Sitelet https://github.com/lightningd/plugins/pull/980
Skip to content

build(deps): bump the all-dependencies group across 3 directories with 4 updates - #980

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/historian/all-dependencies-c17a180cd5
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/historian/all-dependencies-c17a180cd5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 1 update in the /historian directory: werkzeug.
Bumps the all-dependencies group with 1 update in the /monitor directory: werkzeug.
Bumps the all-dependencies group with 4 updates in the /summary directory: pyln-client, pyln-testing, pyln-proto and werkzeug.

Updates werkzeug from 3.1.8 to 3.1.9

Release notes

Sourced from werkzeug's releases.

3.1.9

This is the Werkzeug 3.1.9 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.9/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-9 Milestone: https://github.com/pallets/werkzeug/milestone/46?closed=1

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. GHSA-g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. #3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. #3189
  • Improve performance of parse_options_header. #3231
  • Improve performance of parse_etags. #3231
  • Improve performance of parse_cookie. #3231
  • get_host also checks that the port is in the valid range. #3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). #3237
  • Improve debugger PIN generation from cgroup data inside Podman. #3245
  • Authorization parsing basic auth disallows non-base64 characters. #3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. #3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. #3253
  • Rules with 10 or more converters in a single part assign matched values correctly. #3254
  • The invalid Range suffix length -0 is no longer accepted. #3255
Changelog

Sourced from werkzeug's changelog.

Version 3.1.9

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman. :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters. :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255
Commits

Updates werkzeug from 3.1.8 to 3.1.9

Release notes

Sourced from werkzeug's releases.

3.1.9

This is the Werkzeug 3.1.9 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.9/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-9 Milestone: https://github.com/pallets/werkzeug/milestone/46?closed=1

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. GHSA-g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. #3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. #3189
  • Improve performance of parse_options_header. #3231
  • Improve performance of parse_etags. #3231
  • Improve performance of parse_cookie. #3231
  • get_host also checks that the port is in the valid range. #3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). #3237
  • Improve debugger PIN generation from cgroup data inside Podman. #3245
  • Authorization parsing basic auth disallows non-base64 characters. #3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. #3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. #3253
  • Rules with 10 or more converters in a single part assign matched values correctly. #3254
  • The invalid Range suffix length -0 is no longer accepted. #3255
Changelog

Sourced from werkzeug's changelog.

Version 3.1.9

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman. :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters. :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255
Commits

Updates pyln-client from 26.6.7 to 26.6.8

Release notes

Sourced from pyln-client's releases.

v26.06.8 Quantum-Resistant Lightning Channel V

This 26.06.8 point release includes a set of bug fixes alongside fixes for vulnerabilities responsibly reported by a number of sources. We strongly recommend upgrading to this release.

There is no embargo period for 26.06.8. The release and the associated fixes are available immediately. However, we have temporarily withheld a small number of tests to make it more difficult for prospective attackers to identify, reverse-engineer, and exploit the underlying vulnerabilities.

This measure is intended to give users and network participants more time to upgrade before additional technical detail becomes available.

Notes for operators

  • Dual funding (--experimental-dual-fund) remains experimental. Zero-conf channels with peers you do not trust are discouraged.
  • Nodes that have run development (master) builds cannot downgrade to a 26.06.x release: the database schema is newer.

Thanks

This point release includes fixes for issues responsibly reported by:

To the open source contributors who assisted with fixes and reviews:

And to the maintaining team who worked on this release:

... (truncated)

Commits
  • 6f741af release: CHANGELOG and version bumps for v26.06.8
  • 5891127 lightningd: adopt a confirmed splice candidate whose output is spent before s...
  • 3a91f44 pytest: a confirmed splice output spent before splice_locked must be adopted
  • 3831a85 wallet: fix splice-RBF HTLC signature promotion
  • 84bfdf4 lightningd: refuse channels whose channel_id is already in use
  • bc01ae6 pytest: channels reusing a funding outpoint must not crash us
  • c4b2b41 hsmd: don't report forced channel secrets as memleaks
  • 7bac782 channel_control: don't leave a stale inflight watch on the outpoint after spl...
  • 105f616 lightningd: refuse a dual-funded candidate that reuses a funding outpoint
  • e44cf34 lightningd: watch a dual-funded channel's funding outputs before lock-in
  • Additional commits viewable in compare view

Updates pyln-testing from 26.6.7 to 26.6.8

Updates pyln-proto from 26.6.7 to 26.6.8

Updates werkzeug from 3.1.8 to 3.1.9

Release notes

Sourced from werkzeug's releases.

3.1.9

This is the Werkzeug 3.1.9 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.9/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-9 Milestone: https://github.com/pallets/werkzeug/milestone/46?closed=1

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. GHSA-g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. #3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. #3189
  • Improve performance of parse_options_header. #3231
  • Improve performance of parse_etags. #3231
  • Improve performance of parse_cookie. #3231
  • get_host also checks that the port is in the valid range. #3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). #3237
  • Improve debugger PIN generation from cgroup data inside Podman. #3245
  • Authorization parsing basic auth disallows non-base64 characters. #3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. #3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. #3253
  • Rules with 10 or more converters in a single part assign matched values correctly. #3254
  • The invalid Range suffix length -0 is no longer accepted. #3255
Changelog

Sourced from werkzeug's changelog.

Version 3.1.9

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman. :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters. :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 4 updates

Bumps the all-dependencies group with 1 update in the /historian directory: [werkzeug](https://github.com/pallets/werkzeug).
Bumps the all-dependencies group with 1 update in the /monitor directory: [werkzeug](https://github.com/pallets/werkzeug).
Bumps the all-dependencies group with 4 updates in the /summary directory: [pyln-client](https://github.com/ElementsProject/lightning), pyln-testing, pyln-proto and [werkzeug](https://github.com/pallets/werkzeug).


Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

Updates `pyln-client` from 26.6.7 to 26.6.8
- [Release notes](https://github.com/ElementsProject/lightning/releases)
- [Changelog](https://github.com/ElementsProject/lightning/blob/master/CHANGELOG.md)
- [Commits](ElementsProject/lightning@v26.06.7...v26.06.8)

Updates `pyln-testing` from 26.6.7 to 26.6.8

Updates `pyln-proto` from 26.6.7 to 26.6.8

Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: pyln-client
  dependency-version: 26.6.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: pyln-testing
  dependency-version: 26.6.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: pyln-proto
  dependency-version: 26.6.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants