Update google-auth requirement from >=2.52.0 to >=2.53.0 in /src #32
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#32
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "dependabot/pip/src/google-auth-gte-2.53.0"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Updates the requirements on google-auth to permit the latest version.
Changelog
Sourced from google-auth's changelog.
... (truncated)
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)LGTM, minor version bump on google-auth dependency floor.
Extended reasoning...
Overview
This PR is an automated Dependabot update that bumps the minimum required version of
google-authfrom>=2.52.0to>=2.53.0insrc/requirements.txt. It is a single-line change to a dependency floor.Security risks
None substantive. The change raises the minimum allowed version, which generally pulls in security and bug fixes from upstream. The package is a well-known Google-maintained authentication library, and this is a minor version bump.
Level of scrutiny
Low. Dependency floor bumps of this magnitude are mechanical and well within the scope of automated approval. The bug hunting system found no issues.
Other factors
No prior reviews or outstanding comments on the PR timeline. The change is consistent with the recent pattern of Dependabot bumps in this repository (see recent commits).