Repository navigation
chore(deps): update dependencies and bump ruff to 0.16.10 - #236
Merged
Merged
Conversation
Refresh the uv lockfile to the latest compatible releases (fastapi 0.142.2, starlette 1.7.0, uvicorn 0.54.0, pydantic 2.13.5, lxml 6.1.3, coverage 7.16.2, ruff 0.16.10 among others). Raise the declared lower bounds for fastapi, uvicorn and ruff to match, and align the ruff-pre-commit rev with the pinned ruff version.
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Refreshed the
uvlockfile to the latest compatible releases, aligned the declared version bounds, and bumped theuvbase image used in both Dockerfiles.Notable direct dependency bumps:
Notable transitive bumps: starlette 1.3.1 -> 1.7.0, pydantic 2.13.4 -> 2.13.5, lxml 6.1.1 -> 6.1.3, coverage 7.14.3 -> 7.16.2, urllib3 2.7.0 -> 2.8.0, anyio 4.14.0 -> 4.15.1, wrapt 2.2.2 -> 2.5.0, deprecated 1.3.1 -> 3.0.0.
opentelemetry-apiis pulled in as a new transitive dependency ofdeprecated3.x.Also bumped the
ruff-pre-commitrev from v0.14.14 to v0.16.10 so pre-commit matches the version pinned inpyproject.toml, and bumped theghcr.io/astral-sh/uvbase image from 0.12.3 to 0.12.23 inDockerfileandDockerfile.lambda.This supersedes and replaces #235 and #233 (both closed), which only covered a subset of these bumps.
Security
This clears all 4 Dependabot alerts that were open on
main:Testing
uv run ruff check .- all checks passeduv run ruff format --check .- 30 files already formatteduv run python -m pytest -v --cov=drillapi- 43 passed, 94% coveragedocker build -f Dockerfile .anddocker build -f Dockerfile.lambda .both build successfully with the bumped uv imageNo source changes were needed.
Known pre-existing CI issues (not introduced by this PR)
ecr-build-scan-push.yml@v9whilepublish-ecr.ymlmoved to@v12. Pre-existing version drift, unrelated to this change.public.ecr.aws/lambda/python:3.14), mainly libxml2 CVEs. AWS has not yet published the patched RPM (dnf upgradestill reports Nothing to do); confirmed with a local build.Follow-up
Starlette 1.7.0 emits a new deprecation warning: using
httpxwithstarlette.testclientis deprecated in favour ofhttpx2. Tests still pass, but migrating the test client dependency is worth a separate PR oncerespxsupportshttpx2.