Skip to content

Update dependency compliance-trestle to v3.12.3#156

Open
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
v1.0from
konflux/mintmaker/v1.0/compliance-trestle-3.x
Open

Update dependency compliance-trestle to v3.12.3#156
red-hat-konflux-kflux-prd-rh02[bot] wants to merge 1 commit into
v1.0from
konflux/mintmaker/v1.0/compliance-trestle-3.x

Conversation

@red-hat-konflux-kflux-prd-rh02

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot commented May 11, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
compliance-trestle ==3.8.1==3.12.3 age confidence

Release Notes

oscal-compass/compliance-trestle (compliance-trestle)

v3.12.3

Compare Source

v3.12.3 (2026-05-28)

This release is published under the Apache-2.0 License.

Bug Fixes
  • ci: Prevent maintenance branch releases from being marked latest (d52d24a)

Detailed Changes: v3.12.2...v3.12.3

v3.12.2

Compare Source

v3.12.2 (2026-05-21)

This release is published under the Apache-2.0 License.


Detailed Changes: v3.12.1...v3.12.2

v3.12.1

Compare Source

v3.12.1 (2026-05-11)

This release is published under the Apache-2.0 License.

Bug Fixes
  • Add cross-platform install docs and conventional-pr make target (#​2202, 4444dc2)

  • Address PR review comments on multi-train release support (#​2201, 47ecd1d)

  • Apply mdformat to maintenance_releases.md (#​2201, 47ecd1d)

  • Convert negative security checks to positive allowlists (#​2201, 47ecd1d)

  • Correct act install SHA to commit SHA (not tag object SHA) (#​2201, 47ecd1d)

  • Pin act install to v0.2.87 and fix mdformat table padding (#​2202, 4444dc2)

  • Pre-configure act image to avoid interactive prompt in CI (#​2201, 47ecd1d)

  • Upgrade cryptography to 46.0.7 (SNYK-PYTHON-CRYPTOGRAPHY-15809188, SNYK-PYTHON-CRYPTOGRAPHY-15953315) (e14ffd0)

Continuous Integration
  • Add act-based local workflow testing (#​2202, 4444dc2)

  • Add act-based local workflow testing and CI validation (#​2202, 4444dc2)

  • Add multi-train release support for maintenance branches (#​2201, 47ecd1d)

  • Add Snyk exception for paramiko cryptographic algorithm issue (#​2218, b4c9d94)

  • Fix merge commit validation and document release environment setup (#​2218, b4c9d94)


Detailed Changes: v3.12.0...v3.12.1

v3.12.0

Compare Source

Bug Fixes
Chores
Documentation
Features

v3.11.0

Compare Source

Bug Fixes
Chores
Features
Refactoring

v3.10.4

Compare Source

Bug Fixes

v3.10.3

Compare Source

Bug Fixes

v3.10.2

Compare Source

Bug Fixes

v3.9.3

Compare Source

Bug Fixes

v3.9.2

Compare Source

Note: this entry added manually due to python-semantic-version upgrade issue

Bug Fixes

Add comment (#​1756, 929ee37)

Add newline to workflow file (#​1878, 82bc3bb)

Bad part name/id when generate/assemble markdown (#​1928, 428d880)

Do not continue on error in synk scan job (#​1878, 82bc3bb)

Removes unnecessary line (#​1878, 82bc3bb)

Unit test execution in PyCharm (#​1756, 929ee37)

Unit test execution in PyCharm (#​1755) (#​1756, 929ee37)

Update new tests for cwd (#​1756, 929ee37)

deps: Bump actions/cache from 4.2.3 to 4.2.4 (#​1930, 719eb72)

deps: Bump actions/cache from 4.2.3 to 4.2.4 (#​1927, 4470d53)

deps: Bump actions/checkout from 4.2.2 to 5.0.0 (#​1932, 3fb4ccc)

deps: Bump actions/checkout from 4.2.2 to 5.0.0 (#​1923, 98bd38f)

deps: Bump actions/create-github-app-token from 1.12.0 to 2.1.1 (#​1915, 7211962)

deps: Bump actions/download-artifact from 4.2.1 to 5.0.0 (#​1911, 9acb8e9)

deps: Bump actions/stale from 9.1.0 to 10.0.0 (#​1931, 2a048f2)

deps: Bump cryptography from 44.0.2 to 45.0.6 (#​1910, 9cec58e)

deps: Bump cryptography from 45.0.6 to 45.0.7 (#​1924, 2a09b91)

deps: Bump datamodel-code-generator[http] from 0.25.3 to 0.33.0 (#​1918, b655f46)
deps: Bump github/codeql-action from 3.28.13 to 3.29.11 (#​1916, 3950083)

deps: Bump github/codeql-action from 3.29.11 to 3.30.1 (#​1933, 5a9e53d)

deps: Bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#​1925, 9d7c5ce)

deps: Bump paramiko from 3.5.0 to 4.0.0 (#​1909, a9bfc17)

deps: Bump pypa/gh-action-pypi-publish from 1.12.4 to 1.13.0 (#​1929, adb68ef)

deps: Bump python-semantic-release/python-semantic-release (#​1912, 94826da)

deps: Bump SonarSource/sonarcloud-github-action (#​1926, 3d6eddb)

deps: Bump SonarSource/sonarcloud-github-action (#​1884, 823bf68)

deps: Bump urllib3 from 1.26.19 to 2.5.0 (#​1897, 2fe4fb6)

Chores

Add .synk file with pending license exceptions (#​1878, 82bc3bb)

Add slash at the end of fedramp link (#​1878, 82bc3bb)

Revert docs change (#​1878, 82bc3bb)

Update .snyk to correct paramiko license (#​1878, 82bc3bb)

Update .snyk to include pending exception (#​1878, 82bc3bb)

Continuous Integration

Add snyk license scanning to PR CI workflow (#​1878, 82bc3bb)

Documentation

Update FedRAMP doc templates link (#​1878, 82bc3bb)

v3.9.1

Compare Source

Build
  • build(deps): bump actions/setup-python from 5.5.0 to 5.6.0 (#​1865)

Bumps actions/setup-python from 5.5.0 to 5.6.0.


updated-dependencies:

  • dependency-name: actions/setup-python
    dependency-version: 5.6.0
    dependency-type: direct:production
    update-type: version-update:semver-minor
    ...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.github.com> (c79f7bc)

  • build(deps): update cmarkgfm requirement (#​1757)

Updates the requirements on cmarkgfm to permit the latest version.


updated-dependencies:

  • dependency-name: cmarkgfm
    dependency-type: direct:production
    ...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.github.com>
Co-authored-by: Jennifer Power <barnabei.jennifer@gmail.com> (e1430c0)

Chore
  • chore: Merge back version tags and changelog into develop. (03c5beb)
Ci
  • ci: updates for failing CI jobs (#​1886)

  • docs: updates python-semantic-release link in guide

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>

  • fix: updates ignore comments for mypy version 1.16.0

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>


Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com> (c96da54)

Documentation
  • docs: fixes markdown formatting in docs (#​1893)

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com> (df4091c)

Fix
  • fix: removes reviewers from dependabot configuration (#​1894)

The field is no longer supported. CODEOWNERS will be used.

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com> (ba41c68)

  • fix: prefix dependabot messages with fix (#​1872)

Fixes #​1788

Signed-off-by: d10n <d10n@redhat.com>
Co-authored-by: Jennifer Power <barnabei.jennifer@gmail.com> (357f8ca)

  • fix: website documentation for using mike (#​1817)

  • fix: website documentation for using mike

Signed-off-by: Chris Butler <chris.butler@redhat.com>

  • fix: typofix in website.md

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>


Signed-off-by: Chris Butler <chris.butler@redhat.com>
Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>
Co-authored-by: Jennifer Power <barnabei.jennifer@gmail.com> (9d9ff68)

Unknown
  • Merge pull request #​1899 from oscal-compass/develop

chore: Trestle release 3.9.1 (dc59ed5)

v3.9.0

Compare Source

Build
  • build(deps): bump cryptography from 43.0.3 to 44.0.2 (#​1830)

Bumps cryptography from 43.0.3 to 44.0.2.


updated-dependencies:

  • dependency-name: cryptography
    dependency-type: direct:production
    update-type: version-update:semver-major
    ...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.github.com> (61c0b95)

  • build(deps): bump actions/stale from 9.0.0 to 9.1.0 (#​1804)

Bumps actions/stale from 9.0.0 to 9.1.0.


updated-dependencies:

  • dependency-name: actions/stale
    dependency-type: direct:production
    update-type: version-update:semver-minor
    ...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@​users.noreply.github.com> (b7b5656)

Chore
  • chore: Merge back version tags and changelog into develop. (c578be8)
Ci
  • ci: adds actionlint workflow (#​1771)

  • ci: adds an actionlint workflow

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>

  • docs: adds steps for testing GH Actions in PR template

The steps are commented and can be uncommeted when changes
are to GitHub Actions workflows

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>

  • style: adds newline at the end of new files

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>

  • chore(deps): updates action image version to latest

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>


Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com> (95d5f71)

Documentation
  • docs: updates security insights location and content (#​1840)

  • docs: updates security insights location and content

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>

  • docs: fixes license expression of security insights

Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com>


Signed-off-by: Jennifer Power <barnabei.jennifer@gmail.com> (87c4f80)

Feature
  • feat: move dependencies from setup.cfg to pyproject.toml (#​1859)

  • feat: add content to pyproject.toml for parity with setup.cfg

Signed-off-by: George Vauter <gvauter@redhat.com>

  • remove project metadata and deps from setup.cfg

Signed-off-by: George Vauter <gvauter@redhat.com>

  • fix: replace deprecated license metadata

Signed-off-by: George Vauter <gvauter@redhat.com>

  • fix: remove experimental distutils section from pyproject

Signed-off-by: George Vauter <gvauter@redhat.com>


Signed-off-by: George Vauter <gvauter@redhat.com> (2779edf)

Fix
  • fix: add the score card workflow and badge (#​1854)

Signed-off-by: thealberto <barbaro.alberto@gmail.com>
Co-authored-by: Jennifer Power <barnabei.jennifer@gmail.com> (7ec8006)

  • fix: OSCAL Property must have value field (#​1839)

Signed-off-by: Lou DeGenaro <lou.degenaro@gmail.com> (b243c4a)

Unknown
  • Merge pull request #​1863 from oscal-compass/develop

chore: Trestle Release (ae6d100)

  • [StepSecurity] ci: Harden GitHub Actions (#​1853)

Signed-off-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: StepSecurity Bot <bot@stepsecurity.io>
Co-authored-by: Jennifer Power <barnabei.jennifer@gmail.com> (5bdcd51)


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/v1.0/compliance-trestle-3.x branch from 1e8475d to 550d1e8 Compare May 21, 2026 20:07
@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot changed the title Update dependency compliance-trestle to v3.12.1 Update dependency compliance-trestle to v3.12.2 May 21, 2026
Signed-off-by: red-hat-konflux-kflux-prd-rh02 <190377777+red-hat-konflux-kflux-prd-rh02[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot force-pushed the konflux/mintmaker/v1.0/compliance-trestle-3.x branch from 550d1e8 to d04cccb Compare May 28, 2026 08:07
@red-hat-konflux-kflux-prd-rh02 red-hat-konflux-kflux-prd-rh02 Bot changed the title Update dependency compliance-trestle to v3.12.2 Update dependency compliance-trestle to v3.12.3 May 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants