dependabot[bot] opened a new pull request, #74325:
URL: https://github.com/apache/airflow/pull/74325

   Bumps the uv-security-updates group with 1 update in the /dev/breeze 
directory: [oauthlib](https://github.com/oauthlib/oauthlib).
   
   Updates `oauthlib` from 3.3.1 to 4.0.0
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/oauthlib/oauthlib/releases";>oauthlib's 
releases</a>.</em></p>
   <blockquote>
   <h2>4.0.0</h2>
   <h2>Introduction</h2>
   <p>The release 4.0.0 defines the foundation that enables AI contributions 
and will improve the maintenance of oauthlib by using AI agents, skills, code 
for both contributors and maintainers. It includes devcontainer, skills and 
cleanup of instructions.</p>
   <h2>What's Changed</h2>
   <p><strong>Important</strong>: this release contains 2 breaking changes. See 
CHANGELOG.rst for details:</p>
   <ul>
   <li>Removed JSONP support from token revocation endpoint (<a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/951";>#951</a>)</li>
   <li>Client authentication validation reorganized across grants (<a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/919";>#919</a>, <a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/920";>#920</a>):
   the <code>grant_type</code> parameter is now validated before client 
authentication.</li>
   </ul>
   <ul>
   <li>Replace pyenv with uv in documentation and tooling by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/910";>oauthlib/oauthlib#910</a></li>
   <li>Improve github action to publish package by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/915";>oauthlib/oauthlib#915</a></li>
   <li>Add pre-commit to run linters, formatters, etc. on code changes by <a 
href="https://github.com/cclauss";><code>@​cclauss</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/918";>oauthlib/oauthlib#918</a></li>
   <li>Fix client authentication for DeviceCodeGrant when getting a token by <a 
href="https://github.com/hekhuisk";><code>@​hekhuisk</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/920";>oauthlib/oauthlib#920</a></li>
   <li>Add project URLs to this project's PyPI page by <a 
href="https://github.com/Flimm";><code>@​Flimm</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/921";>oauthlib/oauthlib#921</a></li>
   <li>Fix a typo in ServiceApplicationClient docstring. by <a 
href="https://github.com/rafalkrupinski";><code>@​rafalkrupinski</code></a> in 
<a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/923";>oauthlib/oauthlib#923</a></li>
   <li>Correct grammar in function help by <a 
href="https://github.com/verhovsky";><code>@​verhovsky</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/924";>oauthlib/oauthlib#924</a></li>
   <li>Add Python 3.14 to the testing by <a 
href="https://github.com/cclauss";><code>@​cclauss</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/925";>oauthlib/oauthlib#925</a></li>
   <li>Initial python/uv/tox devcontainer by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/930";>oauthlib/oauthlib#930</a></li>
   <li>Fix ruff checks about unused variables by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/931";>oauthlib/oauthlib#931</a></li>
   <li>Drop EOL Python 3.8 from CI by <a 
href="https://github.com/auvipy";><code>@​auvipy</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/932";>oauthlib/oauthlib#932</a></li>
   <li>Set Open Collective username to 'oauthlib' by <a 
href="https://github.com/auvipy";><code>@​auvipy</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/933";>oauthlib/oauthlib#933</a></li>
   <li>pre-commit autoupdate 2026_02_21 by <a 
href="https://github.com/cclauss";><code>@​cclauss</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/934";>oauthlib/oauthlib#934</a></li>
   <li>Remove a trailing whitespace fo fix failing pre-commit by <a 
href="https://github.com/cclauss";><code>@​cclauss</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/935";>oauthlib/oauthlib#935</a></li>
   <li>Fix typos discovered by typos by <a 
href="https://github.com/cclauss";><code>@​cclauss</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/938";>oauthlib/oauthlib#938</a></li>
   <li>Add <code>resource</code> to Request._params by <a 
href="https://github.com/juannyG";><code>@​juannyG</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/942";>oauthlib/oauthlib#942</a></li>
   <li>Release 3.4.0: Add OAuthLib Maintainer agent by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/950";>oauthlib/oauthlib#950</a></li>
   <li>Remove JSONP support from token revocation by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/951";>oauthlib/oauthlib#951</a></li>
   <li>Improve PKCE code comparison by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/963";>oauthlib/oauthlib#963</a></li>
   <li>Release 4.0.0: bump and update changelog by <a 
href="https://github.com/JonathanHuot";><code>@​JonathanHuot</code></a> in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/976";>oauthlib/oauthlib#976</a></li>
   </ul>
   <h2>New Contributors</h2>
   <ul>
   <li><a href="https://github.com/hekhuisk";><code>@​hekhuisk</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/920";>oauthlib/oauthlib#920</a></li>
   <li><a href="https://github.com/Flimm";><code>@​Flimm</code></a> made their 
first contribution in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/921";>oauthlib/oauthlib#921</a></li>
   <li><a href="https://github.com/verhovsky";><code>@​verhovsky</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/924";>oauthlib/oauthlib#924</a></li>
   <li><a href="https://github.com/juannyG";><code>@​juannyG</code></a> made 
their first contribution in <a 
href="https://redirect.github.com/oauthlib/oauthlib/pull/942";>oauthlib/oauthlib#942</a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/oauthlib/oauthlib/compare/v3.3.1...v4.0.0";>https://github.com/oauthlib/oauthlib/compare/v3.3.1...v4.0.0</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst";>oauthlib's
 changelog</a>.</em></p>
   <blockquote>
   <h2>4.0.0 (2026-09-28):</h2>
   <p>OAuth2.0 Provider:</p>
   <ul>
   <li><strong>Breaking</strong>: <a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/951";>#951</a>: 
Removed JSONP support from token revocation endpoint.
   JSONP has been superseded by CORS for cross-origin requests.
   The <code>enable_jsonp</code> parameter has been removed from 
<code>RevocationEndpoint</code>
   and the <code>callback</code> parameter has been removed from
   <code>prepare_token_revocation_request</code>.</li>
   <li><strong>Breaking</strong>: <a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/919";>#919</a>, <a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/920";>#920</a>: Fixed 
<code>DeviceCodeGrant.validate_token_request</code>
   trying to authenticate public clients.
   Client authentication validation has been reorganized and is now shared
   across <code>AuthorizationCodeGrant</code>, <code>DeviceCodeGrant</code>, 
<code>RefreshTokenGrant</code>
   and <code>ResourceOwnerPasswordCredentialsGrant</code>: the 
<code>grant_type</code> parameter
   is validated before client authentication, so requests missing
   <code>grant_type</code> now return <code>400 invalid_request</code> instead 
of
   <code>401 invalid_client</code>.</li>
   <li><a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/963";>#963</a>: 
Improved PKCE code comparison</li>
   </ul>
   <p>Misc:</p>
   <ul>
   <li><a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/904";>#904</a>: Stop 
installing <code>examples</code> into <code>site-packages</code>.</li>
   <li><a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/930";>#930</a>: Add 
devcontainer, Add Python3.14, Python3.14t.</li>
   <li><a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/931";>#931</a>: Fix 
ruff checks about unused variables.</li>
   <li><a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/932";>#932</a>: 
Dropped EOL Python 3.8 from CI.</li>
   <li><a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/934";>#934</a>: 
Pre-commit hooks autoupdate.</li>
   <li><a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/938";>#938</a>: Fix 
typos discovered by typos.</li>
   <li>Add OAuthLib Maintainer agent for automated issue/PR triage and release
   management.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/145a9a4690cb4d9de30d15fcc2984e34c49df741";><code>145a9a4</code></a>
 Release 4.0.0: clarify changelog breaking changes and reformat entries</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/c8344d61492c7ae708cf378ecabab7ee6ab62812";><code>c8344d6</code></a>
 Update CHANGELOG.rst</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/e172830efd66a2dc1bb34b3bbbf8ee53036a9dac";><code>e172830</code></a>
 Release 4.0.0: bump version to 4.0.0 and update changelog</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950";><code>40b0ab5</code></a>
 Merge pull request <a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/963";>#963</a> from 
oauthlib/ft/pkcecode</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/1b68ceaae02fe62aeaaa3468a8f8082c73830a3a";><code>1b68cea</code></a>
 Merge pull request <a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/920";>#920</a> from 
hekhuisk/validate-client-authentication</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/c951a1d09f99f14e3240973fa83c4f4287d4753d";><code>c951a1d</code></a>
 Organized validate_client functions for all grant to avoid mistake in grnat 
i...</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/74664d3fe037a354e180e305135c6bab1747a6b0";><code>74664d3</code></a>
 Improve PKCE code comparison</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/9859b057ecc5d1ad42711af7d58ee471d708ea36";><code>9859b05</code></a>
 Merge pull request <a 
href="https://redirect.github.com/oauthlib/oauthlib/issues/950";>#950</a> from 
oauthlib/feature/3.4.0-maintainer-agent</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/9bf9b974e0797d2d03cba05854f46e314c730ba6";><code>9bf9b97</code></a>
 Merge branch 'master' into feature/3.4.0-maintainer-agent</li>
   <li><a 
href="https://github.com/oauthlib/oauthlib/commit/1ba7429ad79019289540fd7be27866d7e59f2564";><code>1ba7429</code></a>
 Clarify agent instructions</li>
   <li>Additional commits viewable in <a 
href="https://github.com/oauthlib/oauthlib/compare/v3.3.1...v4.0.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=oauthlib&package-manager=uv&previous-version=3.3.1&new-version=4.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore <dependency name> major version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
major version (unless you unignore this specific dependency's major version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name> minor version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
minor version (unless you unignore this specific dependency's minor version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name>` will close this group update PR and 
stop Dependabot creating any more for the specific dependency (unless you 
unignore this specific dependency or upgrade to it yourself)
   - `@dependabot unignore <dependency name>` will remove all of the ignore 
conditions of the specified dependency
   - `@dependabot unignore <dependency name> <ignore condition>` will remove 
the ignore condition of the specified dependency and ignore conditions
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/airflow/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to