chore(deps-dev): bump jupyterlab from 4.5.8 to 4.5.9 - #11
Conversation
Bumps [jupyterlab](https://github.com/jupyterlab/jupyterlab) from 4.5.8 to 4.5.9. - [Release notes](https://github.com/jupyterlab/jupyterlab/releases) - [Changelog](https://github.com/jupyterlab/jupyterlab/blob/main/RELEASE.md) - [Commits](https://github.com/jupyterlab/jupyterlab/compare/@jupyterlab/lsp@4.5.8...@jupyterlab/lsp@4.5.9) --- updated-dependencies: - dependency-name: jupyterlab dependency-version: 4.5.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Closing: this repository binds paper and expansion artifacts to poetry.lock and pyproject.toml (they are release-critical fingerprinted paths in paper/results/manifest.json and paper/expansion/results/manifest.json), and CI additionally verifies the requirements/ exports match poetry.lock. A lock-only bump therefore always fails the drift gate and the provenance tests by design. Dependency updates land via a coordinated refresh instead: edit pyproject.toml, run scripts/update_dependency_locks.sh, regenerate both artifact releases from a clean source commit, and merge as a reviewed PR. This bump will be included in the next coordinated refresh. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps jupyterlab from 4.5.8 to 4.5.9.
Release notes
Sourced from jupyterlab's releases.
Commits
dd65403[ci skip] Publish 4.5.92693672Backport PR #18992: Fix hidden cells after moving collapsed headings (#19016)360c176Backport PR #18998 on branch 4.5.x (Fix toolbar popup row clipping in Safari)...e9db010Fixjupyter labextension buildcrash onwebpack ≥ 5.107(#19021)3b8428cBackport PR #19013 on branch 4.5.x (Forbid relative URLs in extensionmanager)...3c84a84Backport PR #19003 on branch 4.5.x (Fix XSS in extension manager's `homepage_...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.