2 Commits

Author SHA1 Message Date
95ad195f1f fix(deps): update dependency tomlkit to v0.13.3 (#343)
Some checks failed
Security / sonarqube (push) Failing after 2m2s
Security / snyk (push) Successful in 1m48s
Release / Tag release (push) Successful in 19s
Release / Create Release (push) Successful in 5s
Release / Publish Docker Images (push) Successful in 3m13s
Release / Get Release ID (push) Successful in 6s
Release / Build Wheel File (push) Successful in 36s
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [tomlkit](https://github.com/sdispater/tomlkit) | project.dependencies | patch | `==0.13.2` -> `==0.13.3` |

---

### Release Notes

<details>
<summary>sdispater/tomlkit (tomlkit)</summary>

### [`v0.13.3`](https://github.com/sdispater/tomlkit/blob/HEAD/CHANGELOG.md#0133---2025-06-05)

[Compare Source](https://github.com/sdispater/tomlkit/compare/0.13.2...0.13.3)

##### Added

-   Add `.item()` method to array and tables to retrieve an item by key. ([#&#8203;390](https://github.com/python-poetry/tomlkit/issues/390))

##### Fixed

-   Fix missing newline when parsing a separated array of tables without trailing new line. ([#&#8203;381](https://github.com/python-poetry/tomlkit/issues/381))
-   Fix non-existing key error when deleting an item from an out-of-order table. ([#&#8203;383](https://github.com/python-poetry/tomlkit/issues/383))
-   Ensure newline is added between the plain values and the first table. ([#&#8203;387](https://github.com/python-poetry/tomlkit/issues/387))
-   Fix repeated whitespace when removing an array item. ([#&#8203;405](https://github.com/python-poetry/tomlkit/issues/405))
-   Fix invalid serialization after removing array item if the comma is on its own line. ([#&#8203;408](https://github.com/python-poetry/tomlkit/issues/408))
-   Fix serialization of a nested dotted key table. ([#&#8203;411](https://github.com/python-poetry/tomlkit/issues/411))
-   Refine the error message when use non-string as single key. ([#&#8203;412](https://github.com/python-poetry/tomlkit/issues/412))
-   Fix invalid serialization after overwriting a key of a out-of-order table. ([#&#8203;414](https://github.com/python-poetry/tomlkit/issues/414))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MC40MS40IiwidXBkYXRlZEluVmVyIjoiNDAuNDEuNCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsidHlwZS9kZXBlbmRlbmNpZXMiXX0=-->

Reviewed-on: https://git.tainton.uk/repos/pypilot/pulls/343
Co-authored-by: Renovate [BOT] <renovate-bot@git.tainton.uk>
Co-committed-by: Renovate [BOT] <renovate-bot@git.tainton.uk>
2025-06-06 18:42:10 +02:00
62a4ccbb46 Update .gitea/workflows/ci.yml
Some checks failed
Security / sonarqube (push) Failing after 30s
Security / snyk (push) Successful in 1m10s
2025-06-06 18:39:16 +02:00

View File

@@ -55,17 +55,37 @@ jobs:
- name: Minimize uv cache
run: uv cache prune --ci
- name: SonarQube Scan
uses: SonarSource/sonarqube-scan-action@v5.2.0
env:
SONAR_HOST_URL: ${{ secrets.SONARQUBE_HOST_URL }}
SONAR_TOKEN: ${{ secrets.SONARQUBE_TOKEN }}
# - name: SonarQube Scan
# uses: SonarSource/sonarqube-scan-action@v5.2.0
# env:
# SONAR_HOST_URL: ${{ secrets.SONARQUBE_HOST_URL }}
# SONAR_TOKEN: ${{ secrets.SONARQUBE_TOKEN }}
- name: Snyk Vulnerability Scan
- name: Set up environment for Snyk
run: |
uv pip freeze > requirements.txt
mv pyproject.toml pyproject.toml.bak
mv uv.lock uv.lock.bak
- name: Snyk SAST Scan
uses: snyk/actions/python@master
continue-on-error: true # Sometimes vulns aren't immediately fixable
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
command: snyk
args: test --all-projects
# command: snyk
args: snyk code test #--all-projects --exclude=.archive
# - name: Snyk Vulnerability Scan
# uses: snyk/actions/python@master
# continue-on-error: true # Sometimes vulns aren't immediately fixable
# env:
# SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
# with:
# command: snyk
# args: test --all-projects
- name: Reverse set up environment for Snyk
run: |
rm -f requirements.txt
mv pyproject.toml.bak pyproject.toml
mv uv.lock.bak uv.lock