Skip to content

chore(deps-pip): bump the python-deps group with 5 updates - #7

Merged
github-actions[bot] merged 1 commit into
masterfrom
dependabot/pip/master/python-deps-577aa9f677
Jul 28, 2026
Merged

chore(deps-pip): bump the python-deps group with 5 updates#7
github-actions[bot] merged 1 commit into
masterfrom
dependabot/pip/master/python-deps-577aa9f677

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown

Bumps the python-deps group with 5 updates:

Package From To
mkdocs-material 9.7.0 9.7.7
mkdocs-git-revision-date-localized-plugin 1.5.0 1.5.3
mkdocs-swagger-ui-tag 0.6.11 0.8.1
pillow 10.4.0 12.3.0
cairosvg 2.8.2 2.9.0

Updates mkdocs-material from 9.7.0 to 9.7.7

Release notes

Sourced from mkdocs-material's releases.

mkdocs-material-9.7.7

[!WARNING]

Material for MkDocs is approaching end of life

Material for MkDocs is scheduled to reach end of life on November 5, 2026. Until then, maintenance is limited to critical bug fixes and security updates. After this date, the project will remain available on PyPI and GitHub, but no further maintenance is planned except in exceptional circumstances.

For users looking for a long-term, actively developed successor, we're building Zensical – a next-generation static site generator designed for technical documentation. If you're planning a new documentation project or evaluating your long-term options, we invite you to take a look.

Organizations requiring support beyond this date are welcome to get in touch to discuss available options.

Read the full announcement on our blog

Changes

  • Fixed a DOM-based XSS vulnerability in search suggestions

Thanks to @​p- for responsibly reporting this issue.

mkdocs-material-9.7.6

[!WARNING]

Material for MkDocs is in maintenance mode

Going forward, the Material for MkDocs team focuses on Zensical, a next-gen static site generator built from first principles. We will provide critical bug fixes and security updates for Material for MkDocs until November 2026.

Read the full announcement on our blog

Changes

  • Automatically disable MkDocs 2.0 warning for forks of MkDocs

mkdocs-material-9.7.5

[!WARNING]

Material for MkDocs is in maintenance mode

Going forward, the Material for MkDocs team focuses on Zensical, a next-gen static site generator built from first principles. We will provide critical bug fixes and security updates for Material for MkDocs until November 2026.

Read the full announcement on our blog

... (truncated)

Changelog

Sourced from mkdocs-material's changelog.

mkdocs-material-9.7.7 (2026-07-17)

  • Fixed DOM-based XSS vulnerability in search suggestions

mkdocs-material-9.7.6 (2026-03-19)

  • Automatically disable MkDocs 2.0 warning for forks of MkDocs

mkdocs-material-9.7.5 (2026-03-10)

  • Limited version range of mkdocs to <2
  • Updated MkDocs 2.0 incompatibility warning (clarify relation with MkDocs)

mkdocs-material-9.7.4 (2026-03-03)

  • Hardened social cards plugin by switching to sandboxed environment
  • Updated MkDocs 2.0 incompatibility warning

mkdocs-material-9.7.3 (2026-02-24)

  • Fixed #8567: Print MkDocs 2.0 incompatibility warning to stderr

mkdocs-material-9.7.2 (2026-02-18)

  • Opened up version ranges of optional dependencies for forward-compatibility
  • Added warning to 'mkdocs build' about impending MkDocs 2.0 incompatibility

mkdocs-material-9.7.1 (2025-12-18)

  • Updated requests to 2.30+ to mitigate CVE in urllib
  • Fixed privacy plugin not picking up protocol-relative URLs
  • Fixed #8542: false positives and negatives captured in privacy plugin

mkdocs-material-9.7.0 (2025-11-11)

⚠️ Material for MkDocs is now in maintenance mode

This is the last release of Material for MkDocs that will receive new features. Going forward, the Material for MkDocs team focuses on Zensical, a next-gen static site generator built from first principles. We will provide critical bug fixes and security updates for Material for MkDocs for 12 months at least.

Read the full announcement on our blog: https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/

This release includes all features that were previously exclusive to the Insiders edition. These features are now freely available to everyone.

Note on deprecated plugins: The projects and typeset plugins are included in this release, but must be considered deprecated. Both plugins proved

... (truncated)

Commits

Updates mkdocs-git-revision-date-localized-plugin from 1.5.0 to 1.5.3

Release notes

Sourced from mkdocs-git-revision-date-localized-plugin's releases.

v1.5.3

What's Changed

New Contributors

Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.2...v1.5.3

v1.5.2

What's Changed

Bug fixes

Dependency updates (security)

Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.1...v1.5.2

revision-date-localized v1.5.1

What's Changed

New Contributors

Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.0...v1.5.1

Commits
  • 30e5876 Bump version to 1.5.3
  • d58c5be Merge pull request #211 from mitya57/fix-manifest
  • 6da0b4e Fix paths in MANIFEST.in
  • aa0d4a3 Constrain mkdocs to <2
  • 2afa3d2 Bump version to 1.5.2
  • 66e9b7e Document release process in CONTRIBUTING.md
  • 2fb5070 Merge pull request #209 from timvink/dependabot/uv/urllib3-2.7.0
  • d0bacc8 Bump urllib3 from 2.6.3 to 2.7.0
  • ee28ad9 Merge pull request #208 from timvink/dependabot/uv/gitpython-3.1.50
  • befbdab Bump gitpython from 3.1.49 to 3.1.50
  • Additional commits viewable in compare view

Updates mkdocs-swagger-ui-tag from 0.6.11 to 0.8.1

Release notes

Sourced from mkdocs-swagger-ui-tag's releases.

mkdocs-swagger-ui-tag-0.8.1

What's Changed

New Contributors

Full Changelog: blueswen/mkdocs-swagger-ui-tag@v0.8.0...v0.8.1

mkdocs-swagger-ui-tag-0.8.0

  • Supported deactivate browser cache for openapi files (#37)
  • Updated swagger-ui-dist source (#38)
  • Updated swagger-ui-dist to 5.31.2
  • Switched to swagger ui builtin dark mode

mkdocs-swagger-ui-tag-0.7.2

  • Updated swagger-ui-dist to 5.27.1 (#36)

mkdocs-swagger-ui-tag-0.7.1

  • Updated swagger-ui-dist to 5.21.0

mkdocs-swagger-ui-tag-0.7.0

  • Updated swagger-ui-dist to 5.20.6
  • Migrated to uv and pyproject.toml for development and building
  • Supported filename filter (#26)
  • Compatible with bs4 4.0.0+ (#29)
Changelog

Sourced from mkdocs-swagger-ui-tag's changelog.

mkdocs-swagger-ui-tag 0.8.1 (2026-07-10)

* Fixed syntaxHighlightTheme bug ([#44](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/44))
* Fixed oauth2-redirect bug ([#46](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/46))
* Supported Mkdocs Materialx ([#48](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/48))
* Updated swagger-ui-dist to 5.32.8

mkdocs-swagger-ui-tag 0.8.0 (2026-02-22)

* Supported deactivate browser cache for openapi files ([#37](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/37))
* Updated swagger-ui-dist source ([#38](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/38))
* Updated swagger-ui-dist to 5.31.2
* Switched to swagger ui builtin dark mode

mkdocs-swagger-ui-tag 0.7.2 (2025-08-24)

* Updated swagger-ui-dist to 5.27.1 ([#36](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/36))

mkdocs-swagger-ui-tag 0.7.1 (2025-05-04)

* Updated swagger-ui-dist to 5.21.0

mkdocs-swagger-ui-tag 0.7.0 (2025-04-06)

* Updated swagger-ui-dist to 5.20.6
* Migrated to uv and pyproject.toml for development and building
* Supported filename filter ([#26](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/26))
* Compatible with bs4 4.0.0+ ([#29](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/29))

mkdocs-swagger-ui-tag 0.6.11 (2024-10-27)

* Updated swagger-ui-dist to 5.17.14

mkdocs-swagger-ui-tag 0.6.10 (2024-05-01)

* Updated swagger-ui-dist to 5.17.3

mkdocs-swagger-ui-tag 0.6.9 (2024-03-25)

* Updated swagger-ui-dist to 5.12.0
* Improved OAS 3.1 dark mode contrast ([#22](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/22))
* Generate iframe ids deterministically ([#20](https://github.com/blueswen/mkdocs-swagger-ui-tag/issues/20))

mkdocs-swagger-ui-tag 0.6.8 (2024-01-22)

* Updated swagger-ui-dist to 5.11.0

mkdocs-swagger-ui-tag 0.6.7 (2023-11-18)

* Updated swagger-ui-dist to 5.10.0

... (truncated)

Commits
  • d50e337 Release 0.8.1
  • 311dc03 Update tests
  • 4c84c94 Updat swagger-ui-dist to 5.32.8
  • 968236f Fix syntaxHighlightTheme bug
  • edaaff2 Merge pull request #48 from mw-root/add-materialx-support
  • 5ab0b47 Merge pull request #46 from rowi1de/fix/oauth2-redirect-js-not-copied
  • 5b29153 chore: Add Support for Mkdocs Materialx
  • bbfed94 fix: copy oauth2-redirect.js to assets/swagger-ui/ in on_post_build
  • 61d6c5f Update workflow
  • 972b1e2 Release 0.8.0
  • Additional commits viewable in compare view

Updates pillow from 10.4.0 to 12.3.0

Release notes

Sourced from pillow's releases.

12.3.0

https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html

Removals

Documentation

Dependencies

Testing

... (truncated)

Changelog

Sourced from pillow's changelog.

Changelog (Pillow)

11.1.0 and newer

See GitHub Releases:

11.0.0 (2024-10-15)

  • Update licence to MIT-CMU #8460 [hugovk]

  • Conditionally define ImageCms type hint to avoid requiring core #8197 [radarhere]

  • Support writing LONG8 offsets in AppendingTiffWriter #8417 [radarhere]

  • Use ImageFile.MAXBLOCK when saving TIFF images #8461 [radarhere]

  • Do not close provided file handles with libtiff when saving #8458 [radarhere]

  • Support ImageFilter.BuiltinFilter for I;16* images #8438 [radarhere]

  • Use ImagingCore.ptr instead of ImagingCore.id #8341 [homm, radarhere, hugovk]

  • Updated EPS mode when opening images without transparency #8281 [Yay295, radarhere]

  • Use transparency when combining P frames from APNGs #8443 [radarhere]

  • Support all resampling filters when resizing I;16* images #8422 [radarhere]

  • Free memory on early return #8413 [radarhere]

  • Cast int before potentially exceeding INT_MAX #8402 [radarhere]

... (truncated)

Commits
  • bb1d8e8 12.3.0 version bump
  • e63fc48 Add release notes for SBOM and performance improvements (#9747)
  • 13b701b Add release notes for #9679
  • 5564ca7 List methods
  • a0920fd Speed up ImageChops operations (#9738)
  • 07e9a6c Speed up Image.filter() (#9736)
  • a94578c Speed up Image.getchannel(), Image.merge(), Image.putalpha() and `Image...
  • 53e02c4 Speed up Image.fill(), Image.linear_gradient() and `Image.radial_gradient...
  • af03747 Speed up Image.resample() (#9739)
  • 5c9ca56 Speed up alpha_composite, matrix, negative, quantize (#9740)
  • Additional commits viewable in compare view

Updates cairosvg from 2.8.2 to 2.9.0

Release notes

Sourced from cairosvg's releases.

2.9.0

WARNING: this is a security update.

Using a lot of recursively nested use tags could lead to long rendering times with relatively small inputs. CairoSVG now stops rendering when more than 100k use tags are rendered.

Using the --unsafe option allows to render larger documents.

  • Drop support of Python 3.9, add support of Python 3.14
Changelog

Sourced from cairosvg's changelog.

Version 2.9.0 released on 2026-03-13

WARNING: this is a security update.

Using a lot of recursively nested use tags could lead to long rendering times with relatively small inputs. CairoSVG now stops rendering when more than 100k use tags are rendered.

Using the --unsafe option allows to render larger documents.

  • Drop support of Python 3.9, add support of Python 3.14
Commits
  • fe5cae5 Version 2.9.0
  • 6dde868 Abort when more than 100k referenced elements are rendered
  • a6b3a98 Cut long line again
  • ce8b51d Cut long line
  • b7818c9 Clarify unsafe option scope without removing security warning
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-deps group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [mkdocs-material](https://github.com/squidfunk/mkdocs-material) | `9.7.0` | `9.7.7` |
| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.0` | `1.5.3` |
| [mkdocs-swagger-ui-tag](https://github.com/blueswen/mkdocs-swagger-ui-tag) | `0.6.11` | `0.8.1` |
| [pillow](https://github.com/python-pillow/Pillow) | `10.4.0` | `12.3.0` |
| [cairosvg](https://github.com/Kozea/CairoSVG) | `2.8.2` | `2.9.0` |


Updates `mkdocs-material` from 9.7.0 to 9.7.7
- [Release notes](https://github.com/squidfunk/mkdocs-material/releases)
- [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG)
- [Commits](squidfunk/mkdocs-material@9.7.0...9.7.7)

Updates `mkdocs-git-revision-date-localized-plugin` from 1.5.0 to 1.5.3
- [Release notes](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin/releases)
- [Commits](timvink/mkdocs-git-revision-date-localized-plugin@v1.5.0...v1.5.3)

Updates `mkdocs-swagger-ui-tag` from 0.6.11 to 0.8.1
- [Release notes](https://github.com/blueswen/mkdocs-swagger-ui-tag/releases)
- [Changelog](https://github.com/blueswen/mkdocs-swagger-ui-tag/blob/main/CHANGELOG)
- [Commits](blueswen/mkdocs-swagger-ui-tag@v0.6.11...v0.8.1)

Updates `pillow` from 10.4.0 to 12.3.0
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@10.4.0...12.3.0)

Updates `cairosvg` from 2.8.2 to 2.9.0
- [Release notes](https://github.com/Kozea/CairoSVG/releases)
- [Changelog](https://github.com/Kozea/CairoSVG/blob/main/NEWS.rst)
- [Commits](Kozea/CairoSVG@2.8.2...2.9.0)

---
updated-dependencies:
- dependency-name: mkdocs-material
  dependency-version: 9.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: mkdocs-git-revision-date-localized-plugin
  dependency-version: 1.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: mkdocs-swagger-ui-tag
  dependency-version: 0.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: pillow
  dependency-version: 12.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python-deps
- dependency-name: cairosvg
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jul 28, 2026
@github-actions
github-actions Bot merged commit f12cf65 into master Jul 28, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/master/python-deps-577aa9f677 branch July 28, 2026 22:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants