<feed xmlns='http://www.w3.org/2005/Atom'>
<title>hutch-stats.git/uv.lock, branch dependabot/uv/alembic-1.18.5</title>
<subtitle>polls sourcehut activity, serves a contribution-calendar api.
</subtitle>
<id>http://git.krz.sh/krz/hutch-stats.git/atom?h=dependabot%2Fuv%2Falembic-1.18.5</id>
<link rel='self' href='http://git.krz.sh/krz/hutch-stats.git/atom?h=dependabot%2Fuv%2Falembic-1.18.5'/>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/'/>
<updated>2026-07-27T09:36:56+00:00</updated>
<entry>
<title>chore(deps): bump alembic from 1.18.4 to 1.18.5</title>
<updated>2026-07-27T09:36:56+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-27T09:36:56+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=a7a99e3feb8826afe8b557686808688083a4a42d'/>
<id>urn:sha1:a7a99e3feb8826afe8b557686808688083a4a42d</id>
<content type='text'>
Bumps [alembic](https://github.com/sqlalchemy/alembic) from 1.18.4 to 1.18.5.
- [Release notes](https://github.com/sqlalchemy/alembic/releases)
- [Changelog](https://github.com/sqlalchemy/alembic/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/alembic/commits)

---
updated-dependencies:
- dependency-name: alembic
  dependency-version: 1.18.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;</content>
</entry>
<entry>
<title>Merge pull request #5 from zerolabsco/dependabot/uv/pydantic-2.13.4</title>
<updated>2026-07-20T17:17:54+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-20T17:17:54+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=5d258a14f09f16b40f9007755b07ce123b524dd8'/>
<id>urn:sha1:5d258a14f09f16b40f9007755b07ce123b524dd8</id>
<content type='text'>
chore(deps): bump pydantic from 2.12.5 to 2.13.4</content>
</entry>
<entry>
<title>Merge pull request #1 from zerolabsco/dependabot/uv/apscheduler-3.11.3</title>
<updated>2026-07-20T17:16:42+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-20T17:16:42+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=8ab6265fd26ff95979b83cf68bfaa3efff3a564a'/>
<id>urn:sha1:8ab6265fd26ff95979b83cf68bfaa3efff3a564a</id>
<content type='text'>
chore(deps): bump apscheduler from 3.11.2 to 3.11.3</content>
</entry>
<entry>
<title>chore(deps): allow pytest 9 and upgrade to 9.1.1</title>
<updated>2026-07-20T17:13:25+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-20T17:13:25+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=3cbb408d83668d5c2d5b0bbccf548c832345c870'/>
<id>urn:sha1:3cbb408d83668d5c2d5b0bbccf548c832345c870</id>
<content type='text'>
Closes CVE-2025-71176 (tmpdir handling). Test-only dependency, never in
the runtime image.

Floor raised to 9.0.3 rather than just dropping the &lt;9.0 ceiling: with the
floor left at 8.2 a fresh resolve could still land on a vulnerable 8.x and
the advisory would stay open.
</content>
</entry>
<entry>
<title>chore(deps): bump pydantic from 2.12.5 to 2.13.4</title>
<updated>2026-07-20T17:04:53+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-20T17:04:53+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=1365b6522c3068e0bc39e5695c2bbf9f48394f51'/>
<id>urn:sha1:1365b6522c3068e0bc39e5695c2bbf9f48394f51</id>
<content type='text'>
Bumps [pydantic](https://github.com/pydantic/pydantic) from 2.12.5 to 2.13.4.
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/main/HISTORY.md)
- [Commits](https://github.com/pydantic/pydantic/compare/v2.12.5...v2.13.4)

---
updated-dependencies:
- dependency-name: pydantic
  dependency-version: 2.13.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;</content>
</entry>
<entry>
<title>chore(deps): upgrade starlette, mako, idna and pydantic-settings</title>
<updated>2026-07-20T16:59:47+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-07-20T16:59:47+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=084874158aa177757bb83e400bf1eb986b2b7e6c'/>
<id>urn:sha1:084874158aa177757bb83e400bf1eb986b2b7e6c</id>
<content type='text'>
Clears eight open Dependabot alerts. None were exploitable against this
service as written -- it exposes no form endpoints, mounts no StaticFiles,
never reads request.url, sets no secrets_dir, and runs on Linux while
several of the advisories are Windows-only -- but the bumps are cheap and
that analysis only holds until the surface changes.

starlette 1.0.0 -&gt; 1.3.1 resolves five advisories on its own and requires
fastapi 0.135.3 -&gt; 0.139.2 to satisfy its pin. Mako is a transitive
alembic dependency used only to scaffold migrations.

pytest is left at 8.4.2; its advisory is test-only and the fix would need
the &lt;9.0 constraint in pyproject.toml relaxed across a major version.
</content>
</entry>
<entry>
<title>chore(deps): bump apscheduler from 3.11.2 to 3.11.3</title>
<updated>2026-07-20T16:46:36+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-20T16:46:36+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=78133748520954f445748d5e0225cf9a55cc497b'/>
<id>urn:sha1:78133748520954f445748d5e0225cf9a55cc497b</id>
<content type='text'>
Bumps [apscheduler](https://github.com/agronholm/apscheduler) from 3.11.2 to 3.11.3.
- [Release notes](https://github.com/agronholm/apscheduler/releases)
- [Commits](https://github.com/agronholm/apscheduler/compare/3.11.2...3.11.3)

---
updated-dependencies:
- dependency-name: apscheduler
  dependency-version: 3.11.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;</content>
</entry>
<entry>
<title>fix: reduce sr.ht poll API load with cached repo discovery</title>
<updated>2026-04-12T02:32:49+00:00</updated>
<author>
<name>Christian Cleberg</name>
<email>hello@cleberg.net</email>
</author>
<published>2026-04-12T02:32:49+00:00</published>
<link rel='alternate' type='text/html' href='http://git.krz.sh/krz/hutch-stats.git/commit/?id=533866679755bd6e7a97cfa0f050eaa832b0b373'/>
<id>urn:sha1:533866679755bd6e7a97cfa0f050eaa832b0b373</id>
<content type='text'>
</content>
</entry>
</feed>
