Skip to content

[pull] main from openwallet-foundation:main - #216

Open
pull[bot] wants to merge 693 commits into
Indicio-tech:mainfrom
openwallet-foundation:main
Open

[pull] main from openwallet-foundation:main#216
pull[bot] wants to merge 693 commits into
Indicio-tech:mainfrom
openwallet-foundation:main

Conversation

@pull

@pull pull Bot commented May 1, 2025

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.1)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot added the ⤵️ pull label May 1, 2025
swcurran and others added 29 commits March 20, 2026 13:18
chore: add PR template and issue templates
Bumps [pytest-cov](https://github.com/pytest-dev/pytest-cov) from 7.0.0 to 7.1.0.
- [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-cov@v7.0.0...v7.1.0)

---
updated-dependencies:
- dependency-name: pytest-cov
  dependency-version: 7.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…test-cov-7.1.0

chore(deps-dev): Bump pytest-cov from 7.0.0 to 7.1.0
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Bumps the all-actions group with 4 updates: [octokit/request-action](https://github.com/octokit/request-action), [github/codeql-action](https://github.com/github/codeql-action), [actions/cache](https://github.com/actions/cache) and [dawidd6/action-download-artifact](https://github.com/dawidd6/action-download-artifact).


Updates `octokit/request-action` from 05a2312de9f8207044c4c9e41fe19703986acc13 to fceefc326610e57c85d863dd44ac27fbd90f25e3
- [Release notes](https://github.com/octokit/request-action/releases)
- [Commits](octokit/request-action@05a2312...fceefc3)

Updates `github/codeql-action` from 4.33.0 to 4.34.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@b1bff81...3869755)

Updates `actions/cache` from 5.0.3 to 5.0.4
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@cdf6c1f...6682284)

Updates `dawidd6/action-download-artifact` from 18 to 19
- [Release notes](https://github.com/dawidd6/action-download-artifact/releases)
- [Commits](dawidd6/action-download-artifact@1f8785f...8a33849)

---
updated-dependencies:
- dependency-name: octokit/request-action
  dependency-version: fceefc326610e57c85d863dd44ac27fbd90f25e3
  dependency-type: direct:production
  dependency-group: all-actions
- dependency-name: github/codeql-action
  dependency-version: 4.34.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
- dependency-name: actions/cache
  dependency-version: 5.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-actions
- dependency-name: dawidd6/action-download-artifact
  dependency-version: '19'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
…_actions/all-actions-3e06e99b0f

chore(deps): Bump the all-actions group with 4 updates
…4102)

Bumps the pip group with 1 update in the / directory: [requests](https://github.com/psf/requests).
Bumps the pip group with 1 update in the /scenarios directory: [requests](https://github.com/psf/requests).
Bumps the pip group with 1 update in the /demo/playground/examples directory: [requests](https://github.com/psf/requests).


Updates `requests` from 2.32.5 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.0)

Updates `requests` from 2.32.4 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.0)

Updates `requests` from 2.32.4 to 2.33.0
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: indirect
  dependency-group: pip
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Updates the requirements on [pygments](https://github.com/pygments/pygments) to permit the latest version.
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.19.0...2.20.0)

---
updated-dependencies:
- dependency-name: pygments
  dependency-version: 2.20.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…mo/pygments-approx-eq-2.20

chore(deps): Update pygments requirement from ~=2.19 to ~=2.20 in /demo
Bumps [pygments](https://github.com/pygments/pygments) from 2.19.2 to 2.20.0.
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.19.2...2.20.0)

---
updated-dependencies:
- dependency-name: pygments
  dependency-version: 2.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…4103)

Bumps the pip group with 1 update in the / directory: [cryptography](https://github.com/pyca/cryptography).


Updates `cryptography` from 46.0.5 to 46.0.6
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.5...46.0.6)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.6
  dependency-type: indirect
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jamshale <31809382+jamshale@users.noreply.github.com>
Bumps the all-actions group with 2 updates: [octokit/request-action](https://github.com/octokit/request-action) and [github/codeql-action](https://github.com/github/codeql-action).


Updates `octokit/request-action` from fceefc326610e57c85d863dd44ac27fbd90f25e3 to 10df4beff76ddd0c48b0e983ecde429e7174dfd3
- [Release notes](https://github.com/octokit/request-action/releases)
- [Commits](octokit/request-action@fceefc3...10df4be)

Updates `github/codeql-action` from 4.34.1 to 4.35.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@3869755...c10b806)

---
updated-dependencies:
- dependency-name: octokit/request-action
  dependency-version: 10df4beff76ddd0c48b0e983ecde429e7174dfd3
  dependency-type: direct:production
  dependency-group: all-actions
- dependency-name: github/codeql-action
  dependency-version: 4.35.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
…_actions/all-actions-8da5401910

chore(deps): Bump the all-actions group with 2 updates
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Bumps [pyld](https://github.com/digitalbazaar/pyld) from 2.0.4 to 3.0.0.
- [Changelog](https://github.com/digitalbazaar/pyld/blob/master/CHANGELOG.md)
- [Commits](digitalbazaar/pyld@v2.0.4...v3.0.0)

---
updated-dependencies:
- dependency-name: pyld
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…ld-3.0.0

chore(deps): Bump pyld from 2.0.4 to 3.0.0
Bumps [pydevd](https://github.com/fabioz/PyDev.Debugger) from 3.4.1 to 3.5.0.
- [Commits](https://github.com/fabioz/PyDev.Debugger/commits)

---
updated-dependencies:
- dependency-name: pydevd
  dependency-version: 3.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…4110)

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.13.4
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: aiohttp
  dependency-version: 3.13.4
  dependency-type: indirect
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the all-actions group with 3 updates: [docker/login-action](https://github.com/docker/login-action), [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) and [dawidd6/action-download-artifact](https://github.com/dawidd6/action-download-artifact).


Updates `docker/login-action` from 4.0.0 to 4.1.0
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@b45d80f...4907a6d)

Updates `SonarSource/sonarqube-scan-action` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](SonarSource/sonarqube-scan-action@a31c939...299e4b7)

Updates `dawidd6/action-download-artifact` from 19 to 20
- [Release notes](https://github.com/dawidd6/action-download-artifact/releases)
- [Commits](dawidd6/action-download-artifact@8a33849...8305c0f)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
- dependency-name: dawidd6/action-download-artifact
  dependency-version: '20'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
)

Bumps the pip group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography) and [jwcrypto](https://github.com/latchset/jwcrypto).


Updates `cryptography` from 46.0.6 to 46.0.7
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.6...46.0.7)

Updates `jwcrypto` from 1.5.6 to 1.5.7
- [Release notes](https://github.com/latchset/jwcrypto/releases)
- [Commits](latchset/jwcrypto@v1.5.6...v1.5.7)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: indirect
  dependency-group: pip
- dependency-name: jwcrypto
  dependency-version: 1.5.7
  dependency-type: indirect
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pydantic](https://github.com/pydantic/pydantic) from 2.12.2 to 2.13.0.
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](pydantic/pydantic@v2.12.2...v2.13.0)

---
updated-dependencies:
- dependency-name: pydantic
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…enarios/pydantic-2.13.0

chore(deps): Bump pydantic from 2.12.2 to 2.13.0 in /scenarios
swcurran and others added 30 commits September 1, 2026 11:32
…epmerge-3.0

chore(deps): Bump deepmerge from 2.1.0 to 3.0
Bumps [rlp](https://github.com/ApeWorX/pyrlp) from 4.1.0 to 5.0.0.
- [Release notes](https://github.com/ApeWorX/pyrlp/releases)
- [Changelog](https://github.com/ApeWorX/pyrlp/blob/main/docs/release_notes.rst)
- [Commits](ApeWorX/pyrlp@v4.1.0...v5.0.0)

---
updated-dependencies:
- dependency-name: rlp
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…_actions/all-actions-64c8a27a46

chore(deps): Bump the all-actions group with 3 updates
DIF field paths were parsed with the base jsonpath_ng grammar, which
covers only 9 of the 14 example expressions in the DIF Presentation
Exchange spec's own JSONPath syntax table -- filter expressions
([?(...)]) are a jsonpath_ng.ext-only feature and were unsupported.

Switch pres_exch_handler.py to jsonpath_ng.ext.parse to support filter
expressions (existence, numeric comparison, exact-match, and single-&
compound conditions). No new dependency: jsonpath-ng already ships the
ext module under the pin already in pyproject.toml.

Enabling jsonpath_ng.ext also enables its function-extension surface
(sub, str, sorted, search, match) and a regex-match operator (=~).
Presentation requests are only authenticated at the DIDComm connection
level -- nothing validates the content of a presentation_definition
once received, so an untrusted party who has an active connection
could send a request containing one of these to run logic well beyond
a plain data query, or a malformed expression that raises an unhandled
parser error partway through building a presentation.

Add a whitelist validator (jsonpath_guard.is_safe_jsonpath) wired into
DIFFieldSchema.paths, so every DIFField.paths entry is checked against
a fixed, narrow grammar at deserialization time -- before matching or
presentation-building ever runs. Supports child/wildcard access,
recursive descent, index/slice/union subscripts, the length-relative
script subscript, and filter expressions limited to bare-existence or
single-comparison conditions optionally joined by one &. Anything
outside that grammar is rejected, whether malicious or merely
unsupported syntax (e.g. && instead of &), consistent with the DIF
spec's own Security Considerations guidance to avoid JSONPath's
regular-expression and function-extension features where a direct
alternative exists.

Verified against every JSONPath expression already used across this
package's existing test suite (69 distinct expressions) -- none are
rejected by the new validator.

Signed-off-by: nb-pratik-bhimani <pratik@northernblock.io>
…support-with-safety-guard-main

feat: full JSONPath support via jsonpath_ng.ext with a safety guard
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Bumps the pip group with 1 update in the / directory: [mkdocs-material](https://github.com/squidfunk/mkdocs-material).


Updates `mkdocs-material` from 9.7.0 to 9.7.7
- [Release notes](https://github.com/squidfunk/mkdocs-material/releases)
- [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG)
- [Commits](squidfunk/mkdocs-material@9.7.0...9.7.7)

---
updated-dependencies:
- dependency-name: mkdocs-material
  dependency-version: 9.7.7
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
…p-55c7a475ee

chore(deps): Bump mkdocs-material from 9.7.0 to 9.7.7 in the pip group across 1 directory
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Jackson Riding <jackson.riding@gmail.com>
Bumps [pyld](https://github.com/digitalbazaar/pyld) from 3.2.0 to 3.3.0.
- [Release notes](https://github.com/digitalbazaar/pyld/releases)
- [Changelog](https://github.com/digitalbazaar/pyld/blob/master/CHANGELOG.md)
- [Commits](digitalbazaar/pyld@v3.2.0...v3.3.0)

---
updated-dependencies:
- dependency-name: pyld
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…ld-3.3.0

chore(deps): Bump pyld from 3.2.0 to 3.3.0
Fix DIF holder presentation signing for did:key
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Bumps the pip group with 1 update in the /scenarios directory: [pygments](https://github.com/pygments/pygments).
Bumps the pip group with 1 update in the /demo/playground/examples directory: [pygments](https://github.com/pygments/pygments).
Bumps the pip group with 1 update in the / directory: [pynacl](https://github.com/pyca/pynacl).


Updates `pygments` from 2.19.1 to 2.20.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.19.1...2.20.0)

Updates `pygments` from 2.19.1 to 2.20.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.19.1...2.20.0)

Updates `pynacl` from 1.6.0 to 1.6.2
- [Changelog](https://github.com/pyca/pynacl/blob/main/CHANGELOG.rst)
- [Commits](pyca/pynacl@1.6.0...1.6.2)

---
updated-dependencies:
- dependency-name: pygments
  dependency-version: 2.20.0
  dependency-type: indirect
  dependency-group: pip
- dependency-name: pygments
  dependency-version: 2.20.0
  dependency-type: indirect
  dependency-group: pip
- dependency-name: pynacl
  dependency-version: 1.6.2
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
…enarios/pip-919003f0cc

chore(deps): Bump the pip group across 3 directories with 2 updates
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.