Skip to content

fix(deps): vuln click (minor → 8.5.0) [ddev/pyproject.toml] - #25369

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pep621/ddev/1-1790577624
Draft

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pep621/ddev/1-1790577624

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • ddev/pyproject.toml (pep621)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
click 8.1.6 8.5.0 minor Direct 2 HIGH

Security Details

🚨 Critical & High Severity (2 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
click PYSEC-2026-2132 high - 8.1.6 8.3.3 -
click CVE-2026-7246 high [DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()" 8.1.6 - -
⚠️ Dependencies that have Reached EOL (1)
Dependency Unsafe Version EOL Date New Version Path Case
click 8.1.6 - 8.5.0 ddev/pyproject.toml -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@dd-octo-sts

dd-octo-sts Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

❌ Dispatcher tests: failed

Dispatcher beta: informational only
Existing CI remains the merge signal.

Caution

1 integration failed. 2 of 2 jobs failed. Dispatcher could not collect test results for 2 targets.

  2/2 jobs

❌ 2 failed

Batches · ❌ batch-01 2/2

❌ ddev: 2 failed targets
  • default / linux · batch-01 · step Run ./.github/actions/setup-ddev · artifacts could not be downloaded
  • default / windows · batch-01 · step Run ./.github/actions/setup-ddev · artifacts could not be downloaded

Dispatcher finished on 79186a8 — GitHub Run · Dispatcher Logs.

@datadog-official

datadog-official Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Pipelines

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 307 Pipeline jobs failed

Check PR | run / Check PR changelog

View more details · View in GitHub Actions

PR | test / check

View more details · View in GitHub Actions

PR | test / test (linux, ubuntu-22.04, ddev, ddev on Linux) / ddev on Linux

View more details · View in GitHub Actions

View all 307 failed jobs.

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 14baefb | Docs | View more details | Give us feedback!

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

evalya-impact-summary

evalya impact analysis
Impact analysis: 0 selected, 0 skipped (of 0 test tasks)
Publish tasks:   2 (always emitted)
Diff (1 file):
  ddev/pyproject.toml

Debug a specific task: evalya plan impact --path <path> --task <task>

Learn more about CI impact filtering

@gh-worker-campaigns-3e9aa4

gh-worker-campaigns-3e9aa4 Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with master — rebased onto 79186a8.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-2c363b
dd-octo-sts-2c363b Bot force-pushed the engraver-auto-version-upgrade/minorpatch/pep621/ddev/1-1790577624 branch from 617c25c to c7f4d79 Compare September 29, 2026 23:49
@chouetz chouetz added the internal Identify a non-fork PR label Oct 2, 2026
Co-authored-by: dd-octo-sts-2c363b[bot] <266797965+dd-octo-sts-2c363b[bot]@users.noreply.github.com>
@dd-octo-sts-6bb5b9
dd-octo-sts-6bb5b9 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/pep621/ddev/1-1790577624 branch from c7f4d79 to 14baefb Compare October 5, 2026 12:08

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant