Automated security dependency sync from Dependabot alerts - #8636
Closed
cituspackagingapp[bot] wants to merge 2 commits into
Closed
Automated security dependency sync from Dependabot alerts#8636cituspackagingapp[bot] wants to merge 2 commits into
cituspackagingapp[bot] wants to merge 2 commits into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8636 +/- ##
=======================================
Coverage 88.73% 88.74%
=======================================
Files 288 288
Lines 64384 64386 +2
Branches 8108 8108
=======================================
+ Hits 57133 57138 +5
+ Misses 4909 4906 -3
Partials 2342 2342 🚀 New features to boost your workflow:
|
Pin mitmproxy to citusdata/mitmproxy@321e6d2 (PR #5 branch tip, relaxes the msgpack<=1.1.2 and tornado<=6.5.5 caps) instead of merging that PR. Raises tornado lower bound to 6.5.7 and adds msgpack>=1.2.1; cryptography stays ==48.0.1. Regenerated Pipfile.lock resolves msgpack==1.2.1, tornado==6.5.7. Both regress Pipfile trees kept byte-identical. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
ihalatci
pushed a commit
to citusdata/the-process
that referenced
this pull request
Jul 2, 2026
Testers pick up the msgpack/tornado bumps unblocked by the mitmproxy relaxed-caps SHA pin in citusdata/citus#8636. Stylechecker regenerated via --dev-only (style tools only), reverting the accidental --dev runtime-dep bloat so it no longer regresses master. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
|
Superseded: the-process #231 (dependency-security-sync generator + Fix A) merged as ee457b3. Closing so a fresh automated sync run regenerates this citus PR with the corrected image_suffix (-dev-) flow. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated weekly security sync based on open Dependabot alerts.
This PR is managed by dependency-security-sync workflow.
Supersedes the individual Dependabot PRs for: cryptography, msgpack, tornado. Those PRs are intentionally left open and should be closed when this PR merges.