dependabot[bot]
6e93461918
chore(deps): bump python-multipart from 0.0.24 to 0.0.26
...
Bumps [python-multipart](https://github.com/Kludex/python-multipart ) from 0.0.24 to 0.0.26.
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/master/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.24...0.0.26 )
---
updated-dependencies:
- dependency-name: python-multipart
dependency-version: 0.0.26
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-04-21 13:26:19 +00:00
dependabot[bot]
043ae4b378
chore(deps): bump authlib from 1.6.9 to 1.6.11
...
Bumps [authlib](https://github.com/authlib/authlib ) from 1.6.9 to 1.6.11.
- [Release notes](https://github.com/authlib/authlib/releases )
- [Changelog](https://github.com/authlib/authlib/blob/v1.6.11/docs/changelog.rst )
- [Commits](https://github.com/authlib/authlib/compare/v1.6.9...v1.6.11 )
---
updated-dependencies:
- dependency-name: authlib
dependency-version: 1.6.11
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-04-17 00:41:27 +00:00
ZdenekSrotyr
86fe4b411d
fix: upgrade urllib3 1.26→2.6.3 — resolves all 4 Dependabot security alerts
...
Removed kbcstorage from all dependency groups (optional + dev) so urllib3
is no longer pinned to <2.0. Legacy Keboola client is available via
manual install: pip install kbcstorage
2026-04-09 14:53:30 +02:00
ZdenekSrotyr
809448e02b
fix: move kbcstorage to optional dep — unblocks urllib3 security updates
...
kbcstorage pins urllib3<2.0.0 which blocks Dependabot security patches.
Moved to [project.optional-dependencies] keboola-legacy since the primary
extraction path uses the DuckDB Keboola extension, not kbcstorage.
Legacy fallback uses lazy import — app works without it installed.
2026-04-09 14:46:50 +02:00
ZdenekSrotyr
1ebf50bd78
fix: upgrade setup-uv@v5 → v8 (Node.js 24 native), add uv.lock
...
- setup-uv@v8 runs on Node.js 24 natively — no more deprecation warnings
- Removed FORCE_JAVASCRIPT_ACTIONS_TO_NODE24 workaround (no longer needed)
- Added uv.lock for reproducible dependency resolution
2026-04-09 14:16:55 +02:00