Skip to content

Update dependency pydantic to v1.10.13 [SECURITY]#77

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pydantic-vulnerability
Open

Update dependency pydantic to v1.10.13 [SECURITY]#77
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-pydantic-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Apr 25, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
pydantic (changelog) 1.10.111.10.13 age confidence
pydantic (changelog) ==1.10.9==1.10.13 age confidence

Pydantic regular expression denial of service

CVE-2024-3772 / GHSA-mr82-8j83-vxmv

More information

Details

Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pydantic/pydantic (pydantic)

v1.10.13

Compare Source

v1.10.12

Compare Source

  • Fixes the maxlen property being dropped on deque validation. Happened only if the deque item has been typed. Changes the _validate_sequence_like func, #​6581 by @​maciekglowka

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from 559ef04 to 389f8a4 Compare August 6, 2024 08:18
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from 389f8a4 to 4f7ba2a Compare August 17, 2024 02:15
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from 4f7ba2a to 944a5ad Compare August 28, 2024 08:35
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch 3 times, most recently from 18f1d1e to eedbadb Compare November 3, 2024 14:08
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from eedbadb to d593e73 Compare January 14, 2025 13:42
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from d593e73 to 72d0411 Compare January 30, 2025 19:18
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from 72d0411 to 7db210e Compare March 3, 2025 17:59
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch 2 times, most recently from d9ff61d to d8033d3 Compare March 17, 2025 18:35
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from d8033d3 to bd40ed3 Compare April 8, 2025 14:44
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from bd40ed3 to 753877c Compare May 7, 2025 14:10
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed May 22, 2025
@renovate renovate Bot closed this May 22, 2025
@renovate renovate Bot deleted the renovate/pypi-pydantic-vulnerability branch May 22, 2025 04:07
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Update dependency pydantic to v1.10.13 [SECURITY] May 22, 2025
@renovate renovate Bot reopened this May 22, 2025
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch 2 times, most recently from 753877c to 09aaf57 Compare May 22, 2025 13:23
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Jul 28, 2025
@renovate renovate Bot closed this Jul 28, 2025
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Update dependency pydantic to v1.10.13 [SECURITY] Jul 28, 2025
@renovate renovate Bot reopened this Jul 28, 2025
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch 2 times, most recently from 09aaf57 to 241b735 Compare July 28, 2025 20:10
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from 241b735 to 937ad02 Compare August 10, 2025 14:25
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch from 937ad02 to 0d495bb Compare November 18, 2025 11:59
@renovate

renovate Bot commented Nov 18, 2025

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: poetry.lock
Updating dependencies
Resolving dependencies...

The "poetry.dev-dependencies" section is deprecated and will be removed in a future version. Use "poetry.group.dev.dependencies" instead.
Creating virtualenv ainewstracker-zSIvkN61-py3.14 in /home/ubuntu/.cache/pypoetry/virtualenvs

Package pandas-ta (0.3.14b0) not found.

@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Apr 9, 2026
@renovate renovate Bot closed this Apr 9, 2026
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Update dependency pydantic to v1.10.13 [SECURITY] Apr 9, 2026
@renovate renovate Bot reopened this Apr 9, 2026
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch 2 times, most recently from 0d495bb to 81c7b5b Compare April 9, 2026 10:56
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Update dependency pydantic to v1.10.13 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch 2 times, most recently from 81c7b5b to e247518 Compare April 27, 2026 20:57
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed May 18, 2026
@renovate renovate Bot closed this May 18, 2026
@renovate renovate Bot changed the title Update dependency pydantic to v1.10.13 [SECURITY] - autoclosed Update dependency pydantic to v1.10.13 [SECURITY] May 19, 2026
@renovate renovate Bot reopened this May 19, 2026
@renovate renovate Bot force-pushed the renovate/pypi-pydantic-vulnerability branch 2 times, most recently from e247518 to 3cb7e21 Compare May 19, 2026 00:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants