Skip to content

chore(deps): update dependency bandit to v1.11.1#487

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/bandit-1.x
Open

chore(deps): update dependency bandit to v1.11.1#487
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/bandit-1.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 2, 2026

This PR contains the following updates:

Package Type Update Change
bandit (source) prod minor 1.10.1== 1.11.1

Release Notes

mtrudel/bandit (bandit)

v1.11.1

Compare Source

Fixes
Changes
  • We no longer disallow . and .. path components in HTTP/2 absolute paths (#​581)

v1.11.0

Compare Source

Fixes
Enhancements
  • Define a new max_inflate_ratio WebSocket configuration option that defines a
    maximum allowable decompression ratio to help mitigate inflate bombing. Defaults to 25:1
  • Define a new max_fragmented_message_size WebSocket configuration option
    which defines the maximum allowed WebSocket frame size (inclusive of
    continuation frames). Defaults to 8MB

v1.10.4

Compare Source

Enhancements

v1.10.3

Compare Source

Enhancements
  • Support authority form requests for CONNECT requests (#​571)
  • Narrow acceptance of asterisk form requests to OPTIONS requests (#​571)
  • Detect client disconnect on timeout in ensure_completed (#​566, thanks @​pepicrft!)
  • Improve http2 sendfile streaming (#​565, thanks @​elibosley!)

v1.10.2

Compare Source

Enhancements
  • Distinguish client disconnects from genuine body read timeouts (#​564, thanks @​pepicrft!)

Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency bandit to v1.11.0 chore(deps): update dependency bandit to v1.11.1 May 13, 2026
@renovate renovate Bot force-pushed the renovate/bandit-1.x branch from b1c63f7 to 47677d7 Compare May 13, 2026 14:04
@renovate renovate Bot force-pushed the renovate/bandit-1.x branch from 47677d7 to bf48d51 Compare May 18, 2026 11:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants