Skip to content

Bump modelaudit from 0.2.42 to 0.2.52 in /services/quarantine#92

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/services/quarantine/modelaudit-0.2.52
Open

Bump modelaudit from 0.2.42 to 0.2.52 in /services/quarantine#92
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/services/quarantine/modelaudit-0.2.52

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps modelaudit from 0.2.42 to 0.2.52.

Changelog

Sourced from modelaudit's changelog.

0.2.52 (2026-07-22)

Bug Fixes

0.2.51 (2026-07-20)

Bug Fixes

  • recover root release build and PyPI smoke gates (#1764) (fa350d9)

0.2.50 (2026-07-20)

Security

  • validate Windows MLflow staging hardlinks with native file identities so aliases outside the staging tree fail closed
  • treat protocol-relative report sources as remote identifiers before any Windows UNC filesystem probe
  • reject premature pickle STOP opcodes inside Joblib NumPy wrapper streams and fail closed when wrapper validation cannot complete

Bug Fixes

  • cache: reuse stat without breaking public overrides (#1732) (39cd664)
  • cli: handle startup interrupts gracefully (#1723) (839c7cf)
  • deep-merge partial auth config updates (#1721) (8f33995)
  • deps: update PyTorch to 2.13.0 for CVE-2025-3000; PyTorch-containing extras now require macOS 14 or newer on Apple Silicon and standard (GIL-enabled) CPython 3.13 or Python 3.10-3.12; CPython 3.13t is unsupported, while core-only remains available on macOS 11-13
  • deps: require Click 8.3.3 or newer to address PYSEC-2026-2132
  • deps: require modelaudit-picklescan>=0.1.9 so root upgrades receive the released scanner fixes
  • deps: update NumPy to 2.5 on Python 3.12+ while retaining NumPy 2.4 on Python 3.11, matching NumPy's supported Python versions (#1706) (eeba9b8)
  • hashing: adapt reads near scan deadlines (#1734) (f23e1c0)
  • picklescan: preserve POSIX ctime checks (#1719) (cbde525)
  • picklescan: resolve reviewed runtime hasattr guards without losing call-graph sinks
  • picklescan: restore standalone CI (#1742) (88632fe)
  • restore cross-platform nightly CI safety (#1704) (9df81da)

0.2.49 (2026-06-25)

Bug Fixes

  • picklescan: restore Windows call-graph detection via cross-view stat identity (#1715) (51c0074)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [modelaudit](https://github.com/promptfoo/modelaudit) from 0.2.42 to 0.2.52.
- [Release notes](https://github.com/promptfoo/modelaudit/releases)
- [Changelog](https://github.com/promptfoo/modelaudit/blob/main/CHANGELOG.md)
- [Commits](promptfoo/modelaudit@v0.2.42...v0.2.52)

---
updated-dependencies:
- dependency-name: modelaudit
  dependency-version: 0.2.52
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants