From 179a113f4a4e1e1bc04de007faba28e8bf7be4bf Mon Sep 17 00:00:00 2001 From: rayharnett Date: Mon, 18 May 2026 12:38:38 +0100 Subject: [PATCH 1/2] Bump google-auth 2.48.0 -> 2.53.0 - Dependency update with security patches and bug fixes - Removes rsa as a transitive dependency (no longer needed) Co-Authored-By: Claude Haiku 4.5 --- pyproject.toml | 2 +- uv.lock | 9 ++++----- 2 files changed, 5 insertions(+), 6 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index 8b6f2e65e43..0cc657b5750 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -58,7 +58,7 @@ dependencies = [ "fideslang==3.1.3", "firebase-admin==5.3.0", "flower==2.0.1", - "google-auth==2.48.0", + "google-auth==2.53.0", "httpx~=0.28.1", "iab-tcf==0.2.2", "immutables==0.21", diff --git a/uv.lock b/uv.lock index 6e2521e5f4e..1546a9ef5ec 100644 --- a/uv.lock +++ b/uv.lock @@ -1090,7 +1090,7 @@ requires-dist = [ { name = "firebase-admin", specifier = "==5.3.0" }, { name = "flower", specifier = "==2.0.1" }, { name = "gitpython", specifier = "==3.1.41" }, - { name = "google-auth", specifier = "==2.48.0" }, + { name = "google-auth", specifier = "==2.53.0" }, { name = "httpx", specifier = "~=0.28.1" }, { name = "iab-tcf", specifier = "==0.2.2" }, { name = "immutables", specifier = "==0.21" }, @@ -1629,16 +1629,15 @@ wheels = [ [[package]] name = "google-auth" -version = "2.48.0" +version = "2.53.0" source = { registry = "https://pypi.org/simple" } dependencies = [ { name = "cryptography" }, { name = "pyasn1-modules" }, - { name = "rsa" }, ] -sdist = { url = "https://files.pythonhosted.org/packages/0c/41/242044323fbd746615884b1c16639749e73665b718209946ebad7ba8a813/google_auth-2.48.0.tar.gz", hash = "sha256:4f7e706b0cd3208a3d940a19a822c37a476ddba5450156c3e6624a71f7c841ce", size = 326522, upload-time = "2026-01-26T19:22:47.157Z" } +sdist = { url = "https://files.pythonhosted.org/packages/c6/ad/ff781329bbbdc0974a098d996e89c9e1f7024262f9e3eec442fbb9ad1ac6/google_auth-2.53.0.tar.gz", hash = "sha256:e7e6aa16f6bee7b2b264830fd04f08087a1d5a836df516251a5d15327b246c9c", size = 335844, upload-time = "2026-05-15T20:53:07.928Z" } wheels = [ - { url = "https://files.pythonhosted.org/packages/83/1d/d6466de3a5249d35e832a52834115ca9d1d0de6abc22065f049707516d47/google_auth-2.48.0-py3-none-any.whl", hash = "sha256:2e2a537873d449434252a9632c28bfc268b0adb1e53f9fb62afc5333a975903f", size = 236499, upload-time = "2026-01-26T19:22:45.099Z" }, + { url = "https://files.pythonhosted.org/packages/4a/c9/db44165ba7c581268c6d46017ef63339110378305062830104fc7fa144cb/google_auth-2.53.0-py3-none-any.whl", hash = "sha256:6e7449917c599b35126a99ec268ec6880301f2fea41dce198fe8fd83ff642b68", size = 246071, upload-time = "2026-05-15T20:53:05.609Z" }, ] [[package]] From 55c36843a207c67eb14dea44edb8485aef6bc8a3 Mon Sep 17 00:00:00 2001 From: rayharnett Date: Mon, 18 May 2026 12:45:56 +0100 Subject: [PATCH 2/2] add changelog for PR #8216 --- changelog/8216-bump-google-auth.yaml | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 changelog/8216-bump-google-auth.yaml diff --git a/changelog/8216-bump-google-auth.yaml b/changelog/8216-bump-google-auth.yaml new file mode 100644 index 00000000000..82eefeda663 --- /dev/null +++ b/changelog/8216-bump-google-auth.yaml @@ -0,0 +1,4 @@ +type: Changed +description: Bumped google-auth from 2.48.0 to 2.53.0 +pr: 8216 +labels: []