Skip to content

chore(deps): bump the minor-and-patch group in /memberportal with 2 updates - #60

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/uv/memberportal/minor-and-patch-963a4823a7
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/uv/memberportal/minor-and-patch-963a4823a7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group in /memberportal with 2 updates: sentry-sdk and cbor2.

Updates sentry-sdk from 2.70.0 to 2.71.0

Release notes

Sourced from sentry-sdk's releases.

2.71.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.typesafe import TypeSafeIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
TypeSafeIntegration(),
]
)

Typesafe

Bug Fixes 🐛

Documentation 📚

Internal Changes 🔧

Changelog

Sourced from sentry-sdk's changelog.

2.71.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.typesafe import TypeSafeIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
TypeSafeIntegration(),
]
)

Typesafe

Bug Fixes 🐛

Documentation 📚

Internal Changes 🔧

Commits

Updates cbor2 from 6.1.4 to 6.1.5

Release notes

Sourced from cbor2's releases.

6.1.5

  • Fixed CBORSimpleValue hashing inconsistently with the integer it compares equal to (#334; PR by @​sahvx655-wq)
  • Fixed canonical encoding with value sharing enabled emitting shared references to container keys that were never written to the stream, because the throwaway encoding used to sort the keys registered them as shared values; the output then failed to decode, or decoded with the wrong keys substituted in (#339; PR by @​sahvx655-wq)
  • Fixed shared references (tag 29) to a map or an unhandled tag resolving to the raw dict or CBORTag instead of the value returned by object_hook or tag_hook, a regression from 5.x (#343; PR by @​sahvx655-wq)
  • Fixed the encoder not giving a nested stringref namespace (tag 256) its own index space (#335; PR by @​dylanpulver)
  • Fixed the decoder returning its internal break marker as a value when a break stop code appeared where a data item was expected (#305; PR by @​sahvx655-wq)
  • Fixed a PanicException when trying to decode an epoch-form date (tag 100) with a payload near i32::MAX which then overflowed the addition instead of raising a clean decode error (#340; PR by @​sahvx655-wq)
  • Fixed the decoder accepting a string-form datetime (tag 0) without a UTC offset and returning a naive ~datetime.datetime instead of rejecting it (#347; PR by @​sahvx655-wq)
  • Fixed a reused CBOREncoder no longer flushing its output or resetting its shared container and string reference tracking after an encode() call had raised an exception (#348; PR by @​sahvx655-wq)
Commits
  • cf5b8c5 Fixed flaky datetime comparison
  • 4a20060 Bumped up the version
  • c895351 Reset encoder state after a failed encode (#348)
  • c562883 Bump the github-actions group with 2 updates (#349)
  • 2774413 Reject string-form datetime (tag 0) without a UTC offset (#347)
  • ab3a865 Fixed integer overflow when decoding epoch-form dates (tag 100) (#340)
  • 96c5b15 reject misplaced break stop code instead of leaking break marker (#341)
  • bb301da Give a nested stringref namespace its own index space (#335)
  • 7f84e3d Make shared references honour object_hook and tag_hook results (#343)
  • e480550 Disable value sharing while computing canonical sort keys (#339)
  • Additional commits viewable in compare view

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group in /memberportal with 2 updates: [sentry-sdk](https://github.com/getsentry/sentry-python) and [cbor2](https://github.com/agronholm/cbor2).


Updates `sentry-sdk` from 2.70.0 to 2.71.0
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@2.70.0...2.71.0)

Updates `cbor2` from 6.1.4 to 6.1.5
- [Release notes](https://github.com/agronholm/cbor2/releases)
- [Commits](agronholm/cbor2@6.1.4...6.1.5)

---
updated-dependencies:
- dependency-name: sentry-sdk
  dependency-version: 2.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: cbor2
  dependency-version: 6.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 8, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Created image with name ghcr.io/pawprintprototyping/membermatters:untrusted-pr-image-PawprintPrototyping-dependabot-uv-memberportal-minor-and-patch-963a4823a7. WARNING: run this image at your own risk - it was created from a potentially untrusted PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants