Skip to content

Bump modelaudit from 0.2.42 to 0.2.52 in /services/quarantine - #92

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/services/quarantine/modelaudit-0.2.52
Open

Bump modelaudit from 0.2.42 to 0.2.52 in /services/quarantine#92
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/services/quarantine/modelaudit-0.2.52

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps modelaudit from 0.2.42 to 0.2.52.

Changelog

Sourced from modelaudit's changelog.

0.2.52 (2026-07-22)

Bug Fixes

0.2.51 (2026-07-20)

Bug Fixes

  • recover root release build and PyPI smoke gates (#1764) (fa350d9)

0.2.50 (2026-07-20)

Security

  • validate Windows MLflow staging hardlinks with native file identities so aliases outside the staging tree fail closed
  • treat protocol-relative report sources as remote identifiers before any Windows UNC filesystem probe
  • reject premature pickle STOP opcodes inside Joblib NumPy wrapper streams and fail closed when wrapper validation cannot complete

Bug Fixes

  • cache: reuse stat without breaking public overrides (#1732) (39cd664)
  • cli: handle startup interrupts gracefully (#1723) (839c7cf)
  • deep-merge partial auth config updates (#1721) (8f33995)
  • deps: update PyTorch to 2.13.0 for CVE-2025-3000; PyTorch-containing extras now require macOS 14 or newer on Apple Silicon and standard (GIL-enabled) CPython 3.13 or Python 3.10-3.12; CPython 3.13t is unsupported, while core-only remains available on macOS 11-13
  • deps: require Click 8.3.3 or newer to address PYSEC-2026-2132
  • deps: require modelaudit-picklescan>=0.1.9 so root upgrades receive the released scanner fixes
  • deps: update NumPy to 2.5 on Python 3.12+ while retaining NumPy 2.4 on Python 3.11, matching NumPy's supported Python versions (#1706) (eeba9b8)
  • hashing: adapt reads near scan deadlines (#1734) (f23e1c0)
  • picklescan: preserve POSIX ctime checks (#1719) (cbde525)
  • picklescan: resolve reviewed runtime hasattr guards without losing call-graph sinks
  • picklescan: restore standalone CI (#1742) (88632fe)
  • restore cross-platform nightly CI safety (#1704) (9df81da)

0.2.49 (2026-06-25)

Bug Fixes

  • picklescan: restore Windows call-graph detection via cross-view stat identity (#1715) (51c0074)

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jul 24, 2026
Bumps [modelaudit](https://github.com/promptfoo/modelaudit) from 0.2.42 to 0.2.52.
- [Release notes](https://github.com/promptfoo/modelaudit/releases)
- [Changelog](https://github.com/promptfoo/modelaudit/blob/main/CHANGELOG.md)
- [Commits](promptfoo/modelaudit@v0.2.42...v0.2.52)

---
updated-dependencies:
- dependency-name: modelaudit
  dependency-version: 0.2.52
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/services/quarantine/modelaudit-0.2.52 branch from dc230bc to 35bce7c Compare July 28, 2026 22:37
@dependabot
dependabot Bot requested a review from SecAI-Hub as a code owner July 28, 2026 22:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants