Skip to content

Automated security dependency sync from Dependabot alerts - #8841

Draft
cituspackagingapp[bot] wants to merge 7 commits into
mainfrom
automation/dependency-security-sync
Draft

cituspackagingapp[bot] wants to merge 7 commits into
mainfrom
automation/dependency-security-sync

Conversation

@cituspackagingapp

@cituspackagingapp cituspackagingapp Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Automated security dependency sync generated from the current Dependabot alerts.

  • tornado: 6.5.7 -> 6.5.8
  • h2: 4.3.0 -> 4.4.1
  • cryptography: 48.0.1 -> 50.0.0

Updates both regress/devcontainer Pipfiles and lockfiles, using the mitmproxy fork revision with compatible dependency caps and the OpenSSL 4 protocol-probe fix. This includes the prerequisite pin change from #8840; the pin-only PR does not need to be merged separately if this coordinated PR is used.

Paired image-requirements PR: citusdata/the-process#249
Fork prerequisite: citusdata/mitmproxy#5
Generated by: https://github.com/citusdata/the-process/actions/runs/34461452342

CI is pointed at -dev-f4ed790, built from the paired the-process requirements commit. Merge the-process#249 first; its post-merge workflow updates this PR to the corresponding release-image tag before this PR is merged.

This PR is managed by dependency-security-sync. Superseded individual Dependabot PRs are intentionally left open until the coordinated updates merge. Nothing has been merged by this automation run.

ihalatci-msft and others added 2 commits September 10, 2026 12:22
Consume the fork revision permitting patched cryptography, h2, and tornado versions, including OpenSSL 4 protocol-probe compatibility. Preserve existing resolved versions so the security-sync workflow generates the coordinated dependency and image updates.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cituspackagingapp cituspackagingapp Bot added the dependencies Pull requests that update a dependency file label Sep 10, 2026
@codecov

codecov Bot commented Sep 10, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.75%. Comparing base (a6b4ff0) to head (b0bcbd3).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8841      +/-   ##
==========================================
+ Coverage   88.69%   88.75%   +0.05%     
==========================================
  Files         290      290              
  Lines       65081    65081              
  Branches     8215     8216       +1     
==========================================
+ Hits        57726    57764      +38     
+ Misses       4974     4943      -31     
+ Partials     2381     2374       -7     
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

The generated security dependency refresh advances isort from 8.0.1 to 9.0.1. Collapse its single flagged parenthesized import without changing behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cituspackagingapp

Copy link
Copy Markdown
Contributor Author

the-process sync merged at 1d8d03c41d12ce10305a4f05d3775a694ef93568; updated build_and_test.yml image_suffix to -v1d8d03c.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants