Skip to content

Automated security dependency sync from Dependabot alerts - #8841

Closed
cituspackagingapp[bot] wants to merge 9 commits into
mainfrom
automation/dependency-security-sync
Closed

cituspackagingapp[bot] wants to merge 9 commits into
mainfrom
automation/dependency-security-sync

Conversation

@cituspackagingapp

@cituspackagingapp cituspackagingapp Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Automated security dependency sync generated from the current Dependabot alerts.

  • tornado: 6.5.7 -> 6.5.8
  • h2: 4.3.0 -> 4.4.1
  • cryptography: 48.0.1 -> 50.0.0

Updates both regress/devcontainer Pipfiles and lockfiles, using the mitmproxy fork revision with compatible dependency caps and the OpenSSL 4 protocol-probe fix. This includes the prerequisite pin change from #8840; the pin-only PR does not need to be merged separately if this coordinated PR is used.

Paired image-requirements PR: citusdata/the-process#249
Fork prerequisite: citusdata/mitmproxy#5
Generated by: https://github.com/citusdata/the-process/actions/runs/34461452342

CI is pointed at -dev-f4ed790, built from the paired the-process requirements commit. Merge the-process#249 first; its post-merge workflow updates this PR to the corresponding release-image tag before this PR is merged.

This PR is managed by dependency-security-sync. Superseded individual Dependabot PRs are intentionally left open until the coordinated updates merge. Nothing has been merged by this automation run.

ihalatci-msft and others added 2 commits September 10, 2026 12:22
Consume the fork revision permitting patched cryptography, h2, and tornado versions, including OpenSSL 4 protocol-probe compatibility. Preserve existing resolved versions so the security-sync workflow generates the coordinated dependency and image updates.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cituspackagingapp cituspackagingapp Bot added the dependencies Pull requests that update a dependency file label Sep 10, 2026
@codecov

codecov Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.75%. Comparing base (c267b0b) to head (ba6cc95).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8841      +/-   ##
==========================================
+ Coverage   88.69%   88.75%   +0.06%     
==========================================
  Files         290      290              
  Lines       65155    65102      -53     
  Branches     8219     8219              
==========================================
- Hits        57787    57783       -4     
+ Misses       4993     4943      -50     
- Partials     2375     2376       +1     
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

The generated security dependency refresh advances isort from 8.0.1 to 9.0.1. Collapse its single flagged parenthesized import without changing behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cituspackagingapp

Copy link
Copy Markdown
Contributor Author

the-process sync merged at 1d8d03c41d12ce10305a4f05d3775a694ef93568; updated build_and_test.yml image_suffix to -v1d8d03c.

@ihalatci
ibrahim halatci (ihalatci) marked this pull request as ready for review September 25, 2026 09:55
@ihalatci

Copy link
Copy Markdown
Contributor

Closing to restart the security dependency sync cleanly. This branch accumulated manual \Merge branch 'main'\ commits, which trips the \safe_push.sh\ guard in the-process's dependency-security-sync workflow (it refuses to force-push over non-bot commits), so scheduled regenerations (09-13, 09-20, 09-27) silently no-op'd and the branch went stale/conflicting against main.

Plan: once #8881 merges and main is green again (main is currently broken — PG19 beta4 dev-image suffix + a pg_dist_object reindex race), we'll re-trigger \dependency-security-sync\ in citusdata/the-process (workflow_dispatch, citus_ref=main) to regenerate a fresh coordinated pair of PRs off a clean main.

auto-merge was automatically disabled September 27, 2026 11:23

Pull request was closed

@ihalatci
ibrahim halatci (ihalatci) deleted the automation/dependency-security-sync branch September 27, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants