Repository navigation
fix(deps): update dependencies for GA - #63
Merged
Merged
Conversation
Raise scalo to 2.31.1 and refresh uv.lock to the latest release of everything else. No package moves a major version. requirements-docker.txt is re-exported from the new lock, so the image installs exactly what the tests ran against. scalo 2.31 no longer writes vendor keywords or a maintainer into the generated Chart.yaml. The chart overlay now anchors on the app-name keyword and adds culvert's own keywords and maintainer back, so the regenerated chart is byte-identical to the committed one. scalo 2.31 also types its missing-extra stub as NoReturn, which leaves three ty suppressions in lib/deployment.py with nothing to suppress. They are removed, and the module drops the from __future__ import that 3.14 no longer needs. openvpn-auth-oauth2 moves to 2.2.2, a bug-fix release. Both .deb SHA256s match the release's own checksums.txt. watchtower moves to 1.22.3 and is pinned by digest. The manifest carries amd64 and arm64. The fork's URL in the comment is corrected. supply-chain.md and scalo-reference.md quote the new pins, and supply-chain.md names the 26.04 base the Dockerfile already uses.
pip warns on every build that it is installing as root into the system site-packages. The image has no venv by design, so the warning is switched off with --root-user-action=ignore. BuildKit's SecretsUsedInArgOrEnv check flags the two openvpn-auth-oauth2 SHA256 ARGs because their name contains AUTH. They hold public release checksums, and a comment at the ARGs now says so.
The ubuntu:26.04 base moves to its current digest (sha256:f144425f, amd64 and arm64), which carries the latest security patches. wstunnel moves from 10.6.2 to 10.7.1, the newest 10.x; both tarball SHA256s match the release's checksums.txt. 11.0.0 is a major and stays for after GA. ruff now targets py314 to match requires-python, so it formats except clauses in the 3.14 unparenthesised form and drops one quoted annotation.
This was referenced Oct 6, 2026
Contributor
|
Released in v2.1.17 -- https://github.com/hyperi-io/culvert/releases/tag/v2.1.17 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Final dependency pass on culvert before the DFE 2.2 GA build. scalo goes to 2.31.1 and the lock moves everything else to its latest release. It also folds in the two open bot bumps, so #62 and #30 can close once this merges.
What moved:
Held below latest by upstream, not by us: multidict 6.9.1 (aiohttp caps it below 7), botocore 1.43.106 (aiobotocore caps it), pydantic-core 2.46.5 (pydantic pins it).
Security: no open Dependabot or code-scanning alerts on the repo.
Done when every check on this PR is green, including the container build.