dependabot[bot] opened a new pull request, #3227: URL: https://github.com/apache/sedona/pull/3227
Bumps the uv-dependencies group with 4 updates: [mkdocs-material](https://github.com/squidfunk/mkdocs-material), [prek](https://github.com/j178/prek), [geopandas](https://github.com/geopandas/geopandas) and [pydeck](https://github.com/visgl/deck.gl). Updates `mkdocs-material` from 9.7.6 to 9.7.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/squidfunk/mkdocs-material/releases">mkdocs-material's releases</a>.</em></p> <blockquote> <h2>mkdocs-material-9.7.7</h2> <blockquote> <p>[!WARNING]</p> <p><strong>Material for MkDocs is approaching end of life</strong></p> <p>Material for MkDocs is scheduled to reach end of life on November 5, 2026. Until then, maintenance is limited to critical bug fixes and security updates. After this date, the project will remain available on PyPI and GitHub, but no further maintenance is planned except in exceptional circumstances.</p> <p>For users looking for a long-term, actively developed successor, we're building <a href="https://zensical.org">Zensical</a> – a next-generation static site generator designed for technical documentation. If you're planning a new documentation project or evaluating your long-term options, we invite you to take a look.</p> <p>Organizations requiring support beyond this date are welcome to get in touch to discuss available options.</p> <p><a href="https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/">Read the full announcement on our blog</a></p> </blockquote> <h2>Changes</h2> <ul> <li>Fixed a DOM-based XSS vulnerability in search suggestions</li> </ul> <blockquote> <p>Thanks to <a href="https://github.com/p"><code>@p</code></a>- for responsibly reporting this issue.</p> </blockquote> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG">mkdocs-material's changelog</a>.</em></p> <blockquote> <p>mkdocs-material-9.7.7 (2026-07-17)</p> <ul> <li>Fixed DOM-based XSS vulnerability in search suggestions</li> </ul> <p>mkdocs-material-9.7.6 (2026-03-19)</p> <ul> <li>Automatically disable MkDocs 2.0 warning for forks of MkDocs</li> </ul> <p>mkdocs-material-9.7.5 (2026-03-10)</p> <ul> <li>Limited version range of mkdocs to <2</li> <li>Updated MkDocs 2.0 incompatibility warning (clarify relation with MkDocs)</li> </ul> <p>mkdocs-material-9.7.4 (2026-03-03)</p> <ul> <li>Hardened social cards plugin by switching to sandboxed environment</li> <li>Updated MkDocs 2.0 incompatibility warning</li> </ul> <p>mkdocs-material-9.7.3 (2026-02-24)</p> <ul> <li>Fixed <a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8567">#8567</a>: Print MkDocs 2.0 incompatibility warning to stderr</li> </ul> <p>mkdocs-material-9.7.2 (2026-02-18)</p> <ul> <li>Opened up version ranges of optional dependencies for forward-compatibility</li> <li>Added warning to 'mkdocs build' about impending MkDocs 2.0 incompatibility</li> </ul> <p>mkdocs-material-9.7.1 (2025-12-18)</p> <ul> <li>Updated requests to 2.30+ to mitigate CVE in urllib</li> <li>Fixed privacy plugin not picking up protocol-relative URLs</li> <li>Fixed <a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8542">#8542</a>: false positives and negatives captured in privacy plugin</li> </ul> <p>mkdocs-material-9.7.0 (2025-11-11)</p> <p>⚠️ Material for MkDocs is now in maintenance mode</p> <p>This is the last release of Material for MkDocs that will receive new features. Going forward, the Material for MkDocs team focuses on Zensical, a next-gen static site generator built from first principles. We will provide critical bug fixes and security updates for Material for MkDocs for 12 months at least.</p> <p>Read the full announcement on our blog: <a href="https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/">https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/</a></p> <p>This release includes all features that were previously exclusive to the Insiders edition. These features are now freely available to everyone.</p> <p>Note on deprecated plugins: The projects and typeset plugins are included in this release, but must be considered deprecated. Both plugins proved</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/b3e6dd886a974aa8200759ecfd7db28c598a2894"><code>b3e6dd8</code></a> Prepare 9.7.7 release</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25"><code>52fb6be</code></a> Merge commit from fork</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/901e6335cc80b0f12e46a1e34bd85e983dd78a6e"><code>901e633</code></a> Added <code>SECURITY.md</code> with EOL notice</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/5b36f2ac499a45905e246bc66bbee2858ef6556f"><code>5b36f2a</code></a> Bump js-yaml from 4.1.1 to 4.2.0 (<a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8598">#8598</a>)</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/2d11e7bc92c59b86d6ac0da2e38044fb4befa6e0"><code>2d11e7b</code></a> Bump form-data from 3.0.4 to 3.0.5 (<a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8597">#8597</a>)</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/ae05a534a8c8e1c58eb6aa55d460d309bcfce22b"><code>ae05a53</code></a> Bump esbuild from 0.27.2 to 0.28.1 (<a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8596">#8596</a>)</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/434af93166e5b90b78bba1295ca5a140fc67d0bc"><code>434af93</code></a> Bump shell-quote from 1.7.3 to 1.8.4 (<a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8593">#8593</a>)</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/4447cdadcbe8bc82570e9f1ae2b970f461b03b68"><code>4447cda</code></a> Documentation (<a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8590">#8590</a>)</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/8f8d551c9c5296dfc2a5ede35047bfb491d66bc9"><code>8f8d551</code></a> Updated copyright year (<a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8588">#8588</a>)</li> <li><a href="https://github.com/squidfunk/mkdocs-material/commit/08d8514d491782b4ac46673bcfdedb2f6fc85f3d"><code>08d8514</code></a> Bump fast-uri from 3.0.3 to 3.1.2 (<a href="https://redirect.github.com/squidfunk/mkdocs-material/issues/8587">#8587</a>)</li> <li>Additional commits viewable in <a href="https://github.com/squidfunk/mkdocs-material/compare/9.7.6...9.7.7">compare view</a></li> </ul> </details> <br /> Updates `prek` from 0.4.5 to 0.4.11 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/j178/prek/releases">prek's releases</a>.</em></p> <blockquote> <h2>0.4.11</h2> <h2>Release Notes</h2> <p>Released on 2026-07-25.</p> <h3>Highlights</h3> <ul> <li> <p>This release adds two new builtin hooks, <code>deny-pattern</code> and <code>require-pattern</code>, as native alternatives for <code>pygrep</code> use cases. <code>deny-pattern</code> fails when a configured pattern is found, while <code>require-pattern</code> ensures every selected file contains a match. By matching natively without spawning a Python subprocess, they run over 4x faster than <code>pygrep</code> in benchmarks. Note that they use <a href="https://docs.rs/regex/latest/regex/#syntax">Rust <code>regex</code> syntax</a>, which does not support look-around features such as negative lookbehind.</p> </li> <li> <p><code>prek run</code> now supports <code>--glob <PATTERN></code> to run hooks on tracked files matching a glob. It can be repeated or combined with <code>--files</code> and <code>--directory</code>.</p> </li> <li> <p>Hook priorities now support reusable aliases:</p> <pre lang="toml"><code>[priorities] checks = 10 <p>[[repos]] repo = "builtin" hooks = [ { id = "check-json", priority = "checks" }, { id = "check-yaml", priority = "checks" }, ] </code></pre></p> <p>This makes parallel scheduling easier to read and maintain.</p> </li> </ul> <h3>Enhancements</h3> <ul> <li>Add <code>deny-pattern</code> and <code>require-pattern</code> builtin hooks (<a href="https://redirect.github.com/j178/prek/pull/2359">#2359</a>)</li> <li>Support <code>--glob</code> patterns in <code>prek run</code> (<a href="https://redirect.github.com/j178/prek/pull/2381">#2381</a>)</li> <li>Support reusable aliases for hook priorities (<a href="https://redirect.github.com/j178/prek/pull/2331">#2331</a>)</li> <li>Implement <code>requirements-txt-fixer</code> as a builtin hook (<a href="https://redirect.github.com/j178/prek/pull/2390">#2390</a>)</li> <li>Improve user-facing warnings and errors (<a href="https://redirect.github.com/j178/prek/pull/2380">#2380</a>)</li> <li>Install Node hooks through git url (<a href="https://redirect.github.com/j178/prek/pull/2394">#2394</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reduce blocking-pool overhead in file hooks (<a href="https://redirect.github.com/j178/prek/pull/2384">#2384</a>)</li> <li>Speed up mixed-line-ending scans with memchr2 (<a href="https://redirect.github.com/j178/prek/pull/2391">#2391</a>)</li> </ul> <h3>Bug fixes</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/j178/prek/blob/master/CHANGELOG.md">prek's changelog</a>.</em></p> <blockquote> <h2>0.4.11</h2> <p>Released on 2026-07-25.</p> <h3>Highlights</h3> <ul> <li> <p>This release adds two new builtin hooks, <code>deny-pattern</code> and <code>require-pattern</code>, as native alternatives for <code>pygrep</code> use cases. <code>deny-pattern</code> fails when a configured pattern is found, while <code>require-pattern</code> ensures every selected file contains a match. By matching natively without spawning a Python subprocess, they run over 4x faster than <code>pygrep</code> in benchmarks. Note that they use <a href="https://docs.rs/regex/latest/regex/#syntax">Rust <code>regex</code> syntax</a>, which does not support look-around features such as negative lookbehind.</p> </li> <li> <p><code>prek run</code> now supports <code>--glob <PATTERN></code> to run hooks on tracked files matching a glob. It can be repeated or combined with <code>--files</code> and <code>--directory</code>.</p> </li> <li> <p>Hook priorities now support reusable aliases:</p> <pre lang="toml"><code>[priorities] checks = 10 <p>[[repos]] repo = "builtin" hooks = [ { id = "check-json", priority = "checks" }, { id = "check-yaml", priority = "checks" }, ] </code></pre></p> <p>This makes parallel scheduling easier to read and maintain.</p> </li> </ul> <h3>Enhancements</h3> <ul> <li>Add <code>deny-pattern</code> and <code>require-pattern</code> builtin hooks (<a href="https://redirect.github.com/j178/prek/pull/2359">#2359</a>)</li> <li>Support <code>--glob</code> patterns in <code>prek run</code> (<a href="https://redirect.github.com/j178/prek/pull/2381">#2381</a>)</li> <li>Support reusable aliases for hook priorities (<a href="https://redirect.github.com/j178/prek/pull/2331">#2331</a>)</li> <li>Implement <code>requirements-txt-fixer</code> as a builtin hook (<a href="https://redirect.github.com/j178/prek/pull/2390">#2390</a>)</li> <li>Improve user-facing warnings and errors (<a href="https://redirect.github.com/j178/prek/pull/2380">#2380</a>)</li> <li>Install Node hooks through git url (<a href="https://redirect.github.com/j178/prek/pull/2394">#2394</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reduce blocking-pool overhead in file hooks (<a href="https://redirect.github.com/j178/prek/pull/2384">#2384</a>)</li> <li>Speed up mixed-line-ending scans with memchr2 (<a href="https://redirect.github.com/j178/prek/pull/2391">#2391</a>)</li> </ul> <h3>Bug fixes</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/j178/prek/commit/92ba6c8c21e7acf5ce056b7c9b8dcba7325c3f5a"><code>92ba6c8</code></a> Bump version to 0.4.11 (<a href="https://redirect.github.com/j178/prek/issues/2402">#2402</a>)</li> <li><a href="https://github.com/j178/prek/commit/f575e428961414bc079060061bc570b71e553942"><code>f575e42</code></a> Bump quinn-proto from 0.11.14 to 0.11.16 (<a href="https://redirect.github.com/j178/prek/issues/2401">#2401</a>)</li> <li><a href="https://github.com/j178/prek/commit/c0ed56d92af1530e0acc98da2a8544bcf1dd01e7"><code>c0ed56d</code></a> Preserve system download policy when applying metadata (<a href="https://redirect.github.com/j178/prek/issues/2395">#2395</a>)</li> <li><a href="https://github.com/j178/prek/commit/3b8b5c53ea8ce674112e22f9f84addf3637ca9e0"><code>3b8b5c5</code></a> Install Node hooks through git url (<a href="https://redirect.github.com/j178/prek/issues/2394">#2394</a>)</li> <li><a href="https://github.com/j178/prek/commit/ff11cbb2d30478d9b2607dd1886cf90e33979365"><code>ff11cbb</code></a> Implement <code>requirements-txt-fixer</code> as a builtin hook (<a href="https://redirect.github.com/j178/prek/issues/2390">#2390</a>)</li> <li><a href="https://github.com/j178/prek/commit/c7dfc32c27f74ee04f9a4dc47b842fbb3e417631"><code>c7dfc32</code></a> Match identify tags across filename parts (<a href="https://redirect.github.com/j178/prek/issues/2399">#2399</a>)</li> <li><a href="https://github.com/j178/prek/commit/928dc5cf3b7c7486664d6a7e34ce8d89a603d7f1"><code>928dc5c</code></a> Speed up mixed-line-ending scans with memchr2 (<a href="https://redirect.github.com/j178/prek/issues/2391">#2391</a>)</li> <li><a href="https://github.com/j178/prek/commit/6c898499d8b7741f7e6b60cc42b195660e6d1afa"><code>6c89849</code></a> Honor filenames in builtin hook entry and args (<a href="https://redirect.github.com/j178/prek/issues/2389">#2389</a>)</li> <li><a href="https://github.com/j178/prek/commit/28bc3f013e0c97c39834f2f02a708355ed642462"><code>28bc3f0</code></a> Add description for no-commit-to-branch (<a href="https://redirect.github.com/j178/prek/issues/2388">#2388</a>)</li> <li><a href="https://github.com/j178/prek/commit/1d9adddb83df05770ea2a5562f141171be174d77"><code>1d9addd</code></a> Reduce blocking-pool overhead in file hooks (<a href="https://redirect.github.com/j178/prek/issues/2384">#2384</a>)</li> <li>Additional commits viewable in <a href="https://github.com/j178/prek/compare/v0.4.5...v0.4.11">compare view</a></li> </ul> </details> <br /> Updates `geopandas` from 1.1.3 to 1.1.4 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/geopandas/geopandas/releases">geopandas's releases</a>.</em></p> <blockquote> <h2>Version 1.1.4</h2> <h2>What's Changed</h2> <p>Bug fixes:</p> <ul> <li>Further hardening of <code>to_postgis</code> against SQL injection (<a href="https://redirect.github.com/geopandas/geopandas/issues/3800">#3800</a>).</li> <li>Ensure that points generated by <code>sample_points</code> are not sorted along x-axis (<a href="https://redirect.github.com/geopandas/geopandas/issues/3773">#3773</a>).</li> <li>Fix <code>GeoDataFrame.explore()</code> ignoring custom <code>legend_kwds={"labels": ...}</code> for categorical and boolean columns (<a href="https://redirect.github.com/geopandas/geopandas/issues/3496">#3496</a>).</li> <li>More graceful handling of <code>keep_geom_type</code> in the <code>overlay()</code> function with empty input (<a href="https://redirect.github.com/geopandas/geopandas/issues/3745">#3745</a>).</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/geopandas/geopandas/compare/v1.1.3...v1.1.4">https://github.com/geopandas/geopandas/compare/v1.1.3...v1.1.4</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/geopandas/geopandas/blob/v1.1.4/CHANGELOG.md">geopandas's changelog</a>.</em></p> <blockquote> <h2>Version 1.1.4 (June 26, 2026)</h2> <p>Bug fixes:</p> <ul> <li>Further hardening of <code>to_postgis</code> against SQL injection (<a href="https://redirect.github.com/geopandas/geopandas/issues/3800">#3800</a>).</li> <li>Ensure that points generated by <code>sample_points</code> are not sorted along x-axis (<a href="https://redirect.github.com/geopandas/geopandas/issues/3773">#3773</a>).</li> <li>Fix <code>GeoDataFrame.explore()</code> ignoring custom <code>legend_kwds={"labels": ...}</code> for categorical and boolean columns (<a href="https://redirect.github.com/geopandas/geopandas/issues/3496">#3496</a>).</li> <li>More graceful handling of <code>keep_geom_type</code> in the <code>overlay()</code> function with empty input (<a href="https://redirect.github.com/geopandas/geopandas/issues/3745">#3745</a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/geopandas/geopandas/commit/91ec4af3c502be268ee147a3a832387534c0be3d"><code>91ec4af</code></a> RLS: v1.1.4</li> <li><a href="https://github.com/geopandas/geopandas/commit/b5d685fa127ea0cdcc0d0d41ab6eca4f10b14cf1"><code>b5d685f</code></a> DOC: add changelog for 1.1.4</li> <li><a href="https://github.com/geopandas/geopandas/commit/158d993916f97d91af1972ad93c29b09687a916f"><code>158d993</code></a> BUG: further to_postgis hardening (<a href="https://redirect.github.com/geopandas/geopandas/issues/3800">#3800</a>)</li> <li><a href="https://github.com/geopandas/geopandas/commit/ce959306f1f6c23abfbf4023d2c107f875ddd65f"><code>ce95930</code></a> BUG: honor legend_kwds["labels"] for categorical and boolean columns in explo...</li> <li><a href="https://github.com/geopandas/geopandas/commit/22bf845492a6c4f9055bb00cc58c24bc770b46eb"><code>22bf845</code></a> BUG: overlay with empty input handles keep geom dtype gracefully (<a href="https://redirect.github.com/geopandas/geopandas/issues/3745">#3745</a>)</li> <li><a href="https://github.com/geopandas/geopandas/commit/866a7f02d0e5f7a651486384840654d047b9b373"><code>866a7f0</code></a> BUG: ensure that points from random sampling are not sorted (<a href="https://redirect.github.com/geopandas/geopandas/issues/3773">#3773</a>)</li> <li><a href="https://github.com/geopandas/geopandas/commit/76b16cad9379e5fc55d46430bbdf13443610b74d"><code>76b16ca</code></a> DOC: update Code of Conduct reporting form link (<a href="https://redirect.github.com/geopandas/geopandas/issues/3794">#3794</a>)</li> <li><a href="https://github.com/geopandas/geopandas/commit/3a04a5cc89ac348a82e7461b77fc536ab4feb02c"><code>3a04a5c</code></a> switch to NumFOCUS Code of Conduct (<a href="https://redirect.github.com/geopandas/geopandas/issues/3671">#3671</a>)</li> <li><a href="https://github.com/geopandas/geopandas/commit/6fedb19ae830f1219b2f1b14a7b0cbe5a6d6a3e2"><code>6fedb19</code></a> BLD: setuptools 77+ required for PEP 639 support (<a href="https://redirect.github.com/geopandas/geopandas/issues/3746">#3746</a>)</li> <li>See full diff in <a href="https://github.com/geopandas/geopandas/compare/v1.1.3...v1.1.4">compare view</a></li> </ul> </details> <br /> Updates `pydeck` from 0.9.2 to 0.9.3 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/visgl/deck.gl/commits">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
