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the pip group with 2 updates in the / directory: [sqladmin](https://github.com/smithyhq/sqladmin) and [web3](https://github.com/ApeWorX/web3.py).


Updates `sqladmin` from 0.22.0 to 0.27.1
- [Release notes](https://github.com/smithyhq/sqladmin/releases)
- [Changelog](https://github.com/smithyhq/sqladmin/blob/main/CHANGELOG.md)
- [Commits](smithyhq/sqladmin@0.22.0...0.27.1)

Updates `web3` from 7.14.0 to 7.15.0
- [Release notes](https://github.com/ApeWorX/web3.py/releases)
- [Changelog](https://github.com/ApeWorX/web3.py/blob/main/docs/release_notes.rst)
- [Commits](ApeWorX/web3.py@v7.14.0...v7.15.0)

---
updated-dependencies:
- dependency-name: sqladmin
  dependency-version: 0.27.1
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: web3
  dependency-version: 7.15.0
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants