22# Multiple entries for the same package (with different version constraints) are grouped together.
33
44aiohttp>=3.13.5,<3.14.0; python_version < '3.10'
5- aiohttp>=3.14.2 ; python_version >= '3.10'
6- certifi>=2026.5.20
7- cffi>=2.0.0
5+ aiohttp>=3.14.3 ; python_version >= '3.10'
6+ certifi>=2026.7.22
7+ cffi>=2.1.1
88# cheroot 8.5.2 fails to build with modern setuptools due to setuptools_scm_git_archive dependency
99cheroot>=11.1.2
1010cherrypy>=18.10.0
1111# We need contextvars for salt-ssh
1212contextvars
13- croniter!=0.3.22,>=6.2.2 ; sys_platform != 'win32'
13+ croniter!=0.3.22,>=6.2.4 ; sys_platform != 'win32'
1414# cryptography 48.0.0 drops support for Python 3.9.0 and 3.9.1
1515# (only >3.9.1 is accepted), but the py3.9 lock files are compiled
1616# with --python-version=3.9 which includes those releases. Cap at the
@@ -29,45 +29,45 @@ cryptography>=48.0.1; python_version >= '3.10' and sys_platform != 'win32'
2929distro>=1.9.0
3030frozenlist>=1.8.0; python_version < '3.11'
3131frozenlist>=1.5.0; python_version >= '3.11'
32- gitpython>=3.1.59
32+ gitpython>=3.1.62
3333immutables>=0.21
3434importlib-metadata>=8.7.0
3535# jaraco.functools 4.5.0 and jaraco.context 6.1.2 drop Python 3.9; keep the
3636# last 3.9-compatible releases there and let py>=3.10 float forward.
3737jaraco.functools>=4.4.0,<4.5.0; python_version < '3.10'
38- jaraco.functools>=4.4 .0; python_version >= '3.10'
38+ jaraco.functools>=4.6 .0; python_version >= '3.10'
3939jaraco.context>=6.1.1,<6.1.2; python_version < '3.10'
40- jaraco.context>=6.1.1 ; python_version >= '3.10'
41- jaraco.text>=4.2 .0
40+ jaraco.context>=6.1.2 ; python_version >= '3.10'
41+ jaraco.text>=4.3 .0
4242Jinja2>=3.1.6
4343jmespath>=1.1.0
4444looseversion
45- lxml>=6.1.1 ; sys_platform == 'win32'
45+ lxml>=6.1.3 ; sys_platform == 'win32'
4646MarkupSafe<4.0.0
4747# multidict 6.0.4 fails to source-build under clang 17+ with strict int/pointer
4848# conversion checks (macOS 15 onedir builds compile from sdist via
4949# --no-binary=:all:). 6.6+ fixed the C source compatibility.
50- multidict>=6.6 .0
50+ multidict>=6.8 .0
5151# msgpack 1.2.1 drops Python 3.9; keep the last 3.9-compatible release there.
5252msgpack>=1.1.2,<1.2.1; python_version < '3.10'
53- msgpack>=1.2.0 ; python_version >= '3.10'
53+ msgpack>=1.2.2 ; python_version >= '3.10'
5454# Packaging 24.1+ imports annotations from __future__ which breaks
5555# salt-ssh on target hosts with older Python versions (Amazon Linux 2
5656# still ships Python 3.7). 26.x additionally uses positional-only
5757# `/` parameter syntax which is a SyntaxError on Python <3.8. Keep at
5858# 24.0 to preserve salt-ssh compatibility against legacy target
5959# Pythons; salt 3006.x still promises this matrix.
60- packaging==24.0
60+ packaging==26.3
6161psutil<6.0.0; python_version <= '3.9'
62- psutil>=5.0.0 ; python_version >= '3.10'
62+ psutil>=7.2.2 ; python_version >= '3.10'
6363# pymssql 2.3.12+ dropped win32 (32-bit Windows) wheels; salt 3006.x
6464# still builds a Windows x86 onedir, so pin to the last release that
6565# ships cp3X-win32 wheels.
66- pymssql==2.3.11 ; sys_platform == 'win32'
66+ pymssql==2.4.1 ; sys_platform == 'win32'
6767pymysql>=1.2.0; sys_platform == 'win32'
6868# pyopenssl 26.2 dropped X509Extension and add_extensions(); salt/modules/tls.py
6969# now guards the missing symbol and lets the extension feature degrade cleanly.
70- pyopenssl>=26.0 .0
70+ pyopenssl>=26.4 .0
7171python-dateutil>=2.9.0.post0
7272python-gnupg>=0.5.6
7373# pythonnet 3.1.0 drops Python 3.9; keep the last 3.9-compatible release there.
@@ -83,36 +83,36 @@ setproctitle>=1.3.7
8383# pyzmq 27 dropped its tornado runtime dep; pyzmq.eventloop submodules
8484# (zmqstream, future) still import tornado.ioloop at module load. Pin
8585# tornado explicitly so onedir lockfiles keep shipping it.
86- tornado>=6.5.5
86+ tornado>=6.5.10
8787# Python 3.9 stays on urllib3 1.26.x because botocore on py3.9 hard
8888# requires urllib3 < 2 and Salt 3006.x still builds a py3.9 onedir.
8989# The Python 3.10+ floor carries the urllib3 2.6.3 CVE backports
9090# (CVE-2025-66418, CVE-2026-21441).
9191urllib3>=1.26.20,<2.0.0; python_version < '3.10'
92- urllib3>=2.7 .0; python_version >= '3.10'
92+ urllib3>=2.8 .0; python_version >= '3.10'
9393# virtualenv 21.5.1 drops Python 3.9; keep the last 3.9-compatible release there.
9494virtualenv>=21.4.2,<21.5.1; python_version < '3.10'
95- virtualenv>=21.4.2 ; python_version >= '3.10'
95+ virtualenv>=21.7.10 ; python_version >= '3.10'
9696# Transitive of virtualenv; some uv resolver caches pin a stale 3.25
9797# version that conflicts with the CI floor of 3.29.1 on Python 3.10+.
98- filelock>=3.29.1 ; python_version >= '3.10'
98+ filelock>=3.32.7 ; python_version >= '3.10'
9999filelock>=3.19.1,<3.29.0; python_version < '3.10'
100100wmi>=1.5.1; sys_platform == 'win32'
101101xmltodict>=1.0.4; sys_platform == 'win32'
102102# zipp 4.1.0 drops Python 3.9; keep the last 3.9-compatible release there.
103103zipp>=3.23.1,<4.1.0; python_version < '3.10'
104- zipp>=3.23.1 ; python_version >= '3.10'
104+ zipp>=4.1.0 ; python_version >= '3.10'
105105apache-libcloud>=3.8.0,<3.9.1; python_version < '3.10'
106106apache-libcloud>=3.9.1; python_version >= '3.10'
107- idna>=3.18
107+ idna>=3.19
108108# attrs and charset-normalizer are pulled in transitively by aiohttp/requests.
109109# Explicit floors on py>=3.10 keep them at the current CVE-patched line.
110110attrs>=26.1.0; python_version >= '3.10'
111- charset-normalizer>=3.4.7 ; python_version >= '3.10'
111+ charset-normalizer>=3.5.1 ; python_version >= '3.10'
112112# more-itertools 11.0.0 drops Python 3.9; keep the last 3.9-compatible release there.
113113more-itertools>=10.8.0,<11.0.0; python_version < '3.10'
114- more-itertools>=10.8 .0; python_version >= '3.10'
114+ more-itertools>=11.1 .0; python_version >= '3.10'
115115pyasn1>=0.6.4
116116# pycparser 3.0 drops Python 3.9; keep the last 3.9-compatible release there.
117117pycparser>=2.23,<3.0; python_version < '3.10'
118- pycparser>=2.23 ; python_version >= '3.10'
118+ pycparser>=3.0 ; python_version >= '3.10'
0 commit comments