Skip to content

chore(deps): update python-pam requirement from >=2.0.0 to >=2.1.0 - #88

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-pam-gte-2.1.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-pam-gte-2.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on python-pam to permit the latest version.

Release notes

Sourced from python-pam's releases.

2.1.0

python-pam 2.1.0 — Poetry packaging, thread-safe authenticate, and refreshed tooling.

Features & changes

  • Switch to Poetry; drop Python 2 support
  • Make PAM handle checks more robust
  • Update documentation with a better example
  • CI tox suite covers Python 3.11–3.14
  • pam.authenticate() no longer reuses a process-global PamAuthenticator (thread-safe concurrent auth); libpam ctypes bindings are loaded once and shared (#40)
  • Document the threading model (do not share one PamAuthenticator across threads)
  • Document when to use resetcreds=True vs False (#52)

Tooling

Changelog

Sourced from python-pam's changelog.

2.1.0 Latest

September 16, 2026

  • switch to poetry
  • merge outstanding PRs
  • make handle checks and make them more robust
  • update documentation with better example
  • remove py2 support
  • tox test suite set to py312 and py313
  • fix #40: pam.authenticate() no longer reuses a process-global PamAuthenticator (thread-safe concurrent auth); libpam ctypes bindings are loaded once and shared for performance
  • document threading model (do not share one PamAuthenticator across threads)
  • document when to use resetcreds=True vs False (#52)
  • bump pip to 26.2.1 (CVE-2026-13346 / GHSA-qwm4-qh6w-59xr)
  • refresh tox, pylint, mypy, pytest-env, and pip-tools pins
  • add GitHub Actions trusted publishing for PyPI

2.0.2

March 17, 2022

Surface fixes

  • Fixed #31 whereby I changed the boolean response in 2.0.0 to a PAM constant. This reverts to the boolean response as existed in v1.8.5. The result code is still stored in the obj.code attribute
  • Added the PamAuthenticate.authenticate() method signature and docstring to both of the new and legacy interfaces
  • Changed the PamAuthenticate.authenticate() type hinting so it didn't interfere with the docstring
  • update the version to 2.0.2

Under the hood changes

  • Start mocking the libpam methods so we can wholly disassociate ourselves from the underlying system. This lets us test more of the actual python code and lets us start injecting errors to test for

Release 2.0.0

March 13, 2022

The surface functionality hasn't changed much but a few bugs have been fixed. Under the hood, a lot has changed. Functionality has now been moved into a class that helped with value tracking. I planned on removing Python 2 support but was convinced to leave it in for now as apparently there are still a lot of python2 users. 😕 🤷‍♂️

Most testing has moved to occur underneath tox, this is superior as it provides for testing in a clean environment and an installed environment.

Merges

Features & Changes

... (truncated)

Commits
  • f9c139f Merge pull request #101 from FirefighterBlu3/deps/dev-ci-tools
  • 02f22f4 documentation: note pip CVE and tool bumps
  • 8d72ae0 deps: raise pip and refresh tool pins
  • 3b878f1 Merge pull request #72 from FirefighterBlu3/docs/resetcreds-readme
  • 20c61d3 docs: explain resetcreds default vs password-check-only use
  • 7affefe Merge pull request #71 from FirefighterBlu3/fix/40-thread-safe-authenticate
  • bc05e9d fix: restore pylint score for runtime ctypes bindings
  • f09faf1 fix: make pam.authenticate() safe under concurrent threads
  • 1eacf15 Merge pull request #70 from FirefighterBlu3/dependabot/pip/dot-github/pip-26.1.2
  • c51f9e5 Bump pip from 25.0.1 to 26.1.2 in /.github
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [python-pam](https://github.com/FirefighterBlu3/python-pam) to permit the latest version.
- [Release notes](https://github.com/FirefighterBlu3/python-pam/releases)
- [Changelog](https://github.com/FirefighterBlu3/python-pam/blob/main/ChangeLog.md)
- [Commits](FirefighterBlu3/python-pam@v2.0.0...v2.1.0)

---
updated-dependencies:
- dependency-name: python-pam
  dependency-version: 2.1.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants