[pull] main from openwallet-foundation:main - #216
Open
pull[bot] wants to merge 693 commits into
Open
Conversation
chore: add PR template and issue templates
Bumps [pytest-cov](https://github.com/pytest-dev/pytest-cov) from 7.0.0 to 7.1.0. - [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst) - [Commits](pytest-dev/pytest-cov@v7.0.0...v7.1.0) --- updated-dependencies: - dependency-name: pytest-cov dependency-version: 7.1.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…test-cov-7.1.0 chore(deps-dev): Bump pytest-cov from 7.0.0 to 7.1.0
Bumps the all-actions group with 4 updates: [octokit/request-action](https://github.com/octokit/request-action), [github/codeql-action](https://github.com/github/codeql-action), [actions/cache](https://github.com/actions/cache) and [dawidd6/action-download-artifact](https://github.com/dawidd6/action-download-artifact). Updates `octokit/request-action` from 05a2312de9f8207044c4c9e41fe19703986acc13 to fceefc326610e57c85d863dd44ac27fbd90f25e3 - [Release notes](https://github.com/octokit/request-action/releases) - [Commits](octokit/request-action@05a2312...fceefc3) Updates `github/codeql-action` from 4.33.0 to 4.34.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b1bff81...3869755) Updates `actions/cache` from 5.0.3 to 5.0.4 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@cdf6c1f...6682284) Updates `dawidd6/action-download-artifact` from 18 to 19 - [Release notes](https://github.com/dawidd6/action-download-artifact/releases) - [Commits](dawidd6/action-download-artifact@1f8785f...8a33849) --- updated-dependencies: - dependency-name: octokit/request-action dependency-version: fceefc326610e57c85d863dd44ac27fbd90f25e3 dependency-type: direct:production dependency-group: all-actions - dependency-name: github/codeql-action dependency-version: 4.34.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: actions/cache dependency-version: 5.0.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-actions - dependency-name: dawidd6/action-download-artifact dependency-version: '19' dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-actions ... Signed-off-by: dependabot[bot] <support@github.com>
…_actions/all-actions-3e06e99b0f chore(deps): Bump the all-actions group with 4 updates
…4102) Bumps the pip group with 1 update in the / directory: [requests](https://github.com/psf/requests). Bumps the pip group with 1 update in the /scenarios directory: [requests](https://github.com/psf/requests). Bumps the pip group with 1 update in the /demo/playground/examples directory: [requests](https://github.com/psf/requests). Updates `requests` from 2.32.5 to 2.33.0 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.5...v2.33.0) Updates `requests` from 2.32.4 to 2.33.0 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.5...v2.33.0) Updates `requests` from 2.32.4 to 2.33.0 - [Release notes](https://github.com/psf/requests/releases) - [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md) - [Commits](psf/requests@v2.32.5...v2.33.0) --- updated-dependencies: - dependency-name: requests dependency-version: 2.33.0 dependency-type: direct:production dependency-group: pip - dependency-name: requests dependency-version: 2.33.0 dependency-type: indirect dependency-group: pip - dependency-name: requests dependency-version: 2.33.0 dependency-type: direct:production dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Updates the requirements on [pygments](https://github.com/pygments/pygments) to permit the latest version. - [Release notes](https://github.com/pygments/pygments/releases) - [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES) - [Commits](pygments/pygments@2.19.0...2.20.0) --- updated-dependencies: - dependency-name: pygments dependency-version: 2.20.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…mo/pygments-approx-eq-2.20 chore(deps): Update pygments requirement from ~=2.19 to ~=2.20 in /demo
Bumps [pygments](https://github.com/pygments/pygments) from 2.19.2 to 2.20.0. - [Release notes](https://github.com/pygments/pygments/releases) - [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES) - [Commits](pygments/pygments@2.19.2...2.20.0) --- updated-dependencies: - dependency-name: pygments dependency-version: 2.20.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…4103) Bumps the pip group with 1 update in the / directory: [cryptography](https://github.com/pyca/cryptography). Updates `cryptography` from 46.0.5 to 46.0.6 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.5...46.0.6) --- updated-dependencies: - dependency-name: cryptography dependency-version: 46.0.6 dependency-type: indirect dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: jamshale <31809382+jamshale@users.noreply.github.com>
Bumps the all-actions group with 2 updates: [octokit/request-action](https://github.com/octokit/request-action) and [github/codeql-action](https://github.com/github/codeql-action). Updates `octokit/request-action` from fceefc326610e57c85d863dd44ac27fbd90f25e3 to 10df4beff76ddd0c48b0e983ecde429e7174dfd3 - [Release notes](https://github.com/octokit/request-action/releases) - [Commits](octokit/request-action@fceefc3...10df4be) Updates `github/codeql-action` from 4.34.1 to 4.35.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@3869755...c10b806) --- updated-dependencies: - dependency-name: octokit/request-action dependency-version: 10df4beff76ddd0c48b0e983ecde429e7174dfd3 dependency-type: direct:production dependency-group: all-actions - dependency-name: github/codeql-action dependency-version: 4.35.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions ... Signed-off-by: dependabot[bot] <support@github.com>
…_actions/all-actions-8da5401910 chore(deps): Bump the all-actions group with 2 updates
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Bumps [pyld](https://github.com/digitalbazaar/pyld) from 2.0.4 to 3.0.0. - [Changelog](https://github.com/digitalbazaar/pyld/blob/master/CHANGELOG.md) - [Commits](digitalbazaar/pyld@v2.0.4...v3.0.0) --- updated-dependencies: - dependency-name: pyld dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ld-3.0.0 chore(deps): Bump pyld from 2.0.4 to 3.0.0
Bumps [pydevd](https://github.com/fabioz/PyDev.Debugger) from 3.4.1 to 3.5.0. - [Commits](https://github.com/fabioz/PyDev.Debugger/commits) --- updated-dependencies: - dependency-name: pydevd dependency-version: 3.5.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…4110) --- updated-dependencies: - dependency-name: aiohttp dependency-version: 3.13.4 dependency-type: direct:production dependency-group: pip - dependency-name: aiohttp dependency-version: 3.13.4 dependency-type: indirect dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the all-actions group with 3 updates: [docker/login-action](https://github.com/docker/login-action), [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) and [dawidd6/action-download-artifact](https://github.com/dawidd6/action-download-artifact). Updates `docker/login-action` from 4.0.0 to 4.1.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@b45d80f...4907a6d) Updates `SonarSource/sonarqube-scan-action` from 7.0.0 to 7.1.0 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@a31c939...299e4b7) Updates `dawidd6/action-download-artifact` from 19 to 20 - [Release notes](https://github.com/dawidd6/action-download-artifact/releases) - [Commits](dawidd6/action-download-artifact@8a33849...8305c0f) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 7.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: dawidd6/action-download-artifact dependency-version: '20' dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
) Bumps the pip group with 2 updates in the / directory: [cryptography](https://github.com/pyca/cryptography) and [jwcrypto](https://github.com/latchset/jwcrypto). Updates `cryptography` from 46.0.6 to 46.0.7 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@46.0.6...46.0.7) Updates `jwcrypto` from 1.5.6 to 1.5.7 - [Release notes](https://github.com/latchset/jwcrypto/releases) - [Commits](latchset/jwcrypto@v1.5.6...v1.5.7) --- updated-dependencies: - dependency-name: cryptography dependency-version: 46.0.7 dependency-type: indirect dependency-group: pip - dependency-name: jwcrypto dependency-version: 1.5.7 dependency-type: indirect dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pydantic](https://github.com/pydantic/pydantic) from 2.12.2 to 2.13.0. - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md) - [Commits](pydantic/pydantic@v2.12.2...v2.13.0) --- updated-dependencies: - dependency-name: pydantic dependency-version: 2.13.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…enarios/pydantic-2.13.0 chore(deps): Bump pydantic from 2.12.2 to 2.13.0 in /scenarios
…epmerge-3.0 chore(deps): Bump deepmerge from 2.1.0 to 3.0
Bumps [rlp](https://github.com/ApeWorX/pyrlp) from 4.1.0 to 5.0.0. - [Release notes](https://github.com/ApeWorX/pyrlp/releases) - [Changelog](https://github.com/ApeWorX/pyrlp/blob/main/docs/release_notes.rst) - [Commits](ApeWorX/pyrlp@v4.1.0...v5.0.0) --- updated-dependencies: - dependency-name: rlp dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…_actions/all-actions-64c8a27a46 chore(deps): Bump the all-actions group with 3 updates
DIF field paths were parsed with the base jsonpath_ng grammar, which covers only 9 of the 14 example expressions in the DIF Presentation Exchange spec's own JSONPath syntax table -- filter expressions ([?(...)]) are a jsonpath_ng.ext-only feature and were unsupported. Switch pres_exch_handler.py to jsonpath_ng.ext.parse to support filter expressions (existence, numeric comparison, exact-match, and single-& compound conditions). No new dependency: jsonpath-ng already ships the ext module under the pin already in pyproject.toml. Enabling jsonpath_ng.ext also enables its function-extension surface (sub, str, sorted, search, match) and a regex-match operator (=~). Presentation requests are only authenticated at the DIDComm connection level -- nothing validates the content of a presentation_definition once received, so an untrusted party who has an active connection could send a request containing one of these to run logic well beyond a plain data query, or a malformed expression that raises an unhandled parser error partway through building a presentation. Add a whitelist validator (jsonpath_guard.is_safe_jsonpath) wired into DIFFieldSchema.paths, so every DIFField.paths entry is checked against a fixed, narrow grammar at deserialization time -- before matching or presentation-building ever runs. Supports child/wildcard access, recursive descent, index/slice/union subscripts, the length-relative script subscript, and filter expressions limited to bare-existence or single-comparison conditions optionally joined by one &. Anything outside that grammar is rejected, whether malicious or merely unsupported syntax (e.g. && instead of &), consistent with the DIF spec's own Security Considerations guidance to avoid JSONPath's regular-expression and function-extension features where a direct alternative exists. Verified against every JSONPath expression already used across this package's existing test suite (69 distinct expressions) -- none are rejected by the new validator. Signed-off-by: nb-pratik-bhimani <pratik@northernblock.io>
…support-with-safety-guard-main feat: full JSONPath support via jsonpath_ng.ext with a safety guard
Bumps the pip group with 1 update in the / directory: [mkdocs-material](https://github.com/squidfunk/mkdocs-material). Updates `mkdocs-material` from 9.7.0 to 9.7.7 - [Release notes](https://github.com/squidfunk/mkdocs-material/releases) - [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG) - [Commits](squidfunk/mkdocs-material@9.7.0...9.7.7) --- updated-dependencies: - dependency-name: mkdocs-material dependency-version: 9.7.7 dependency-type: direct:production dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
…p-55c7a475ee chore(deps): Bump mkdocs-material from 9.7.0 to 9.7.7 in the pip group across 1 directory
Signed-off-by: Stephen Curran <swcurran@gmail.com>
Signed-off-by: Jackson Riding <jackson.riding@gmail.com>
Bumps [pyld](https://github.com/digitalbazaar/pyld) from 3.2.0 to 3.3.0. - [Release notes](https://github.com/digitalbazaar/pyld/releases) - [Changelog](https://github.com/digitalbazaar/pyld/blob/master/CHANGELOG.md) - [Commits](digitalbazaar/pyld@v3.2.0...v3.3.0) --- updated-dependencies: - dependency-name: pyld dependency-version: 3.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…ld-3.3.0 chore(deps): Bump pyld from 3.2.0 to 3.3.0
Fix DIF holder presentation signing for did:key
Bumps the pip group with 1 update in the /scenarios directory: [pygments](https://github.com/pygments/pygments). Bumps the pip group with 1 update in the /demo/playground/examples directory: [pygments](https://github.com/pygments/pygments). Bumps the pip group with 1 update in the / directory: [pynacl](https://github.com/pyca/pynacl). Updates `pygments` from 2.19.1 to 2.20.0 - [Release notes](https://github.com/pygments/pygments/releases) - [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES) - [Commits](pygments/pygments@2.19.1...2.20.0) Updates `pygments` from 2.19.1 to 2.20.0 - [Release notes](https://github.com/pygments/pygments/releases) - [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES) - [Commits](pygments/pygments@2.19.1...2.20.0) Updates `pynacl` from 1.6.0 to 1.6.2 - [Changelog](https://github.com/pyca/pynacl/blob/main/CHANGELOG.rst) - [Commits](pyca/pynacl@1.6.0...1.6.2) --- updated-dependencies: - dependency-name: pygments dependency-version: 2.20.0 dependency-type: indirect dependency-group: pip - dependency-name: pygments dependency-version: 2.20.0 dependency-type: indirect dependency-group: pip - dependency-name: pynacl dependency-version: 1.6.2 dependency-type: direct:production dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
…enarios/pip-919003f0cc chore(deps): Bump the pip group across 3 directories with 2 updates
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.1)
Can you help keep this open source service alive? 💖 Please sponsor : )