Commit Graph

12918 Commits

Author SHA1 Message Date
Kenneth Kehl
fe1f333d4c Update app/aws/s3.py
Co-authored-by: ccostino <ccostino@users.noreply.github.com>
2025-06-11 07:27:51 -07:00
Kenneth Kehl
414298fd79 merge from main 2025-06-10 07:52:00 -07:00
ccostino
172293d33a Merge pull request #1762 from GSA/dependabot/pip/phonenumbers-9.0.7
Bump phonenumbers from 9.0.6 to 9.0.7
2025-06-10 10:48:52 -04:00
dependabot[bot]
e04b3cf438 Bump phonenumbers from 9.0.6 to 9.0.7
Bumps [phonenumbers](https://github.com/daviddrysdale/python-phonenumbers) from 9.0.6 to 9.0.7.
- [Commits](https://github.com/daviddrysdale/python-phonenumbers/compare/v9.0.6...v9.0.7)

---
updated-dependencies:
- dependency-name: phonenumbers
  dependency-version: 9.0.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-06-10 13:50:31 +00:00
ccostino
df48988db1 Merge pull request #1763 from GSA/dependabot/pip/requests-2.32.4
Bump requests from 2.32.3 to 2.32.4
2025-06-10 09:48:20 -04:00
dependabot[bot]
27e73343b8 Bump requests from 2.32.3 to 2.32.4
Bumps [requests](https://github.com/psf/requests) from 2.32.3 to 2.32.4.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](https://github.com/psf/requests/compare/v2.32.3...v2.32.4)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.32.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-06-09 21:26:53 +00:00
ccostino
214ee24836 Merge pull request #1761 from GSA/python_manual_unwind
Python manual unwind
2025-06-09 12:28:09 -04:00
Kenneth Kehl
e7406aaf60 add poetry.lock 2025-06-09 08:46:50 -07:00
Kenneth Kehl
97ea02e85a manually roll python back to 3.12.2 2025-06-09 08:46:07 -07:00
Kenneth Kehl
fbe733bc7e check which services have csvs 2025-06-09 07:12:05 -07:00
ccostino
8e0bb22634 Merge pull request #1756 from GSA/add-cert-env-var
Add one more cert environment variable
2025-06-05 17:51:07 -04:00
Carlo Costino
a6bc7b4985 Add one more cert environment variable
This changeset adds an additional environment variable to enforce usage of the correct CA certificate in case any libraries override it.

Please see https://cloud.gov/docs/management/container-to-container/#addressing-certificate-validation-errors for more details.

Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2025-06-05 17:41:03 -04:00
ccostino
dc71f03692 Merge pull request #1755 from GSA/better_debug
improve debug of external issues
2025-06-05 11:31:44 -04:00
Kenneth Kehl
2abcbc5560 cleanup 2025-06-05 08:17:30 -07:00
Kenneth Kehl
aa9cafb5f1 improve debug of external issues 2025-06-05 08:12:56 -07:00
ccostino
630641af1d Merge pull request #1754 from GSA/unpin-egress-proxy
Unpin egress proxy release
2025-06-04 15:30:56 -04:00
Carlo Costino
ed4cbbc05b Unpin egress proxy release
This changeset unpins the egress proxy release now that we have resolved the other issues surrounding the connectivity to S3.

Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2025-06-04 12:02:52 -04:00
ccostino
1547478bbf Merge pull request #1752 from GSA/get_rid_of_oscrypto
get rid of oscrypto
2025-06-04 11:44:05 -04:00
Kenneth Kehl
57f98b1507 cleanup 2025-06-04 08:03:01 -07:00
Kenneth Kehl
5eade384c5 fix imports 2025-06-04 07:42:41 -07:00
Kenneth Kehl
9379ca0436 get rid of oscrypto 2025-06-04 07:38:53 -07:00
ccostino
acfbffa3d8 Merge pull request #1745 from GSA/pythonupgrade
python upgrade to 3.13.2
2025-06-03 14:53:46 -04:00
Kenneth Kehl
965bb3047c update 2025-06-03 08:57:34 -07:00
ccostino
bcd33e7af8 Merge pull request #1751 from GSA/dependabot/pip/pytest-8.4.0
Bump pytest from 8.3.5 to 8.4.0
2025-06-03 10:47:27 -04:00
dependabot[bot]
64535abb7c Bump pytest from 8.3.5 to 8.4.0
Bumps [pytest](https://github.com/pytest-dev/pytest) from 8.3.5 to 8.4.0.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.5...8.4.0)

---
updated-dependencies:
- dependency-name: pytest
  dependency-version: 8.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-06-03 12:56:28 +00:00
ccostino
25ee386155 Merge pull request #1750 from GSA/dependabot/pip/celery-5.5.3
Bump celery from 5.5.2 to 5.5.3
2025-06-03 08:54:17 -04:00
dependabot[bot]
e15a49ba18 Bump celery from 5.5.2 to 5.5.3
Bumps [celery](https://github.com/celery/celery) from 5.5.2 to 5.5.3.
- [Release notes](https://github.com/celery/celery/releases)
- [Changelog](https://github.com/celery/celery/blob/main/Changelog.rst)
- [Commits](https://github.com/celery/celery/compare/v5.5.2...v5.5.3)

---
updated-dependencies:
- dependency-name: celery
  dependency-version: 5.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-06-02 21:49:47 +00:00
ccostino
6d8e2221d0 Merge pull request #1748 from GSA/fix-daily-checks
Update daily checks to match PR checks
2025-06-02 09:52:15 -04:00
Carlo Costino
8af59b1c55 Update daily checks to match PR checks
This changeset adds the same additional steps needed in our PR checks to make sure the daily checks work properly with the recent Poetry update.  It also updates our PR checks to use the latest pip-audit GitHub action.

Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2025-06-02 09:23:02 -04:00
Beverly Nguyen
abdaa74d0b Merge pull request #1747 from GSA/remove-python-vuln-ignore-again
Remove extra vulnerability from our ignore list
2025-05-30 14:21:57 -07:00
Kenneth Kehl
44f2c52a52 merge from main 2025-05-30 13:29:53 -07:00
Carlo Costino
cf4deb083b Remove extra vulnerability from our ignore list
This changeset fixes an oversight where a vulnerability got added back to our ignore list.

Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2025-05-30 16:28:03 -04:00
Kenneth Kehl
fb3bf6d9b1 okay upgrade to 3.13.2 now to stay in sync with admin 2025-05-30 12:35:27 -07:00
Kenneth Kehl
86c7e77197 try eventlet 0.40.0 2025-05-30 11:37:43 -07:00
Kenneth Kehl
f7f92dd1f4 try python 3.13.3 2025-05-30 11:20:56 -07:00
Kenneth Kehl
ad17ddc23f try upgrading to python 3.13.1 2025-05-30 11:09:10 -07:00
Kenneth Kehl
ac9e3a49d8 try downgrading eventlet to 0.33.3 2025-05-30 11:01:31 -07:00
Kenneth Kehl
72289ace08 python upgrade 2025-05-30 10:49:42 -07:00
ccostino
cbe50a1aa7 Merge pull request #1744 from GSA/add-detect-secrets-docs
Add detect-secrets documentation
5-30-2025
2025-05-30 11:50:14 -04:00
Carlo Costino
0a28b33e99 Add detect-secrets documentation
This changeset adds documentation to help our team manage our secrets detection with the detect-secrets pre-commit plugin.

Signed-off-by: Carlo Costino <carlo.costino@gsa.gov>
2025-05-30 11:39:07 -04:00
ccostino
c301513caf Merge pull request #1738 from GSA/poetry
upgrade poetry
2025-05-30 10:55:47 -04:00
Kenneth Kehl
e5484f0723 Update Makefile
Co-authored-by: ccostino <ccostino@users.noreply.github.com>
2025-05-29 11:14:29 -07:00
Kenneth Kehl
222e258e34 Update Makefile
Co-authored-by: ccostino <ccostino@users.noreply.github.com>
2025-05-29 11:14:00 -07:00
Kenneth Kehl
d40ab17770 Update Makefile
Co-authored-by: ccostino <ccostino@users.noreply.github.com>
2025-05-29 11:13:36 -07:00
Kenneth Kehl
3b5f11932f ugh secrets 2025-05-29 10:15:58 -07:00
Kenneth Kehl
c2ed11d28e add comments about poetry upgrade 2025-05-29 08:48:00 -07:00
Kenneth Kehl
59af82b0a4 merge from main 2025-05-29 08:05:46 -07:00
Alex Janousek
062683ada6 Merge pull request #1742 from GSA/dependabot/pip/phonenumbers-9.0.6
Bump phonenumbers from 9.0.5 to 9.0.6
2025-05-29 09:19:29 -04:00
dependabot[bot]
47a3c6dc91 Bump phonenumbers from 9.0.5 to 9.0.6
Bumps [phonenumbers](https://github.com/daviddrysdale/python-phonenumbers) from 9.0.5 to 9.0.6.
- [Commits](https://github.com/daviddrysdale/python-phonenumbers/compare/v9.0.5...v9.0.6)

---
updated-dependencies:
- dependency-name: phonenumbers
  dependency-version: 9.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-05-29 13:12:28 +00:00
Beverly Nguyen
500dc80557 Merge pull request #1743 from GSA/ignore-redis-false-report
Updated pip-audit ignore-vulns
2025-05-28 17:32:24 -07:00