Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 21, 2025

Bumps django-polymorphic from 3.1.0 to 4.1.0.

Release notes

Sourced from django-polymorphic's releases.

v4.1.0

What's Changed

We are waiting on permissions to publish through PyPi. Thank you for your patience. In the mean time this release tag passes CI on Django 5.2.

New Contributors

Full Changelog: jazzband/django-polymorphic@v4.0.0...v4.1.0

v4.0.0

What's Changed

... (truncated)

Commits
  • 3a81c0e Merge pull request #627 from jazzband/dependabot/pip/docs/_ext/djangodummy/dj...
  • fdcb919 Bump django from 4.2.16 to 4.2.18 in /docs/_ext/djangodummy
  • 7768cdc Merge pull request #611 from jazzband/pre-commit-ci-update-config
  • ed4a35b Merge pull request #619 from jazzband/dependabot/pip/docs/_ext/djangodummy/dj...
  • c360bf3 Merge pull request #622 from joaoseckler/css-vars
  • 87061aa Merge pull request #626 from bckohan/master
  • da65e09 update test matrix to correct python/django combinations and test against 5.1...
  • 76b0e77 Merge pull request #624 from bckohan/master
  • 62fb809 Merge branch 'jazzband:master' into master
  • 1d4f95f upgrade GHA versions
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [django-polymorphic](https://github.com/jazzband/django-polymorphic) from 3.1.0 to 4.1.0.
- [Release notes](https://github.com/jazzband/django-polymorphic/releases)
- [Changelog](https://github.com/jazzband/django-polymorphic/blob/master/docs/changelog.rst)
- [Commits](jazzband/django-polymorphic@v3.1...v4.1.0)

---
updated-dependencies:
- dependency-name: django-polymorphic
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 21, 2025
@dependabot dependabot bot requested review from Maffooch and mtesauro as code owners May 21, 2025 12:41
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 21, 2025
Copy link

DryRun Security

This pull request involves a potential dependency version upgrade for django-polymorphic that may introduce breaking changes and requires careful review of compatibility to prevent unintended security consequences.

💭 Unconfirmed Findings (1)
Vulnerability Potential Dependency Version Change Risk
Description Upgrading django-polymorphic from version 3.1.0 to 4.1.0 may introduce breaking changes and potentially expose new security surface areas. Careful review of changelog and compatibility is recommended to prevent unintended security consequences.

All finding details can be found in the DryRun Security Dashboard.

Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@mtesauro mtesauro merged commit 541ce46 into dev May 21, 2025
77 checks passed
@dependabot dependabot bot deleted the dependabot/pip/dev/django-polymorphic-4.1.0 branch May 21, 2025 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants