Skip to content

Build(deps): bump oauthlib from 3.3.1 to 4.0.0 in /docker/panw-iot - #47078

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/docker/panw-iot/oauthlib-4.0.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/docker/panw-iot/oauthlib-4.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps oauthlib from 3.3.1 to 4.0.0.

Release notes

Sourced from oauthlib's releases.

4.0.0

Introduction

The release 4.0.0 defines the foundation that enables AI contributions and will improve the maintenance of oauthlib by using AI agents, skills, code for both contributors and maintainers. It includes devcontainer, skills and cleanup of instructions.

What's Changed

Important: this release contains 2 breaking changes. See CHANGELOG.rst for details:

  • Removed JSONP support from token revocation endpoint (#951)
  • Client authentication validation reorganized across grants (#919, #920): the grant_type parameter is now validated before client authentication.

New Contributors

Full Changelog: oauthlib/oauthlib@v3.3.1...v4.0.0

Changelog

Sourced from oauthlib's changelog.

4.0.0 (2026-09-28):

OAuth2.0 Provider:

  • Breaking: #951: Removed JSONP support from token revocation endpoint. JSONP has been superseded by CORS for cross-origin requests. The enable_jsonp parameter has been removed from RevocationEndpoint and the callback parameter has been removed from prepare_token_revocation_request.
  • Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client.
  • #963: Improved PKCE code comparison

Misc:

  • #904: Stop installing examples into site-packages.
  • #930: Add devcontainer, Add Python3.14, Python3.14t.
  • #931: Fix ruff checks about unused variables.
  • #932: Dropped EOL Python 3.8 from CI.
  • #934: Pre-commit hooks autoupdate.
  • #938: Fix typos discovered by typos.
  • Add OAuthLib Maintainer agent for automated issue/PR triage and release management.
Commits
  • 145a9a4 Release 4.0.0: clarify changelog breaking changes and reformat entries
  • c8344d6 Update CHANGELOG.rst
  • e172830 Release 4.0.0: bump version to 4.0.0 and update changelog
  • 40b0ab5 Merge pull request #963 from oauthlib/ft/pkcecode
  • 1b68cea Merge pull request #920 from hekhuisk/validate-client-authentication
  • c951a1d Organized validate_client functions for all grant to avoid mistake in grnat i...
  • 74664d3 Improve PKCE code comparison
  • 9859b05 Merge pull request #950 from oauthlib/feature/3.4.0-maintainer-agent
  • 9bf9b97 Merge branch 'master' into feature/3.4.0-maintainer-agent
  • 1ba7429 Clarify agent instructions
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [oauthlib](https://github.com/oauthlib/oauthlib) from 3.3.1 to 4.0.0.
- [Release notes](https://github.com/oauthlib/oauthlib/releases)
- [Changelog](https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst)
- [Commits](oauthlib/oauthlib@v3.3.1...v4.0.0)

---
updated-dependencies:
- dependency-name: oauthlib
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 1, 2026
@content-bot

Copy link
Copy Markdown
Contributor

Docker Image Ready - Dev

Docker automatic build has deployed your docker image: devdemisto/panw-iot:1.0.0.13465214
It is available now on docker hub at: https://hub.docker.com/r/devdemisto/panw-iot/tags
Get started by pulling the image:

docker pull devdemisto/panw-iot:1.0.0.13465214

Docker Metadata

  • Image Size: 129.93M
  • Image ID: sha256:c16ac7d37f39065a568b4a9bef85fd38b1cd4b9c96743f1fdd907145c0af094f
  • Created: 2026-10-01T14:22:47.01832341Z
  • Arch: linux/amd64
  • Command: ["python3"]
  • Environment:
    • PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
    • LANG=C.UTF-8
    • GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305
    • PYTHON_VERSION=3.12.14
    • PYTHON_SHA256=5c8462af5790baf43a321a1559dbe0db06d1be4300fb85fb53c40060668e548a
    • DOCKER_IMAGE=devdemisto/panw-iot:1.0.0.13465214
  • Labels:
    • io.buildah.version:1.37.5
    • org.opencontainers.image.authors:Demisto <containers@demisto.com>
    • org.opencontainers.image.revision:53640377e24439903ed56a68599f463c3a445e8f
    • org.opencontainers.image.version:1.0.0.13465214
    • panw.builtby.pipeline:12344622
    • panw.builtby.project:xdr/cortex-content/dockerfiles
    • panw.builtby.template:build-scan-publish

@content-bot

Copy link
Copy Markdown
Contributor

🔍 AI Triage Report Available

An automated triage report has been generated for this pipeline.

Status: failed
Report ID: 6bb5d1fd25158350

📋 Triage Report
💡 Resolutions are available in the full report.

⚠️ AI-generated triage. Validate before acting.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant