22# Multiple entries for the same package (with different version constraints) are grouped together.
33
44aiohttp>=3.13.5,<3.14.0; python_version < '3.10'
5- aiohttp>=3.14.1 ; python_version >= '3.10'
5+ aiohttp>=3.14.3 ; python_version >= '3.10'
66apache-libcloud>=3.8.0,<3.9.1; python_version < '3.10'
77apache-libcloud>=3.9.1; python_version >= '3.10'
88# attrs and charset-normalizer are pulled in transitively by aiohttp/requests.
99# Explicit floors on py>=3.10 keep them at the current CVE-patched line.
1010attrs>=26.1.0; python_version >= '3.10'
11- certifi>=2026.5.20
12- cffi>=2.0.0
13- charset-normalizer>=3.4.7 ; python_version >= '3.10'
11+ certifi>=2026.7.22
12+ cffi>=2.1.1
13+ charset-normalizer>=3.5.1 ; python_version >= '3.10'
1414# cheroot 8.5.2 fails to build with modern setuptools due to setuptools_scm_git_archive dependency
1515cheroot>=11.1.2
1616cherrypy>=18.10.0
1717# We need contextvars for salt-ssh
1818contextvars; python_version < '3.7'
19- croniter!=0.3.22,>=6.2.2 ; sys_platform != 'win32'
19+ croniter!=0.3.22,>=6.2.4 ; sys_platform != 'win32'
2020# cryptography 48.0.0 drops support for Python 3.9.0 and 3.9.1
2121# (only >3.9.1 is accepted), but the py3.9 lock files are compiled
2222# with --python-version=3.9 which includes those releases. Cap at the
2323# last 46.x release for Python 3.9 so uv pip compile can still resolve.
2424cryptography>=46.0.7,<48.0.0; python_version < '3.10'
25- cryptography>=50.0.0 ; python_version >= '3.10'
25+ cryptography>=50.0.1 ; python_version >= '3.10'
2626distro>=1.9.0
2727frozenlist>=1.8.0; python_version < '3.11'
2828frozenlist>=1.5.0; python_version >= '3.11'
29- gitpython>=3.1.59
30- idna>=3.18
29+ gitpython>=3.1.62
30+ idna>=3.19
3131immutables>=0.21; python_version < '3.7'
3232# importlib-metadata 9.x drops py3.9 support. Cap on py3.9, allow 8.7+ on
3333# py3.10, and let py>=3.11 use the existing 8.7+ floor.
@@ -36,45 +36,45 @@ importlib-metadata>=8.7.0; python_version >= '3.10'
3636# jaraco.functools 4.5.0 and jaraco.context 6.1.2 drop Python 3.9; keep the
3737# last 3.9-compatible releases there and let py>=3.10 float forward.
3838jaraco.functools>=4.4.0,<4.5.0; python_version < '3.10'
39- jaraco.functools>=4.4 .0; python_version >= '3.10'
39+ jaraco.functools>=4.6 .0; python_version >= '3.10'
4040jaraco.context>=6.1.1,<6.1.2; python_version < '3.10'
41- jaraco.context>=6.1.1 ; python_version >= '3.10'
42- jaraco.text>=4.2 .0
41+ jaraco.context>=6.1.2 ; python_version >= '3.10'
42+ jaraco.text>=4.3 .0
4343Jinja2>=3.1.6
4444jmespath>=1.1.0
4545looseversion
46- lxml>=6.1.1 ; sys_platform == 'win32'
46+ lxml>=6.1.3 ; sys_platform == 'win32'
4747MarkupSafe>=3.0.3; python_version < '3.14'
4848MarkupSafe>=3.0.3,<4.0.0; python_version >= '3.14'
4949more-itertools>=10.8.0,<11.0.0; python_version < '3.10'
5050more-itertools>=11.1.0; python_version >= '3.10'
5151# msgpack 1.2.1 drops Python 3.9; keep the last 3.9-compatible release there.
5252msgpack>=1.1.2,<1.2.1 ; python_version < '3.10'
53- msgpack>=1.2.1 ; python_version >= '3.10'
53+ msgpack>=1.2.2 ; python_version >= '3.10'
5454# multidict 6.0.4 fails to source-build under clang 17+ with strict int/pointer
5555# conversion checks (macOS 15 onedir builds compile from sdist via
5656# --no-binary=:all:). 6.6+ fixed the C source compatibility.
57- multidict>=6.6 .0
57+ multidict>=6.8 .0
5858# opentelemetry 1.43.0 (and exporter-prometheus 0.64b0) drop Python 3.9; keep
5959# the last 3.9-compatible releases there and let py>=3.10 float forward.
6060opentelemetry-api>=1.41.1,<1.43.0; python_version < '3.10'
61- opentelemetry-api>=1.41.1 ; python_version >= '3.10'
61+ opentelemetry-api>=1.44.0 ; python_version >= '3.10'
6262opentelemetry-sdk>=1.41.1,<1.43.0; python_version < '3.10'
63- opentelemetry-sdk>=1.41.1 ; python_version >= '3.10'
63+ opentelemetry-sdk>=1.44.0 ; python_version >= '3.10'
6464opentelemetry-exporter-otlp-proto-http>=1.41.1,<1.43.0; python_version < '3.10'
65- opentelemetry-exporter-otlp-proto-http>=1.41.1 ; python_version >= '3.10'
65+ opentelemetry-exporter-otlp-proto-http>=1.44.0 ; python_version >= '3.10'
6666opentelemetry-exporter-prometheus>=0.62b1,<0.64b0; python_version < '3.10'
67- opentelemetry-exporter-prometheus>=0.62b1 ; python_version >= '3.10'
67+ opentelemetry-exporter-prometheus>=0.65b0 ; python_version >= '3.10'
6868# xxhash 3.8.0 drops Python 3.9; keep the last 3.9-compatible release there.
6969xxhash>=3.7.0,<3.8.0; python_version < '3.10'
70- xxhash>=3.7.0 ; python_version >= '3.10'
70+ xxhash>=4.0.1 ; python_version >= '3.10'
7171# Packaging 24.1 imports annotations from __future__ which breaks salt ssh
7272# tests on target hosts with older python versions.
73- packaging>=26.2 ; python_version < '3.11'
73+ packaging>=26.3 ; python_version < '3.11'
7474packaging==24.0; python_version >= '3.11' and python_version < '3.14'
7575packaging>=26.0,<27.0; python_version >= '3.14'
7676psutil<6.0.0; python_version <= '3.9'
77- psutil>=5.0.0 ; python_version >= '3.10'
77+ psutil>=7.2.2 ; python_version >= '3.10'
7878pyasn1>=0.6.4
7979pycparser>=2.23,<3.0; python_version < '3.10'
8080pycparser>=3.0; python_version >= '3.10'
@@ -96,28 +96,28 @@ pywin32>=312; sys_platform == 'win32'
9696pycryptodomex>=3.23.0
9797PyYAML>=6.0.3
9898requests>=2.32.5; python_version < '3.10'
99- requests<2.32 .0 ; python_version >= '3.10' and python_version < '3.11'
99+ requests<2.35 .0 ; python_version >= '3.10' and python_version < '3.11'
100100requests>=2.34.2 ; python_version >= '3.11'
101101setproctitle>=1.3.7
102102timelib>=0.3.0; python_version < '3.11'
103103timelib>=0.3.0; python_version >= '3.11'
104- tornado>=6.5.6
105- truststore>=0.10.0 ; python_version >= "3.10"
104+ tornado>=6.5.10
105+ truststore>=0.10.4 ; python_version >= "3.10"
106106# Python 3.9 stays on urllib3 1.26.x because botocore on py3.9 hard
107107# requires urllib3 < 2 and Salt 3008.x still ships py3.9 lockfiles.
108108# The Python 3.10+ floor carries the urllib3 2.6.3 CVE backports
109109# (CVE-2025-66418, CVE-2026-21441).
110110urllib3>=1.26.20,<2.0.0; python_version < '3.10'
111- urllib3>=2.7 .0; python_version >= '3.10'
111+ urllib3>=2.8 .0; python_version >= '3.10'
112112# virtualenv 21.5.1 drops Python 3.9; keep the last 3.9-compatible release there.
113113virtualenv>=21.4.2,<21.5.1; python_version < '3.10'
114- virtualenv>=21.4.2 ; python_version >= '3.10'
114+ virtualenv>=21.7.10 ; python_version >= '3.10'
115115# Transitive of virtualenv; some uv resolver caches pin a stale 3.25
116116# version that conflicts with the CI floor of 3.29.1 on Python 3.10+.
117- filelock>=3.29.1 ; python_version >= '3.10'
117+ filelock>=3.32.7 ; python_version >= '3.10'
118118filelock>=3.19.1,<3.29.0; python_version < '3.10'
119119wmi>=1.5.1; sys_platform == 'win32'
120120xmltodict>=1.0.4; sys_platform == 'win32'
121121# zipp 4.1.0 drops Python 3.9; keep the last 3.9-compatible release there.
122122zipp>=3.23.1,<4.1.0; python_version < '3.10'
123- zipp>=3.23.1 ; python_version >= '3.10'
123+ zipp>=4.1.0 ; python_version >= '3.10'
0 commit comments