Skip to content

Update all dependencies - #297

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all
Open

Update all dependencies#297
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Mar 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/checkout action major v6v7 age confidence
actions/setup-python action major v6v7 age confidence
codecov/codecov-action action major v5v7 age confidence
mypy (changelog) dev major 1.19.12.3.1 age confidence
pubtools-pulplib (changelog) dependencies minor 2.44.02.45.0 age confidence
snok/install-poetry (changelog) action digest 76e04a9a783c32

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source

actions/setup-python (actions/setup-python)

v7.0.0

Compare Source

codecov/codecov-action (codecov/codecov-action)

v7.0.0

Compare Source

⚠️ Due to migration issues with keybase, we are unable to update our keys under the codecovsecurity account. We have deleted the account and are using codecovsecops with the original gpg key

What's Changed

Full Changelog: codecov/codecov-action@v6.0.1...v7.0.0

v6.0.2

Compare Source

This is a copy of the v7.0.0 release to make updates easier

What's Changed

Full Changelog: codecov/codecov-action@v6.0.1...v6.0.2

v6.0.1

Compare Source

What's Changed

Full Changelog: codecov/codecov-action@v6.0.0...v6.0.1

v6.0.0

Compare Source

⚠️ This version introduces support for node24 which make cause breaking changes for systems that do not currently support node24. ⚠️
What's Changed

Full Changelog: codecov/codecov-action@v5.5.4...v6.0.0

python/mypy (mypy)

v2.3.1

Compare Source

v2.3.0

Compare Source

v2.2.0

Compare Source

v2.1.0

Compare Source

v2.0.0

Compare Source

v1.20.2

Compare Source

v1.20.1

Compare Source

  • Always disable sync in SQLite cache (Ivan Levkivskyi, PR 21184)
  • Temporarily skip few base64 tests (Ivan Levkivskyi, PR 21193)
  • Revert dict.__or__ typeshed change (Ivan Levkivskyi, PR 21186)
  • Fix narrowing for match case with variadic tuples (Shantanu, PR 21192)
  • Avoid narrowing type[T] in type calls (Shantanu, PR 21174)
  • Fix regression for catching empty tuple in except (Shantanu, PR 21153)
  • Fix reachability for frozenset and dict view narrowing (Shantanu, PR 21151)
  • Fix narrowing with chained comparison (Shantanu, PR 21150)
  • Avoid narrowing to unreachable at module level (Shantanu, PR 21144)
  • Allow dangerous identity comparisons to Any typed variables (Shantanu, PR 21142)
  • --warn-unused-config should not be a strict flag (Ivan Levkivskyi, PR 21139)

v1.20.0

Compare Source

release-engineering/pubtools-pulplib (pubtools-pulplib)

v2.45.0

Compare Source

Added
  • get_distribution() method for pulp3 client

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested review from drepelov and rbikar as code owners March 28, 2026 00:46
@codecov

codecov Bot commented Mar 28, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.71%. Comparing base (068a446) to head (04834e9).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #297   +/-   ##
=======================================
  Coverage   98.71%   98.71%           
=======================================
  Files           6        6           
  Lines         701      701           
=======================================
  Hits          692      692           
  Misses          9        9           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@renovate renovate Bot changed the title Update codecov/codecov-action action to v6 Update all dependencies Mar 31, 2026
@renovate

renovate Bot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: poetry.lock
Updating dependencies
Resolving dependencies...

Creating virtualenv ubi-population-tool-crxXe_nh-py3.14 in /home/ubuntu/.cache/pypoetry/virtualenvs

The current project's supported Python range (>=3.9,<3.15) is not compatible with some of the required packages Python requirement:
  - mypy requires Python >=3.10, so it will not be installable for Python >=3.9,<3.10

Because ubi-population-tool depends on mypy (2.3.1) which requires Python >=3.10, version solving failed.

  * Check your dependencies Python requirement: The Python requirement can be specified via the `python` or `markers` properties

    For mypy, a possible solution would be to set the `python` property to ">=3.10,<3.15"

    https://python-poetry.org/docs/dependency-specification/#python-restricted-dependencies,
    https://python-poetry.org/docs/dependency-specification/#using-environment-markers


@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from ed0e951 to 7fe25ef Compare April 17, 2026 10:35
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from afa6b24 to d2a3e26 Compare May 6, 2026 21:55
@renovate
renovate Bot force-pushed the renovate/all branch from d2a3e26 to 7669111 Compare May 11, 2026 18:50
@renovate
renovate Bot force-pushed the renovate/all branch from 7669111 to acc7d05 Compare May 18, 2026 21:14
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 60ab3d0 to df6e28c Compare June 3, 2026 16:48
@renovate
renovate Bot force-pushed the renovate/all branch from df6e28c to c0d3cc8 Compare June 7, 2026 04:48
@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 6a360e2 to 7251445 Compare June 25, 2026 08:24
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 2df3ed7 to e79cc87 Compare July 13, 2026 11:47
@coderabbitai

coderabbitai Bot commented Jul 13, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated automated documentation, release, testing, coverage, and security workflows to use refreshed, verified tooling versions.
    • Updated static type-checking tooling to improve compatibility with current development environments.
    • Improved the reliability and security of automated project maintenance checks.
    • Existing build, test, documentation, and publishing processes remain unchanged.

Walkthrough

The pull request updates pinned GitHub Actions revisions across documentation, release, test, coverage, and security workflows. It also upgrades the Poetry development dependency mypy from 1.19.1 to 2.3.0.

Changes

CI and tooling updates

Layer / File(s) Summary
Workflow action pin updates
.github/workflows/docs.yml, .github/workflows/release.yml
Pinned checkout, Python setup, and Poetry installation action revisions were updated.
Test workflow action updates
.github/workflows/tox-test.yml
Pinned action revisions were updated across test, coverage, and security jobs. The Codecov action now uses a pinned v7 revision.
Mypy development dependency update
pyproject.toml
The mypy development dependency was updated from 1.19.1 to 2.3.0.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: rbikar, drepelov

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The changes do not address the linked issue objectives for pytest compatibility or serialization failures. Implement or document the required pytest and test serialization fixes, or remove the linked issue objectives from this pull request.
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check ✅ Passed The title accurately identifies the dependency updates, although it is broader than the specific changes.
Description check ✅ Passed The description clearly documents the dependency and GitHub Actions updates in the changeset.
Out of Scope Changes check ✅ Passed The changes are limited to dependency and GitHub Actions updates and are consistent with the stated dependency-update scope.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/all

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/tox-test.yml:
- Line 9: Disable credential persistence on every actions/checkout step in
.github/workflows/tox-test.yml at lines 9-9, 25-25, 41-41, 59-59, 86-86, and
102-102, and in .github/workflows/docs.yml at 10-10 and
.github/workflows/release.yml at 12-12 by setting persist-credentials to false.
In docs.yml, give scripts/push-docs a separate narrowly scoped credential;
release.yml requires no persisted GitHub token.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: 807014a7-44eb-4195-9fd2-e4bb85acfdac

📥 Commits

Reviewing files that changed from the base of the PR and between ac5c1a1 and e79cc87.

📒 Files selected for processing (4)
  • .github/workflows/docs.yml
  • .github/workflows/release.yml
  • .github/workflows/tox-test.yml
  • pyproject.toml

Comment thread .github/workflows/tox-test.yml Outdated
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== workflow files ==\n'
git ls-files '.github/workflows/*.yml' '.github/workflows/*.yaml'

printf '\n== tox-test.yml ==\n'
cat -n .github/workflows/tox-test.yml

printf '\n== docs.yml ==\n'
cat -n .github/workflows/docs.yml

printf '\n== release.yml ==\n'
cat -n .github/workflows/release.yml

printf '\n== references to push-docs / git push / checkout ==\n'
rg -n "push-docs|git push|actions/checkout|persist-credentials|GITHUB_TOKEN|token:" .github/workflows README.md . -g '!**/.git/**'

Repository: release-engineering/ubi-population-tool

Length of output: 8087


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== workflow file sizes ==\n'
wc -l .github/workflows/tox-test.yml .github/workflows/docs.yml .github/workflows/release.yml

printf '\n== targeted slices ==\n'
sed -n '1,140p' .github/workflows/tox-test.yml
printf '\n--- docs.yml ---\n'
sed -n '1,80p' .github/workflows/docs.yml
printf '\n--- release.yml ---\n'
sed -n '1,80p' .github/workflows/release.yml

Repository: release-engineering/ubi-population-tool

Length of output: 5819


🏁 Script executed:

#!/bin/bash
set -euo pipefail

python3 - <<'PY'
from pathlib import Path
for path in [Path('.github/workflows/tox-test.yml'), Path('.github/workflows/docs.yml'), Path('.github/workflows/release.yml')]:
    print(f'== {path} ==')
    for i, line in enumerate(path.read_text().splitlines(), 1):
        if 'actions/checkout' in line or 'persist-credentials' in line or 'push-docs' in line or 'GITHUB_TOKEN' in line or 'token:' in line or 'uses:' in line and 'checkout' not in line:
            print(f'{i}: {line}')
    print()
PY

Repository: release-engineering/ubi-population-tool

Length of output: 2345


Disable checkout credential persistence on these workflow steps.

Set persist-credentials: false on the actions/checkout steps in .github/workflows/tox-test.yml, .github/workflows/docs.yml, and .github/workflows/release.yml; otherwise later repository-controlled commands can read GITHUB_TOKEN from .git/config.

  • In docs.yml, give scripts/push-docs its own narrowly scoped credential.
  • In release.yml, checkout does not need GitHub token persistence at all.
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 9-9: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

📍 Affects 3 files
  • .github/workflows/tox-test.yml#L9-L9 (this comment)
  • .github/workflows/tox-test.yml#L25-L25
  • .github/workflows/tox-test.yml#L41-L41
  • .github/workflows/tox-test.yml#L59-L59
  • .github/workflows/tox-test.yml#L86-L86
  • .github/workflows/tox-test.yml#L102-L102
  • .github/workflows/docs.yml#L10-L10
  • .github/workflows/release.yml#L12-L12
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/tox-test.yml at line 9, Disable credential persistence on
every actions/checkout step in .github/workflows/tox-test.yml at lines 9-9,
25-25, 41-41, 59-59, 86-86, and 102-102, and in .github/workflows/docs.yml at
10-10 and .github/workflows/release.yml at 12-12 by setting persist-credentials
to false. In docs.yml, give scripts/push-docs a separate narrowly scoped
credential; release.yml requires no persisted GitHub token.

Sources: Path instructions, Linters/SAST tools

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.github/workflows/tox-test.yml (1)

22-37: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Set explicit permissions: contents: read on these jobs.

  • .github/workflows/tox-test.yml: add the block to py313 and static; they only need repo read access for checkout.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/tox-test.yml around lines 22 - 37, Add job-level
permissions to both the py313 and static jobs in tox-test.yml, setting contents
to read for each. No other workflow behavior needs to change.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release.yml:
- Line 12: Update the actions/checkout step in the release workflow to set
persist-credentials to false, preventing the GitHub token from being retained in
the repository configuration while leaving the pinned checkout action unchanged.

---

Nitpick comments:
In @.github/workflows/tox-test.yml:
- Around line 22-37: Add job-level permissions to both the py313 and static jobs
in tox-test.yml, setting contents to read for each. No other workflow behavior
needs to change.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: b335f0ac-83b7-457f-a397-fa9f43e69b88

📥 Commits

Reviewing files that changed from the base of the PR and between e79cc87 and 1493a69.

📒 Files selected for processing (4)
  • .github/workflows/docs.yml
  • .github/workflows/release.yml
  • .github/workflows/tox-test.yml
  • pyproject.toml
🚧 Files skipped from review as they are similar to previous changes (1)
  • pyproject.toml

Comment thread .github/workflows/release.yml Outdated
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Disable checkout credential persistence.

actions/checkout stores the GitHub token in the local repository configuration. If the release workspace is accidentally included in a build artifact or exposed by a later step, that token can leak. Add persist-credentials: false; the workflow does not need authenticated Git operations after checkout.

Proposed fix
     - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
+      with:
+        persist-credentials: false
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
persist-credentials: false
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release.yml at line 12, Update the actions/checkout step
in the release workflow to set persist-credentials to false, preventing the
GitHub token from being retained in the repository configuration while leaving
the pinned checkout action unchanged.

Source: Linters/SAST tools

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/tox-test.yml:
- Around line 22-37: Declare workflow-level permissions in
.github/workflows/tox-test.yml with contents: read for the default jobs,
including py312, py313, static, bandit, and bandit-exitzero. Configure the
coverage job separately with contents: read and id-token: write so checkout and
Codecov continue to work.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: e6f5a9d4-db00-43e5-adbf-2840846d194d

📥 Commits

Reviewing files that changed from the base of the PR and between 1493a69 and cf18c05.

📒 Files selected for processing (4)
  • .github/workflows/docs.yml
  • .github/workflows/release.yml
  • .github/workflows/tox-test.yml
  • pyproject.toml
🚧 Files skipped from review as they are similar to previous changes (1)
  • pyproject.toml

Comment on lines 22 to 37
py313:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
- name: Setup Python
uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
with:
python-version: "3.13"
- name: Install base packages
run: sudo apt-get install gcc python3-dev libkrb5-dev
- name: Install Tox
run: pip install tox
- name: Install Poetry
uses: snok/install-poetry@76e04a911780d5b312d89783f7b1cd627778900a # v1
uses: snok/install-poetry@a783c322200f0519c7926aa6faa857c4e23e9263 # v1
- name: Run Tox
run: tox -e py313

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

git ls-files .github/workflows/tox-test.yml .github/workflows

Repository: release-engineering/ubi-population-tool

Length of output: 265


🏁 Script executed:

cat -n .github/workflows/tox-test.yml

Repository: release-engineering/ubi-population-tool

Length of output: 5086


Declare explicit read-only permissions for this workflow.

py312, py313, static, bandit, and bandit-exitzero all inherit the repo-default GITHUB_TOKEN scope here. Set permissions: contents: read at the workflow level; keep coverage as contents: read, id-token: write so checkout and Codecov still work.

🧰 Tools
🪛 zizmor (1.26.1)

[warning] 25-25: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[warning] 22-37: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block

(excessive-permissions)

📍 Affects 1 file
  • .github/workflows/tox-test.yml#L22-L37 (this comment)
  • .github/workflows/tox-test.yml#L38-L53
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/tox-test.yml around lines 22 - 37, Declare workflow-level
permissions in .github/workflows/tox-test.yml with contents: read for the
default jobs, including py312, py313, static, bandit, and bandit-exitzero.
Configure the coverage job separately with contents: read and id-token: write so
checkout and Codecov continue to work.

Source: Linters/SAST tools

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants