build(deps): update pyyaml requirement from <7,>=6.0 to >=6.0.3,<7 - #209
build(deps): update pyyaml requirement from <7,>=6.0 to >=6.0.3,<7#209dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [pyyaml](https://github.com/yaml/pyyaml) to permit the latest version. - [Release notes](https://github.com/yaml/pyyaml/releases) - [Changelog](https://github.com/yaml/pyyaml/blob/6.0.3/CHANGES) - [Commits](yaml/pyyaml@6.0...6.0.3) --- updated-dependencies: - dependency-name: pyyaml dependency-version: 6.0.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
268f7e3 to
5ddbda0
Compare
|
Declining this one — not superseded. The floor stays at Checked against GitHub's advisory database before deciding: no advisory touches PyYAML above 5.4, and this project's floor is already 6.0. So the raise fixes nothing here. That matters because it isn't free. Nothing is wrong with the proposal — Sibling proposals #208, #211 and #212 were taken and shipped in #221 — #211 was the one that mattered, clearing a HIGH and a MODERATE advisory in Reopen if an advisory later lands in the allowed range. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Updates the requirements on pyyaml to permit the latest version.
Release notes
Sourced from pyyaml's releases.
Changelog
Sourced from pyyaml's changelog.
... (truncated)
Commits
49790e7Release 6.0.3 (#889)41309b0Release 6.0.2 (#819)dd9f0e16.0.2rc1 (#809)f5527a2disable CI trigger on PR editsb4d80a7Python 3.12 + musllinux_1_1_x86_64 wheel supportc42fa3b6.0.1 releaseae08bdcblock Cython 3.0+ as a build dep (#702)f873cfeAdd python 3.11 support (#663)