Skip to content

Automated security dependency sync from Dependabot alerts - #8841

Draft
cituspackagingapp[bot] wants to merge 5 commits into
mainfrom
automation/dependency-security-sync
Draft

Automated security dependency sync from Dependabot alerts#8841
cituspackagingapp[bot] wants to merge 5 commits into
mainfrom
automation/dependency-security-sync

Conversation

@cituspackagingapp

@cituspackagingapp cituspackagingapp Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Automated security dependency sync generated from the current Dependabot alerts.

  • tornado: 6.5.7 -> 6.5.8
  • h2: 4.3.0 -> 4.4.1
  • cryptography: 48.0.1 -> 50.0.0

Updates both regress/devcontainer Pipfiles and lockfiles, using the mitmproxy fork revision with compatible dependency caps and the OpenSSL 4 protocol-probe fix. This includes the prerequisite pin change from #8840; the pin-only PR does not need to be merged separately if this coordinated PR is used.

Paired image-requirements PR: citusdata/the-process#249
Fork prerequisite: citusdata/mitmproxy#5
Generated by: https://github.com/citusdata/the-process/actions/runs/34461452342

CI is pointed at -dev-f4ed790, built from the paired the-process requirements commit. Merge the-process#249 first; its post-merge workflow updates this PR to the corresponding release-image tag before this PR is merged.

This PR is managed by dependency-security-sync. Superseded individual Dependabot PRs are intentionally left open until the coordinated updates merge. Nothing has been merged by this automation run.

ihalatci-msft and others added 2 commits September 10, 2026 12:22
Consume the fork revision permitting patched cryptography, h2, and tornado versions, including OpenSSL 4 protocol-probe compatibility. Preserve existing resolved versions so the security-sync workflow generates the coordinated dependency and image updates.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@cituspackagingapp cituspackagingapp Bot added the dependencies Pull requests that update a dependency file label Sep 10, 2026
@codecov

codecov Bot commented Sep 10, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.73%. Comparing base (f172859) to head (08bf47e).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #8841   +/-   ##
=======================================
  Coverage   88.73%   88.73%           
=======================================
  Files         289      289           
  Lines       65012    65012           
  Branches     8203     8203           
=======================================
+ Hits        57690    57691    +1     
  Misses       4952     4952           
+ Partials     2370     2369    -1     
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

The generated security dependency refresh advances isort from 8.0.1 to 9.0.1. Collapse its single flagged parenthesized import without changing behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants