Compare commits

...

80 Commits

Author SHA1 Message Date
Kenneth Kehl
2545eb980f Merge pull request #2276 from GSA/allow_node_20
upgrade from node 20 to node 24 for github actions
2026-06-02 08:46:49 -07:00
Kenneth Kehl
be991afeb2 upgrade pyjwt even more 2026-06-02 08:09:11 -07:00
Kenneth Kehl
e6815ed918 upgrade dulwich idna and pyjwt 2026-06-02 08:06:49 -07:00
Kenneth Kehl
9c15262b06 upgrade from node 20 to node 24 for github actions 2026-06-02 07:59:37 -07:00
Kenneth Kehl
b988d472ae Merge pull request #2270 from GSA/dependabot/pip/urllib3-2.7.0
Bump urllib3 from 2.6.3 to 2.7.0
2026-05-12 07:06:56 -07:00
dependabot[bot]
ac96886a4a Bump urllib3 from 2.6.3 to 2.7.0
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.3 to 2.7.0.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.7.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-05-11 17:19:48 +00:00
Kenneth Kehl
32bd7af1b0 Merge pull request #2269 from GSA/update_mistune
update mistune
2026-05-07 07:40:09 -07:00
Kenneth Kehl
8c4a8ea43a update mako also 2026-05-07 07:23:10 -07:00
Kenneth Kehl
b52ece0f84 update mistune 2026-05-07 07:18:13 -07:00
Kenneth Kehl
9ccc698bb3 Merge pull request #2262 from GSA/dependabot/pip/mako-1.3.11
Bump mako from 1.3.10 to 1.3.11
2026-05-07 07:12:00 -07:00
Kenneth Kehl
bf60cdf9e4 Merge pull request #2264 from GSA/dependabot/pip/lxml-6.1.0
Bump lxml from 6.0.2 to 6.1.0
2026-04-22 09:41:20 -07:00
Kenneth Kehl
e3dabd1c1a ugh 2026-04-22 09:25:20 -07:00
Kenneth Kehl
c5b7a6e45c keep trying to upgrade poetry 2026-04-22 09:15:18 -07:00
Kenneth Kehl
47b28fc9f7 update poetry to 2.3.4 as well 2026-04-22 09:10:03 -07:00
Kenneth Kehl
620a730903 upgrade poetry-dotenv as well 2026-04-22 08:56:48 -07:00
dependabot[bot]
90ef879c60 Bump lxml from 6.0.2 to 6.1.0
Bumps [lxml](https://github.com/lxml/lxml) from 6.0.2 to 6.1.0.
- [Release notes](https://github.com/lxml/lxml/releases)
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)
- [Commits](https://github.com/lxml/lxml/compare/lxml-6.0.2...lxml-6.1.0)

---
updated-dependencies:
- dependency-name: lxml
  dependency-version: 6.1.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-21 22:49:51 +00:00
dependabot[bot]
7e24314397 Bump mako from 1.3.10 to 1.3.11
Bumps [mako](https://github.com/sqlalchemy/mako) from 1.3.10 to 1.3.11.
- [Release notes](https://github.com/sqlalchemy/mako/releases)
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/mako/commits)

---
updated-dependencies:
- dependency-name: mako
  dependency-version: 1.3.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-16 22:49:54 +00:00
Kenneth Kehl
2090127c7a Merge pull request #2261 from GSA/dependabot/pip/pytest-9.0.3
Bump pytest from 9.0.2 to 9.0.3
2026-04-14 08:12:32 -07:00
dependabot[bot]
3d384f78ca Bump pytest from 9.0.2 to 9.0.3
Bumps [pytest](https://github.com/pytest-dev/pytest) from 9.0.2 to 9.0.3.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/9.0.2...9.0.3)

---
updated-dependencies:
- dependency-name: pytest
  dependency-version: 9.0.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-14 02:29:29 +00:00
Kenneth Kehl
c171648bb1 Merge pull request #2260 from GSA/dependabot/pip/cryptography-46.0.7
Bump cryptography from 46.0.6 to 46.0.7
2026-04-09 08:15:30 -07:00
dependabot[bot]
0de64dc74a Bump cryptography from 46.0.6 to 46.0.7
Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.6 to 46.0.7.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.6...46.0.7)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-08 23:00:11 +00:00
dependabot[bot]
66e9ce1d39 Bump black from 26.1.0 to 26.3.1 (#2247)
* Bump black from 26.1.0 to 26.3.1

Bumps [black](https://github.com/psf/black) from 26.1.0 to 26.3.1.
- [Release notes](https://github.com/psf/black/releases)
- [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)
- [Commits](https://github.com/psf/black/compare/26.1.0...26.3.1)

---
updated-dependencies:
- dependency-name: black
  dependency-version: 26.3.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* Updated lockfile

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alex Janousek <alex.janousek@gsa.gov>
2026-04-06 15:04:55 -04:00
dependabot[bot]
e095649189 Bump pygments from 2.19.2 to 2.20.0 (#2257)
Bumps [pygments](https://github.com/pygments/pygments) from 2.19.2 to 2.20.0.
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](https://github.com/pygments/pygments/compare/2.19.2...2.20.0)

---
updated-dependencies:
- dependency-name: pygments
  dependency-version: 2.20.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 15:05:40 -04:00
Kenneth Kehl
7a0e43f474 Merge pull request #2259 from GSA/dependabot/pip/poetry-2.3.3
Bump poetry from 2.3.1 to 2.3.3
2026-04-02 09:01:57 -07:00
dependabot[bot]
eab4e45450 Bump poetry from 2.3.1 to 2.3.3
Bumps [poetry](https://github.com/python-poetry/poetry) from 2.3.1 to 2.3.3.
- [Release notes](https://github.com/python-poetry/poetry/releases)
- [Changelog](https://github.com/python-poetry/poetry/blob/main/CHANGELOG.md)
- [Commits](https://github.com/python-poetry/poetry/compare/2.3.1...2.3.3)

---
updated-dependencies:
- dependency-name: poetry
  dependency-version: 2.3.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-02 15:53:53 +00:00
Kenneth Kehl
412b36f5cf Merge pull request #2258 from GSA/dependabot/pip/aiohttp-3.13.4
Bump aiohttp from 3.13.3 to 3.13.4
2026-04-02 08:49:32 -07:00
dependabot[bot]
9fc9c1dcf1 Bump aiohttp from 3.13.3 to 3.13.4
---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.13.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-01 22:16:05 +00:00
Kenneth Kehl
11030c0a0d Merge pull request #2256 from GSA/dependabot/pip/cryptography-46.0.6
Bump cryptography from 46.0.5 to 46.0.6
2026-03-30 07:40:38 -07:00
dependabot[bot]
6ede7e5b1b Bump cryptography from 46.0.5 to 46.0.6
Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.5 to 46.0.6.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.5...46.0.6)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-03-29 03:31:08 +00:00
Kenneth Kehl
a8060cec04 Merge pull request #2254 from GSA/daily_scans_requests
daily scan work
2026-03-26 14:58:47 -07:00
Kenneth Kehl
76df6bbabe run pip-audit only on production code 2026-03-26 10:24:43 -07:00
Kenneth Kehl
b4196f1c5e run pip-audit only on production code 2026-03-26 10:19:15 -07:00
Kenneth Kehl
dbfe67db31 run pip-audit only on production code 2026-03-26 10:07:16 -07:00
Kenneth Kehl
2f7afb4d57 daily scan work 2026-03-26 08:49:16 -07:00
Kenneth Kehl
bdd4b67414 Merge pull request #2251 from GSA/daily_scans_pyjwt
upgrade github-script to version 7
2026-03-18 07:27:48 -07:00
Kenneth Kehl
3d5c6be492 upgrade pyasn1 as well due to pip-audit finding 2026-03-17 14:26:06 -07:00
Kenneth Kehl
f85184ed62 upgrade github-script to version 7 2026-03-17 14:20:46 -07:00
Kenneth Kehl
ee922d735f Merge pull request #2249 from GSA/daily_scans_pyjwt
fix test for pyjwt upgrade
2026-03-17 12:03:12 -07:00
Kenneth Kehl
af4a47dd7f fix test for pyjwt upgrade 2026-03-17 08:24:17 -07:00
Kenneth Kehl
268136b1b5 fix test for pyjwt upgrade 2026-03-17 08:15:56 -07:00
Kenneth Kehl
773460dcaf fix test for pyjwt upgrade 2026-03-17 08:03:37 -07:00
Kenneth Kehl
d033af8f76 fix test for pyjwt upgrade 2026-03-17 07:51:12 -07:00
Alex Janousek
776a33a9e3 Disable automatic version updates from dependabot (#2246) 2026-03-02 13:56:56 -05:00
dependabot[bot]
931c7791ba Bump virtualenv from 21.0.0 to 21.1.0 (#2244)
* Bump virtualenv from 21.0.0 to 21.1.0

Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.0.0 to 21.1.0.
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](https://github.com/pypa/virtualenv/compare/21.0.0...21.1.0)

---
updated-dependencies:
- dependency-name: virtualenv
  dependency-version: 21.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* Fix build errors

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alex Janousek <alex.janousek@gsa.gov>
2026-03-02 11:55:43 -05:00
dependabot[bot]
1dfafb7728 Bump certifi from 2026.1.4 to 2026.2.25 (#2241)
Bumps [certifi](https://github.com/certifi/python-certifi) from 2026.1.4 to 2026.2.25.
- [Commits](https://github.com/certifi/python-certifi/compare/2026.01.04...2026.02.25)

---
updated-dependencies:
- dependency-name: certifi
  dependency-version: 2026.2.25
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-27 11:53:04 -05:00
dependabot[bot]
a1569223b8 Bump sqlalchemy from 2.0.46 to 2.0.47 (#2243)
Bumps [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) from 2.0.46 to 2.0.47.
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

---
updated-dependencies:
- dependency-name: sqlalchemy
  dependency-version: 2.0.47
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-27 11:49:56 -05:00
dependabot[bot]
03f28ca25a Bump bandit from 1.9.3 to 1.9.4 (#2239)
Bumps [bandit](https://github.com/PyCQA/bandit) from 1.9.3 to 1.9.4.
- [Release notes](https://github.com/PyCQA/bandit/releases)
- [Commits](https://github.com/PyCQA/bandit/compare/1.9.3...1.9.4)

---
updated-dependencies:
- dependency-name: bandit
  dependency-version: 1.9.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-26 13:47:06 -05:00
dependabot[bot]
99f325f5fd Bump virtualenv from 20.38.0 to 21.0.0 (#2240)
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 20.38.0 to 21.0.0.
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](https://github.com/pypa/virtualenv/compare/20.38.0...21.0.0)

---
updated-dependencies:
- dependency-name: virtualenv
  dependency-version: 21.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-26 13:43:42 -05:00
dependabot[bot]
24294972c5 Bump isort from 7.0.0 to 8.0.0 (#2237)
Bumps [isort](https://github.com/PyCQA/isort) from 7.0.0 to 8.0.0.
- [Release notes](https://github.com/PyCQA/isort/releases)
- [Changelog](https://github.com/PyCQA/isort/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PyCQA/isort/compare/7.0.0...8.0.0)

---
updated-dependencies:
- dependency-name: isort
  dependency-version: 8.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-26 17:10:43 +00:00
dependabot[bot]
ff2e8a1c17 Bump faker from 40.4.0 to 40.5.1 (#2235)
Bumps [faker](https://github.com/joke2k/faker) from 40.4.0 to 40.5.1.
- [Release notes](https://github.com/joke2k/faker/releases)
- [Changelog](https://github.com/joke2k/faker/blob/master/CHANGELOG.md)
- [Commits](https://github.com/joke2k/faker/compare/v40.4.0...v40.5.1)

---
updated-dependencies:
- dependency-name: faker
  dependency-version: 40.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-26 17:02:19 +00:00
dependabot[bot]
d6c216c157 Bump newrelic from 11.4.0 to 11.5.0 (#2233)
Bumps [newrelic](https://github.com/newrelic/newrelic-python-agent) from 11.4.0 to 11.5.0.
- [Release notes](https://github.com/newrelic/newrelic-python-agent/releases)
- [Commits](https://github.com/newrelic/newrelic-python-agent/compare/v11.4.0...v11.5.0)

---
updated-dependencies:
- dependency-name: newrelic
  dependency-version: 11.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-26 16:53:52 +00:00
Alex Janousek
8420d602a2 Updaed poetry (#2238) 2026-02-25 13:02:45 -08:00
dependabot[bot]
9250b19fbf Bump flask from 3.1.2 to 3.1.3 (#2231)
Bumps [flask](https://github.com/pallets/flask) from 3.1.2 to 3.1.3.
- [Release notes](https://github.com/pallets/flask/releases)
- [Changelog](https://github.com/pallets/flask/blob/main/CHANGES.rst)
- [Commits](https://github.com/pallets/flask/compare/3.1.2...3.1.3)

---
updated-dependencies:
- dependency-name: flask
  dependency-version: 3.1.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-23 13:34:52 -05:00
dependabot[bot]
b90e103d03 Bump filelock from 3.24.2 to 3.24.3 (#2232)
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.24.2 to 3.24.3.
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/py-filelock/compare/3.24.2...3.24.3)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 3.24.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-23 13:32:48 -05:00
dependabot[bot]
dbebb24690 Bump regex from 2026.1.15 to 2026.2.19 (#2234)
Bumps [regex](https://github.com/mrabarnett/mrab-regex) from 2026.1.15 to 2026.2.19.
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](https://github.com/mrabarnett/mrab-regex/compare/2026.1.15...2026.2.19)

---
updated-dependencies:
- dependency-name: regex
  dependency-version: 2026.2.19
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-23 13:28:38 -05:00
dependabot[bot]
e4c61ca897 Bump virtualenv from 20.37.0 to 20.38.0 (#2229)
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 20.37.0 to 20.38.0.
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](https://github.com/pypa/virtualenv/compare/20.37.0...20.38.0)

---
updated-dependencies:
- dependency-name: virtualenv
  dependency-version: 20.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-20 11:23:19 -05:00
dependabot[bot]
8b45b72e03 Bump virtualenv from 20.36.1 to 20.37.0 (#2226)
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 20.36.1 to 20.37.0.
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](https://github.com/pypa/virtualenv/commits)

---
updated-dependencies:
- dependency-name: virtualenv
  dependency-version: 20.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-18 08:49:54 -05:00
dependabot[bot]
5803215c9a Bump hypothesis from 6.151.8 to 6.151.9 (#2227)
Bumps [hypothesis](https://github.com/HypothesisWorks/hypothesis) from 6.151.8 to 6.151.9.
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](https://github.com/HypothesisWorks/hypothesis/compare/hypothesis-python-6.151.8...hypothesis-python-6.151.9)

---
updated-dependencies:
- dependency-name: hypothesis
  dependency-version: 6.151.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-18 08:34:49 -05:00
dependabot[bot]
adede6f78b Bump pytest-env from 1.3.2 to 1.5.0 (#2228)
Bumps [pytest-env](https://github.com/pytest-dev/pytest-env) from 1.3.2 to 1.5.0.
- [Release notes](https://github.com/pytest-dev/pytest-env/releases)
- [Commits](https://github.com/pytest-dev/pytest-env/compare/1.3.2...1.5.0)

---
updated-dependencies:
- dependency-name: pytest-env
  dependency-version: 1.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-18 08:19:44 -05:00
dependabot[bot]
f51eb6c157 Bump hypothesis from 6.151.6 to 6.151.8 (#2224)
Bumps [hypothesis](https://github.com/HypothesisWorks/hypothesis) from 6.151.6 to 6.151.8.
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](https://github.com/HypothesisWorks/hypothesis/compare/hypothesis-python-6.151.6...hypothesis-python-6.151.8)

---
updated-dependencies:
- dependency-name: hypothesis
  dependency-version: 6.151.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-17 11:54:39 -05:00
dependabot[bot]
914efac7e6 Bump filelock from 3.21.2 to 3.24.2 (#2225)
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.21.2 to 3.24.2.
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/py-filelock/compare/3.21.2...3.24.2)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 3.24.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-17 11:49:35 -05:00
dependabot[bot]
05849703b8 Bump gunicorn from 25.0.3 to 25.1.0 (#2221)
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 25.0.3 to 25.1.0.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/25.0.3...25.1.0)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 25.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-16 15:38:20 -05:00
dependabot[bot]
e8ca918db0 Bump filelock from 3.21.0 to 3.21.2 (#2222)
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.21.0 to 3.21.2.
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/py-filelock/compare/3.21.0...3.21.2)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 3.21.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-16 15:29:56 -05:00
dependabot[bot]
77976a9b06 Bump phonenumbers from 9.0.23 to 9.0.24 (#2223)
Bumps [phonenumbers](https://github.com/daviddrysdale/python-phonenumbers) from 9.0.23 to 9.0.24.
- [Commits](https://github.com/daviddrysdale/python-phonenumbers/compare/v9.0.23...v9.0.24)

---
updated-dependencies:
- dependency-name: phonenumbers
  dependency-version: 9.0.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-16 15:21:31 -05:00
dependabot[bot]
7ad499eb97 Bump filelock from 3.20.3 to 3.21.0 (#2220)
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.20.3 to 3.21.0.
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](https://github.com/tox-dev/py-filelock/compare/3.20.3...3.21.0)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 3.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-13 09:43:40 -05:00
dependabot[bot]
a99685a6a0 Bump cloudfoundry-client from 1.40.2 to 1.40.3 (#2216)
* Bump cloudfoundry-client from 1.40.2 to 1.40.3

Bumps [cloudfoundry-client](https://github.com/cloudfoundry-community/cf-python-client) from 1.40.2 to 1.40.3.
- [Commits](https://github.com/cloudfoundry-community/cf-python-client/compare/v1.40.2...v1.40.3)

---
updated-dependencies:
- dependency-name: cloudfoundry-client
  dependency-version: 1.40.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Fixing security issues

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Alex Janousek <alex.janousek@gsa.gov>
2026-02-12 15:52:54 +00:00
dependabot[bot]
4896e72306 Bump pytest-env from 1.2.0 to 1.3.0 (#2218)
Bumps [pytest-env](https://github.com/pytest-dev/pytest-env) from 1.2.0 to 1.3.0.
- [Release notes](https://github.com/pytest-dev/pytest-env/releases)
- [Commits](https://github.com/pytest-dev/pytest-env/compare/1.2.0...1.3.0)

---
updated-dependencies:
- dependency-name: pytest-env
  dependency-version: 1.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-12 15:08:21 +00:00
dependabot[bot]
09bc850e6b Bump cachetools from 7.0.0 to 7.0.1 (#2217)
Bumps [cachetools](https://github.com/tkem/cachetools) from 7.0.0 to 7.0.1.
- [Changelog](https://github.com/tkem/cachetools/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/tkem/cachetools/compare/v7.0.0...v7.0.1)

---
updated-dependencies:
- dependency-name: cachetools
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-12 14:59:13 +00:00
dependabot[bot]
27b37c7a5e Bump hypothesis from 6.151.5 to 6.151.6 (#2219)
Bumps [hypothesis](https://github.com/HypothesisWorks/hypothesis) from 6.151.5 to 6.151.6.
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](https://github.com/HypothesisWorks/hypothesis/compare/hypothesis-python-6.151.5...hypothesis-python-6.151.6)

---
updated-dependencies:
- dependency-name: hypothesis
  dependency-version: 6.151.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-12 09:50:42 -05:00
dependabot[bot]
48beb45add Bump alembic from 1.18.3 to 1.18.4 (#2215)
Bumps [alembic](https://github.com/sqlalchemy/alembic) from 1.18.3 to 1.18.4.
- [Release notes](https://github.com/sqlalchemy/alembic/releases)
- [Changelog](https://github.com/sqlalchemy/alembic/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/alembic/commits)

---
updated-dependencies:
- dependency-name: alembic
  dependency-version: 1.18.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-11 14:17:53 +00:00
dependabot[bot]
049f52d9dc Bump cryptography from 46.0.4 to 46.0.5 (#2214)
Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.4 to 46.0.5.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/46.0.4...46.0.5)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 46.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-11 09:08:23 -05:00
dependabot[bot]
05a5e33dc3 Bump moto from 5.1.20 to 5.1.21 (#2210)
Bumps [moto](https://github.com/getmoto/moto) from 5.1.20 to 5.1.21.
- [Release notes](https://github.com/getmoto/moto/releases)
- [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md)
- [Commits](https://github.com/getmoto/moto/compare/5.1.20...5.1.21)

---
updated-dependencies:
- dependency-name: moto
  dependency-version: 5.1.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-10 16:25:41 +00:00
dependabot[bot]
fc5e356cad Bump setuptools from 81.0.0 to 82.0.0 (#2212)
Bumps [setuptools](https://github.com/pypa/setuptools) from 81.0.0 to 82.0.0.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](https://github.com/pypa/setuptools/compare/v81.0.0...v82.0.0)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-version: 82.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-10 16:16:58 +00:00
dependabot[bot]
de73d515ac Bump gunicorn from 25.0.1 to 25.0.3 (#2211)
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 25.0.1 to 25.0.3.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/25.0.1...25.0.3)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 25.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-10 16:07:55 +00:00
dependabot[bot]
f9322ecfa2 Bump faker from 40.1.2 to 40.4.0 (#2213)
Bumps [faker](https://github.com/joke2k/faker) from 40.1.2 to 40.4.0.
- [Release notes](https://github.com/joke2k/faker/releases)
- [Changelog](https://github.com/joke2k/faker/blob/master/CHANGELOG.md)
- [Commits](https://github.com/joke2k/faker/compare/v40.1.2...v40.4.0)

---
updated-dependencies:
- dependency-name: faker
  dependency-version: 40.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-10 10:59:20 -05:00
dependabot[bot]
e516878565 Bump setuptools from 80.10.2 to 81.0.0 (#2209)
Bumps [setuptools](https://github.com/pypa/setuptools) from 80.10.2 to 81.0.0.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](https://github.com/pypa/setuptools/compare/v80.10.2...v81.0.0)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-version: 81.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-09 11:40:52 -05:00
dependabot[bot]
afe927728a Bump phonenumbers from 9.0.22 to 9.0.23 (#2206)
Bumps [phonenumbers](https://github.com/daviddrysdale/python-phonenumbers) from 9.0.22 to 9.0.23.
- [Commits](https://github.com/daviddrysdale/python-phonenumbers/compare/v9.0.22...v9.0.23)

---
updated-dependencies:
- dependency-name: phonenumbers
  dependency-version: 9.0.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-06 14:17:16 +00:00
dependabot[bot]
e557f236f9 Bump marshmallow from 4.2.1 to 4.2.2 (#2207)
Bumps [marshmallow](https://github.com/marshmallow-code/marshmallow) from 4.2.1 to 4.2.2.
- [Changelog](https://github.com/marshmallow-code/marshmallow/blob/dev/CHANGELOG.rst)
- [Commits](https://github.com/marshmallow-code/marshmallow/compare/4.2.1...4.2.2)

---
updated-dependencies:
- dependency-name: marshmallow
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-06 09:08:42 -05:00
dependabot[bot]
7ff7263717 Bump hypothesis from 6.151.4 to 6.151.5 (#2205)
Bumps [hypothesis](https://github.com/HypothesisWorks/hypothesis) from 6.151.4 to 6.151.5.
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](https://github.com/HypothesisWorks/hypothesis/compare/hypothesis-python-6.151.4...hypothesis-python-6.151.5)

---
updated-dependencies:
- dependency-name: hypothesis
  dependency-version: 6.151.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-04 09:58:52 -05:00
dependabot[bot]
b2bd1d52b2 Bump gunicorn from 24.1.1 to 25.0.1 (#2203)
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 24.1.1 to 25.0.1.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](https://github.com/benoitc/gunicorn/compare/24.1.1...25.0.1)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 25.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-03 14:52:29 +00:00
17 changed files with 846 additions and 811 deletions

View File

@@ -133,7 +133,7 @@
"filename": ".github/workflows/checks.yml",
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
"is_verified": false,
"line_number": 28,
"line_number": 29,
"is_secret": false
},
{
@@ -141,7 +141,7 @@
"filename": ".github/workflows/checks.yml",
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
"is_verified": false,
"line_number": 45,
"line_number": 46,
"is_secret": false
}
],
@@ -151,7 +151,7 @@
"filename": ".github/workflows/daily_checks.yml",
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
"is_verified": false,
"line_number": 63,
"line_number": 66,
"is_secret": false
},
{
@@ -159,7 +159,7 @@
"filename": ".github/workflows/daily_checks.yml",
"hashed_secret": "5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8",
"is_verified": false,
"line_number": 79,
"line_number": 82,
"is_secret": false
}
],
@@ -374,5 +374,5 @@
}
]
},
"generated_at": "2025-09-11T16:22:46Z"
"generated_at": "2026-06-02T14:59:28Z"
}

View File

@@ -10,12 +10,12 @@ runs:
&& sudo apt-get install -y --no-install-recommends \
libcurl4-openssl-dev
- name: Set up Python 3.13.2
uses: actions/setup-python@v4
uses: actions/setup-python@v6
with:
python-version: "3.13.2"
- name: Install poetry
shell: bash
run: pip install poetry==2.1.3
run: pip install poetry==2.3.4
- name: Install poetry export
shell: bash
run: poetry self add poetry-plugin-export

View File

@@ -3,16 +3,19 @@
# Please see the documentation for all configuration options:
# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates
# Note: Setting open-pull-requests-limit to 0 disables automatic version update PRs.
# Security updates are still active and managed separately in repository settings under
# "Security & analysis" > "Dependabot security updates"
version: 2
updates:
- package-ecosystem: "pip" # See documentation for possible values
directory: "/" # Location of package manifests
schedule:
interval: "daily"
open-pull-requests-limit: 0 # Disable version update PRs; security updates still active
labels:
- "dependabot" # Custom label to identify Dependabot PRs
assignees:
- "alexjanousekGSA"
ignore:
# gevent 25.8+ breaks Celery/Kombu compatibility (potentially)
- dependency-name: "gevent"

View File

@@ -19,7 +19,7 @@ jobs:
run: exit 0
- name: checkout main branch
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: main
ssh-key: ${{ secrets.SSH_PRIVATE_KEY }}

View File

@@ -14,6 +14,7 @@ env:
WERKZEUG_DEBUG_PIN: off
REDIS_ENABLED: 0
AWS_US_TOLL_FREE_NUMBER: "+18556438890"
ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION: true
jobs:
@@ -37,7 +38,7 @@ jobs:
- 5432:5432
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Install application dependencies
run: make bootstrap
@@ -70,7 +71,7 @@ jobs:
runs-on: ubuntu-latest
environment: staging
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Install poetry packages
run: poetry install
@@ -84,7 +85,7 @@ jobs:
pip-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Create requirements.txt
run: poetry export --output requirements.txt
@@ -93,11 +94,12 @@ jobs:
inputs: requirements.txt
ignore-vulns: |
PYSEC-2023-312
CVE-2026-4539
static-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Install bandit
run: pip install bandit
@@ -122,7 +124,7 @@ jobs:
# Maps tcp port 5432 on service container to the host
- 5432:5432
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Install application dependencies
run: make bootstrap

View File

@@ -56,7 +56,7 @@ jobs:
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v6
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL

View File

@@ -19,11 +19,13 @@ env:
REDIS_ENABLED: 0
AWS_US_TOLL_FREE_NUMBER: "+18556438890"
jobs:
pip-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Create requirements.txt
run: poetry export --output requirements.txt
@@ -32,8 +34,9 @@ jobs:
inputs: requirements.txt
ignore-vulns: |
PYSEC-2023-312
CVE-2026-4539
- name: Upload pip-audit artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: pip-audit-report
path: /tmp/pip-audit-output.txt
@@ -41,14 +44,14 @@ jobs:
static-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Install bandit
run: pip install bandit
- name: Run scan
run: bandit -r app/ -f txt -o /tmp/bandit-output.txt --confidence-level medium
- name: Upload bandit artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: bandit-report
path: /tmp/bandit-output.txt
@@ -71,7 +74,7 @@ jobs:
# Maps tcp port 5432 on service container to the host
- 5432:5432
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
- uses: ./.github/actions/setup-project
- name: Install application dependencies
run: make bootstrap

View File

@@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest
environment: demo
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
with:
fetch-depth: 2

View File

@@ -16,7 +16,7 @@ jobs:
runs-on: ubuntu-latest
environment: production
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
with:
fetch-depth: 2

View File

@@ -18,7 +18,7 @@ jobs:
environment: staging
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v6
with:
fetch-depth: 2
@@ -113,6 +113,6 @@ jobs:
runs-on: ubuntu-latest
if: ${{ github.event.workflow_run.conclusion == 'failure' }}
steps:
- uses: actions/github-script@v6
- uses: actions/github-script@v9
with:
script: core.setFailed('Checks failed, not deploying')

View File

@@ -13,7 +13,7 @@ jobs:
environment: staging
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v6
# Looks like we need to install Terraform ourselves now!
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
@@ -50,7 +50,7 @@ jobs:
# environment: demo
# steps:
# - name: Checkout
# uses: actions/checkout@v4
# uses: actions/checkout@v6
# with:
# ref: 'production'
@@ -89,7 +89,7 @@ jobs:
environment: production
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v6
with:
ref: 'production'

View File

@@ -16,7 +16,7 @@ jobs:
environment: demo
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v6
# Looks like we need to install Terraform ourselves now!
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
@@ -59,7 +59,7 @@ jobs:
# inspiration: https://learn.hashicorp.com/tutorials/terraform/github-actions#review-actions-workflow
- name: Update PR
uses: actions/github-script@v7
uses: actions/github-script@v9
# we would like to update the PR even when a prior step failed
if: ${{ always() }}
with:

View File

@@ -16,7 +16,7 @@ jobs:
environment: production
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v6
# Looks like we need to install Terraform ourselves now!
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
@@ -59,7 +59,7 @@ jobs:
# inspiration: https://learn.hashicorp.com/tutorials/terraform/github-actions#review-actions-workflow
- name: Update PR
uses: actions/github-script@v7
uses: actions/github-script@v9
# we would like to update the PR even when a prior step failed
if: ${{ always() }}
with:

View File

@@ -16,7 +16,7 @@ jobs:
environment: staging
steps:
- name: Checkout
uses: actions/checkout@v4
uses: actions/checkout@v6
# Looks like we need to install Terraform ourselves now!
# https://github.com/actions/runner-images/issues/10796#issuecomment-2417064348
@@ -60,7 +60,7 @@ jobs:
# inspiration: https://learn.hashicorp.com/tutorials/terraform/github-actions#review-actions-workflow
- name: Update PR
uses: actions/github-script@v7
uses: actions/github-script@v9
# we would like to update the PR even when a prior step failed
if: ${{ always() }}
with:

1510
poetry.lock generated

File diff suppressed because it is too large Load Diff

View File

@@ -9,12 +9,12 @@ readme = "README.md"
[tool.poetry.dependencies]
python = "^3.13.2"
alembic = "==1.18.3"
alembic = "==1.18.4"
amqp = "==5.3.1"
beautifulsoup4 = "==4.14.3"
boto3 = "^1.38.27"
botocore = "^1.38.27"
cachetools = "==7.0.0"
cachetools = "==7.0.1"
celery = {version = "==5.6.2", extras = ["redis"]}
certifi = ">=2022.12.7"
cffi = "==2.0.0"
@@ -24,6 +24,7 @@ click-didyoumean = "==0.3.1"
click-plugins = "==1.1.1.2"
click-repl = "==0.3.0"
deprecated = "==1.3.1"
dulwich = "^1.2.5"
gevent = "==25.5.1"
expiringdict = "==1.2.2"
flask = "~=3.1"
@@ -31,84 +32,85 @@ flask-bcrypt = "==1.0.1"
flask-migrate = "==4.1.0"
flask-redis = "==0.4.0"
flask-sqlalchemy = "^3.1.1"
gunicorn = {version = "==24.1.1", extras = ["gevent"]}
gunicorn = {version = "==25.1.0", extras = ["gevent"]}
iso8601 = "==2.1.0"
jsonschema = {version = "==4.26.0", extras = ["format"]}
lxml = "==6.0.2"
marshmallow = "^4.2.1"
lxml = "==6.1.0"
marshmallow = "^4.2.2"
marshmallow-sqlalchemy = "^1.4.2"
newrelic = "^11.4.0"
newrelic = "^11.5.0"
packaging = "==26.0"
poetry-dotenv-plugin = "==0.2.0"
psycopg2-binary = "==2.9.11"
pyjwt = "==2.10.1"
python-dotenv = "==1.2.1"
sqlalchemy = "==2.0.46"
pyjwt = "==2.13.0"
python-dotenv = "==1.2.2"
sqlalchemy = "==2.0.47"
werkzeug = "^3.1.5"
faker = "^40.1.0"
faker = "^40.5.1"
async-timeout = "^5.0.1"
bleach = "^6.3.0"
geojson = "^3.2.0"
numpy = "^2.4.2"
ordered-set = "^4.1.0"
phonenumbers = "^9.0.22"
phonenumbers = "^9.0.24"
python-json-logger = "^4.0.0"
regex = "^2026.1.15"
regex = "^2026.2.19"
shapely = "^2.1.2"
smartypants = "^2.0.1"
mistune = "^3.2.0"
mistune = "^3.2.1"
blinker = "^1.9.0"
cryptography = "^46.0.4"
idna = "^3.11"
cryptography = "^46.0.7"
idna = "^3.15"
jmespath = "^1.1.0"
markupsafe = "^3.0.3"
mako = "^1.3.12"
pycparser = "^3.0"
python-dateutil = "^2.9.0.post0"
pyyaml = "^6.0.3"
s3transfer = "^0.13.1"
s3transfer = "^0.16.0"
six = "^1.16.0"
urllib3 = "^2.6.3"
webencodings = "^0.5.1"
itsdangerous = "^2.2.0"
jinja2 = "^3.1.6"
redis = "^6.4.0"
requests = "^2.32.5"
virtualenv = "^20.36.1"
requests = "^2.33.0"
virtualenv = "^21.1.0"
marshmallow-enum = "^1.5.1"
awscli = "^1.40.36"
awscli = "^1.44.38"
typing-extensions = "^4.15.0"
aiohttp = "^3.13.3"
aiohttp = "^3.13.4"
pytest = "^9.0.2"
filelock = ">=3.20.3"
pyasn1 = ">=0.6.2"
pyasn1 = ">=0.6.3"
jaraco-context = ">=6.1.0"
wheel = ">=0.46.2"
[tool.poetry.group.dev.dependencies]
bandit = "*"
black = "^26.1.0"
black = "^26.3.1"
cyclonedx-python-lib = "^11.6.0"
cloudfoundry-client = "*"
exceptiongroup = "==1.3.1"
flake8 = "^7.3.0"
flake8-bugbear = "^25.11.29"
freezegun = "^1.5.5"
hypothesis = "^6.151.4"
hypothesis = "^6.151.9"
honcho = "*"
isort = "^7.0.0"
isort = "^8.0.0"
jinja2-cli = {version = "==1.0.0", extras = ["yaml"]}
moto = "==5.1.20"
moto = "==5.1.21"
pip-audit = "*"
pre-commit = "^4.5.1"
pytest = "^9.0.2"
pytest-env = "^1.2.0"
pytest-env = "^1.5.0"
pytest-mock = "^3.15.1"
pytest-cov = "^7.0.0"
pytest-xdist = "^3.8.0"
radon = "^6.0.1"
requests-mock = "^1.11.0"
setuptools = "^80.9.0"
setuptools = "^82.0.0"
sqlalchemy-utils = "^0.41.2"
vulture = "^2.10"
detect-secrets = "^1.5.0"

View File

@@ -238,12 +238,11 @@ def test_decode_jwt_token_returns_error_with_no_secrets(client):
assert exc.value.short_message == "Invalid token: API key not found"
@pytest.mark.parametrize("service_id", ["not-a-valid-id", 1234])
def test_requires_auth_should_not_allow_service_id_with_the_wrong_data_type(
client, service_jwt_secret, service_id
client, service_jwt_secret
):
token = create_jwt_token(
client_id=service_id,
client_id="not-a-valid-id",
secret=service_jwt_secret,
)
@@ -256,6 +255,16 @@ def test_requires_auth_should_not_allow_service_id_with_the_wrong_data_type(
)
def test_requires_auth_should_not_allow_service_id_with_a_non_string(
client, service_jwt_secret
):
with pytest.raises(TypeError):
create_jwt_token(
client_id=1234,
secret=service_jwt_secret,
)
def test_requires_auth_returns_error_when_service_doesnt_exist(client, sample_api_key):
# get service ID and secret the wrong way around
token = create_jwt_token(