Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Sep 3, 2025

Bumps safety from 2.3.5 to 3.6.1.

Release notes

Sourced from safety's releases.

Version 3.6.1

What's Changed

  • bump: version 3.6.1b0 → 3.6.1 (f5e7262)
  • fix: Import rich_utils as a module and don't access as an attribute. (#780) (b0ea9c3)
  • docs: update min Python version required (#777) (42282d4)

Version 3.6.1b0

What's Changed

  • bump: version 3.6.0 → 3.6.1b0 (d50c580)
  • chore: relax psutil version constraints (#776) (a66193e)
  • chore: relax filelock version constraints (#775) (926c93f)
  • ci: introduce click main branch as a target to improve early integration (#752) (d87aa74)
  • fix: set custom user-agent header to all HTTP requests (#769) (4f09253)

Version 3.6.0

What's Changed

  • bump: version 3.6.0b0 → 3.6.0 (af75197)
  • chore: prepare for stable release (2f7df72)

Version 3.6.0b0

What's Changed

  • bump: version 3.5.2 → 3.6.0b0 (dd6c81b)
  • fix: issues with encoding in all the outputs (#757) (293bccb)
  • fix: restore missing codebase name prompt in scan command (#771) (0abd016)
  • fix: issues with click 8.2.0 (#748) (d5be19c)
  • fix: codebase init --link-to help text (#770) (99971f8)
  • feat: add Windows venv wrappers support (#768) (0a3d05a)
  • feat: add codebase init command (#756) (bd1fade)
  • test: use tomllib in tests if available (#765) (f1e3d4d)
  • fix: test isolation for firewall tests on unix-like systems (#767) (362f6e0)

Version 3.5.2

What's Changed

  • bump: version 3.5.2b1 → 3.5.2 (03e057b)
  • fix: resolve logger warnings (#761) (4cbb766)

Version 3.5.2b1

What's Changed

  • bump: version 3.5.2b0 → 3.5.2b1 (e89c965)
  • ci: use a newer windows runner image (#760) (35bc33f)

Version 3.5.1

What's Changed

  • bump: version 3.5.1b0 → 3.5.1 (9dc9ac3)
  • chore: update CHANGELOG.md with note (#753) (a01f411)

Version 3.5.1b0

What's Changed

  • bump: version 3.5.0 → 3.5.1b0 (7eadf12)
  • fix: add missing uv index env var for auth (#751) (1136c27)

... (truncated)

Changelog

Sourced from safety's changelog.

3.6.1 (2025-09-01)

Fix

  • Import rich_utils as a module and don't access as an attribute. (#780)

3.6.1b0 (2025-08-25)

Fix

  • set custom user-agent header to all HTTP requests (#769)

3.6.0 (2025-07-09)

3.6.0b0 (2025-07-09)

Feat

  • add Windows venv wrappers support (#768)
  • add codebase init command (#756)

Fix

  • issues with encoding in all the outputs (#757)
  • restore missing codebase name prompt in scan command (#771)
  • issues with click 8.2.0 (#748)
  • codebase init --link-to help text (#770)
  • test isolation for firewall tests on unix-like systems (#767)

3.5.2 (2025-06-04)

Fix

  • resolve logger warnings (#761)

3.5.2b1 (2025-06-03)

3.5.2b0 (2025-06-03)

Fix

  • encoding issues when reading user UTF-16 and UTF-8-SIG encoded files (#759)
  • include missing warn for Poetry (#758)
  • missing poetry index credentials (#754)

3.5.1 (2025-05-14)

3.5.1b0 (2025-05-13)

Fix

... (truncated)

Commits
  • f5e7262 bump: version 3.6.1b0 → 3.6.1
  • b0ea9c3 fix: Import rich_utils as a module and don't access as an attribute. (#780)
  • 42282d4 docs: update min Python version required (#777)
  • d50c580 bump: version 3.6.0 → 3.6.1b0
  • a66193e chore: relax psutil version constraints (#776)
  • 926c93f chore: relax filelock version constraints (#775)
  • d87aa74 ci: introduce click main branch as a target to improve early integration (#752)
  • 4f09253 fix: set custom user-agent header to all HTTP requests (#769)
  • af75197 bump: version 3.6.0b0 → 3.6.0
  • 2f7df72 chore: prepare for stable release
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [safety](https://github.com/pyupio/safety) from 2.3.5 to 3.6.1.
- [Release notes](https://github.com/pyupio/safety/releases)
- [Changelog](https://github.com/pyupio/safety/blob/main/CHANGELOG.md)
- [Commits](pyupio/safety@2.3.5...3.6.1)

---
updated-dependencies:
- dependency-name: safety
  dependency-version: 3.6.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 3, 2025
@coderabbitai
Copy link
Contributor

coderabbitai bot commented Sep 3, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

Support

Need help? Join our Discord community for assistance with any issues or questions.

CodeRabbit Commands (Invoked using PR/Issue comments)

Type @coderabbitai help to get the list of available commands.

Other keywords and placeholders

  • Add @coderabbitai ignore or @coderabbit ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Status, Documentation and Community

  • Visit our Status Page to check the current availability of CodeRabbit.
  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Sep 24, 2025

Superseded by #403.

@dependabot dependabot bot closed this Sep 24, 2025
@dependabot dependabot bot deleted the dependabot/pip/safety-3.6.1 branch September 24, 2025 21:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant