Skip to content

chore: Upgrade Python requirements - #251

Open
edx-requirements-bot wants to merge 1 commit into
mainfrom
repo-tools/upgrade-python-requirements-ea1e3cf
Open

chore: Upgrade Python requirements#251
edx-requirements-bot wants to merge 1 commit into
mainfrom
repo-tools/upgrade-python-requirements-ea1e3cf

Conversation

@edx-requirements-bot

Copy link
Copy Markdown
Contributor

Python requirements update. Please review the changelogs for the upgraded packages.

@edx-requirements-bot

Copy link
Copy Markdown
Contributor Author

List of packages in the PR without any issue.

  • build changes from 1.5.0 to 1.6.0
  • click changes from 8.4.2 to 8.5.0
  • cryptography changes from 50.0.0 to 50.0.1
  • faker changes from 40.36.0 to 40.37.0
  • filelock changes from 3.32.3 to 3.32.4
  • imagesize changes from 2.0.0 to 2.0.1
  • nh3 changes from 0.3.6 to 0.3.7
  • platformdirs changes from 4.11.3 to 4.11.5
  • python-discovery changes from 1.5.2 to 1.5.3
  • tox changes from 4.60.0 to 4.60.1
  • virtualenv changes from 21.7.4 to 21.7.5

@edx-requirements-bot

Copy link
Copy Markdown
Contributor Author

These Packages need manual review..

  • [NEW] jeepney (0.9.0) added to the requirements
  • [NEW] secretstorage (3.5.0) added to the requirements

@brobro10000

Copy link
Copy Markdown
Member

🤖 Automated Requirements Analysis — 2026-08-31

CI Status: ✅ Passing
Recommendation: ⚠️ NEEDS CLOSER LOOK (MINOR production update)

Dependency Changes

Package From To Bump Env Risk Release Notes
click 8.4.2 8.5.0 MINOR prod Moderate release notes
cryptography 50.0.0 50.0.1 PATCH prod Low release notes
django 5.2.17 5.2.17 None prod Low release notes

Findings

  • MINOR Production Bump: click is updated from 8.4.2 to 8.5.0. While generally stable, CLI behavior changes should be verified.
  • Critical Runtime Package: cryptography is updated to 50.0.1 (PATCH). This is a security-sensitive package.
  • CI Status: All tests and coverage checks are passing successfully.

Recommended Validation

  • Deploy to staging and validate core ledger workflows, particularly those involving CLI commands or background tasks using click.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants