<feed xmlns='http://www.w3.org/2005/Atom'>
<title>pyvyos.git/.github/workflows/python-pr-validation.yml, branch dependabot/github_actions/pypa/gh-action-pypi-publish-1.14.2</title>
<subtitle>Python SDK for interacting with VyOS API (mirror of https://github.com/vyos-contrib/pyvyos.git)
</subtitle>
<id>https://git.amelek.net/vyos-contrib/pyvyos.git/atom?h=dependabot%2Fgithub_actions%2Fpypa%2Fgh-action-pypi-publish-1.14.2</id>
<link rel='self' href='https://git.amelek.net/vyos-contrib/pyvyos.git/atom?h=dependabot%2Fgithub_actions%2Fpypa%2Fgh-action-pypi-publish-1.14.2'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/'/>
<updated>2026-07-26T13:55:50+00:00</updated>
<entry>
<title>Merge pull request #49 from vyos-contrib/dependabot/github_actions/actions/checkout-7.0.0</title>
<updated>2026-07-26T13:55:50+00:00</updated>
<author>
<name>Roberto Bertó</name>
<email>463349+robertoberto@users.noreply.github.com</email>
</author>
<published>2026-07-26T13:55:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=51b2625d8a4f376b2d7c80bb022f7647e7f80b40'/>
<id>urn:sha1:51b2625d8a4f376b2d7c80bb022f7647e7f80b40</id>
<content type='text'>
Bump actions/checkout from 6.0.2 to 7.0.0</content>
</entry>
<entry>
<title>Merge pull request #47 from vyos-contrib/dependabot/github_actions/actions/setup-python-6.3.0</title>
<updated>2026-07-26T13:55:37+00:00</updated>
<author>
<name>Roberto Bertó</name>
<email>463349+robertoberto@users.noreply.github.com</email>
</author>
<published>2026-07-26T13:55:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=edab63680d70cc1347c7fce0f55175c39bdd7d1d'/>
<id>urn:sha1:edab63680d70cc1347c7fce0f55175c39bdd7d1d</id>
<content type='text'>
Bump actions/setup-python from 6.2.0 to 6.3.0</content>
</entry>
<entry>
<title>Bump actions/checkout from 6.0.2 to 7.0.0</title>
<updated>2026-07-01T12:48:53+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-01T12:48:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=56408f9cc868ce4e71fac63118efc35816c4ad23'/>
<id>urn:sha1:56408f9cc868ce4e71fac63118efc35816c4ad23</id>
<content type='text'>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;</content>
</entry>
<entry>
<title>Bump astral-sh/setup-uv from 8.1.0 to 8.2.0</title>
<updated>2026-07-01T12:48:49+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-01T12:48:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=cd23d2b960c79a4f965ccfdbf2b7b54165cddea2'/>
<id>urn:sha1:cd23d2b960c79a4f965ccfdbf2b7b54165cddea2</id>
<content type='text'>
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.1.0 to 8.2.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](https://github.com/astral-sh/setup-uv/compare/08807647e7069bb48b6ef5acd8ec9567f424441b...fac544c07dec837d0ccb6301d7b5580bf5edae39)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;</content>
</entry>
<entry>
<title>Bump actions/setup-python from 6.2.0 to 6.3.0</title>
<updated>2026-07-01T12:48:46+00:00</updated>
<author>
<name>dependabot[bot]</name>
<email>49699333+dependabot[bot]@users.noreply.github.com</email>
</author>
<published>2026-07-01T12:48:46+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=32210137c1609e3a6fa5b3cf6b1e7e88a724b745'/>
<id>urn:sha1:32210137c1609e3a6fa5b3cf6b1e7e88a724b745</id>
<content type='text'>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] &lt;support@github.com&gt;</content>
</entry>
<entry>
<title>ci: pin actions by full commit SHA</title>
<updated>2026-05-19T06:14:08+00:00</updated>
<author>
<name>Roberto Bertó</name>
<email>463349+robertoberto@users.noreply.github.com</email>
</author>
<published>2026-05-19T06:14:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=6071528289e4a8b11a772433c33851136d30f133'/>
<id>urn:sha1:6071528289e4a8b11a772433c33851136d30f133</id>
<content type='text'>
Per OpenSSF Scorecard 'Pinned-Dependencies' guidance, third-party
GitHub Actions should be referenced by full commit SHA, not by tag.
Tags are mutable; a SHA is not.

Each pin keeps a '# vX.Y.Z' trailing comment so Dependabot can read
the current version and propose updates while still pinning by SHA.

- actions/checkout         de0fac2 # v6.0.2
- actions/setup-python     a309ff8 # v6.2.0
- astral-sh/setup-uv       0880764 # v8.1.0
- pypa/gh-action-pypi-publish  cef2210 # v1.14.0

This commit does not change pyvyos HTTP payloads, request handling, or
response parsing.
</content>
</entry>
<entry>
<title>ci: pin setup-uv to v8.1.0 (no floating v8 tag yet)</title>
<updated>2026-05-19T06:10:07+00:00</updated>
<author>
<name>Roberto Bertó</name>
<email>463349+robertoberto@users.noreply.github.com</email>
</author>
<published>2026-05-19T06:10:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=4080faf81dcfe248394643cfce14112f3346b62f'/>
<id>urn:sha1:4080faf81dcfe248394643cfce14112f3346b62f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>ci: bump actions off Node.js 20</title>
<updated>2026-05-19T06:08:52+00:00</updated>
<author>
<name>Roberto Bertó</name>
<email>463349+robertoberto@users.noreply.github.com</email>
</author>
<published>2026-05-19T06:08:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=62aa8b885e45ad9cd8f8ce5d2a48b4aeff82e502'/>
<id>urn:sha1:62aa8b885e45ad9cd8f8ce5d2a48b4aeff82e502</id>
<content type='text'>
GitHub deprecation notice: Node.js 20 will be removed from runners in
September 2026 and forced to Node 24 in June 2026. Pin to current
majors that already run on Node 24.

- actions/checkout@v4 -&gt; v6
- actions/setup-python@v5 -&gt; v6
- astral-sh/setup-uv@v3 -&gt; v8
- pypa/gh-action-pypi-publish@v1.13.0 -&gt; v1.14.0
- pre-commit/pre-commit-hooks@v5.0.0 -&gt; v6.0.0

This commit does not change pyvyos HTTP payloads, request handling, or
response parsing.
</content>
</entry>
<entry>
<title>ci: pin uv cache key to pyproject.toml</title>
<updated>2026-05-19T03:20:53+00:00</updated>
<author>
<name>Roberto Bertó</name>
<email>463349+robertoberto@users.noreply.github.com</email>
</author>
<published>2026-05-19T03:20:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=c5a2ae114835791de16c5b982632569377c39bfa'/>
<id>urn:sha1:c5a2ae114835791de16c5b982632569377c39bfa</id>
<content type='text'>
The matrix job in commit 7aa4989 left astral-sh/setup-uv@v3 with its
default cache fingerprint of "**/uv.lock". This repo is a library
and intentionally does not commit uv.lock (commit a2df706), so the
glob matches nothing and the action errors out.

Switch the fingerprint to pyproject.toml, the actual source of truth
for dependencies. Cache hits remain across PRs that don't touch
dependencies; cache invalidates on dependency changes.
</content>
</entry>
<entry>
<title>build: tighten runtime deps and lower Python floor to 3.11</title>
<updated>2026-05-19T03:06:11+00:00</updated>
<author>
<name>Roberto Bertó</name>
<email>463349+robertoberto@users.noreply.github.com</email>
</author>
<published>2026-05-19T03:06:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos-contrib/pyvyos.git/commit/?id=7aa4989061950a336287cd8b581813ccd60b1832'/>
<id>urn:sha1:7aa4989061950a336287cd8b581813ccd60b1832</id>
<content type='text'>
- requires-python: &gt;=3.13 -&gt; &gt;=3.11. The code does not use any
  3.13-only feature. typing.List/Dict/Union/Optional throughout, no
  PEP 695 generics, no Self, no match. Classifiers updated to advertise
  3.11/3.12/3.13.
- runtime dependencies: trim to requests only.
  - python-dotenv is only used by examples; move to the dev extra.
  - urllib3 is never imported by pyvyos directly; it remains available
    transitively through requests.
- pre-existing dev tooling (pytest, pytest-cov, pytest-env) untouched.
- CI: PR validation runs on a 3.11/3.12/3.13 matrix.
- README: reword the Python requirement.
- .python-version: 3.13.0 -&gt; 3.13 (CI uses the matrix).
- Wheel build verified to include pyvyos/py.typed and to declare
  Requires-Python: &gt;=3.11 with requests as the only runtime requirement.
</content>
</entry>
</feed>
