Skip to content

chore(deps): Bump cedarpy from 4.12.0 to 4.12.1 - #212

Merged
imran-siddique merged 1 commit into
mainfrom
dependabot/pip/cedarpy-4.12.1
Sep 28, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
dependabot/pip/cedarpy-4.12.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps cedarpy from 4.12.0 to 4.12.1.

Release notes

Sourced from cedarpy's releases.

cedarpy v4.12.1

Patch release on the Cedar 4.12.0 engine line.

Fixed

  • is_authorized and is_authorized_batch now say why a request could not be built. A context that Cedar rejects (a JSON null, a float, a record that does not match the action's schema) produced the single diagnostic failed to parse schema from request, which hid the cause and named a schema even when none was passed. The diagnostic is now failed to build request: <cause>, for example failed to build request: while parsing context, found a `null`; JSON `null`s are not allowed in Cedar. Diagnostics for a principal, action, or resource that fails to parse, and for entities that fail to parse, carry their cause the same way (#118). Thanks @​david-long1!

Full Changelog: k9securityio/cedar-py@v4.12.0...v4.12.1

Changelog

Sourced from cedarpy's changelog.

[4.12.1] - 2026-09-23

Fixed

  • is_authorized and is_authorized_batch now say why a request could not be built. A context that Cedar rejects (a JSON null, a float, a record that does not match the action's schema) produced the single diagnostic failed to parse schema from request, which hid the cause and named a schema even when none was passed. The diagnostic is now failed to build request: <cause>, for example failed to build request: while parsing context, found a `null`; JSON `null`s are not allowed in Cedar. Diagnostics for a principal, action, or resource that fails to parse, and for entities that fail to parse, carry their cause the same way (#118). Thanks @​david-long1!
Commits
  • 1a8a275 Merge pull request #119 from k9securityio/release/4.12.1
  • 148ecd0 release: bump version to 4.12.1
  • 6c6cdbc Merge pull request #118 from david-long1/fix/request-build-error-chain
  • a162ae2 docs: credit @​david-long1 in the CHANGELOG entry for #118
  • ac36124 fix: report the cause when an authorization request cannot be built
  • dd6861e chore(benchmark): move the regression baseline to v4.12.0
  • 3d7b88f test(benchmark): capture v4.12.0 into the historical record
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cedarpy](https://github.com/k9securityio/cedar-py) from 4.12.0 to 4.12.1.
- [Release notes](https://github.com/k9securityio/cedar-py/releases)
- [Changelog](https://github.com/k9securityio/cedar-py/blob/main/CHANGELOG.md)
- [Commits](k9securityio/cedar-py@v4.12.0...v4.12.1)

---
updated-dependencies:
- dependency-name: cedarpy
  dependency-version: 4.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026
@dependabot
dependabot Bot requested review from a team, carloshvp and zohebk8s as code owners September 28, 2026 19:06
@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency update, CI green.

@imran-siddique
imran-siddique merged commit d1edb55 into main Sep 28, 2026
16 of 17 checks passed
@imran-siddique
imran-siddique deleted the dependabot/pip/cedarpy-4.12.1 branch September 28, 2026 19:41
imran-siddique added a commit that referenced this pull request Sep 28, 2026
….12.1

Dependabot compiled requirements/dev.txt without --universal, dropping the
win32 colorama pin that bandit needs, so every test leg failed under
--require-hashes. #212 bumped cedarpy in the .in files but left both locks
at 4.12.0. Regenerated both with the command in each file's header.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
imran-siddique added a commit that referenced this pull request Sep 28, 2026
* chore(deps-dev): Bump ruff from 0.16.8 to 0.16.9

Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.8 to 0.16.9.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix(deps): regenerate locks universally for ruff 0.16.9 and cedarpy 4.12.1

Dependabot compiled requirements/dev.txt without --universal, dropping the
win32 colorama pin that bandit needs, so every test leg failed under
--require-hashes. #212 bumped cedarpy in the .in files but left both locks
at 4.12.0. Regenerated both with the command in each file's header.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants