Repository navigation
deps: Update weasyprint requirement from <70,>=69.0 to >=70.0,<71 - #191
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
…n and dead triggers gone
An analysis of all ten workflows found that pytest runs once per PR
(lint-and-test). The other PR checks do different jobs: image smoke tests,
external PDF/A validation, secret and scope scans. Three things were real
duplication:
- veraPDF: verapdf.yml rebuilt the environment lint-and-test already had (41
of its 49 s), and no ruleset required it, although the README and the
pricing page call it a CI gate. Its steps (fixture via
scripts/verapdf_check.py, the digest-pinned verapdf/cli run, artifact
upload) now follow the test run in lint-and-test, a required check, so a
PDF/A-2b regression blocks the merge. The container now runs with
`--network none` and a read-only mount, and the upload uses
`if: ${{ !cancelled() }}`. verapdf.yml is gone.
test_verapdf_gate_is_part_of_the_required_lint_and_test_job pins both gate
steps in that job: no step- or job-level `if:` or `continue-on-error`,
`--flavour 2b`, and no `|| true`.
- sbom.yml built the same SBOM on every main push as docker.yml's `sbom` job,
which also attests it to the images. The 90-day artifact had no reader.
sbom.yml keeps workflow_dispatch as the rehearsal for the SBOM steps.
- `develop` triggers in ci.yml and scope-guard.yml: no such branch exists.
Dependabot: Dependabot gives requirements.txt floor raises (`>=a` -> `>=b`)
no update type, so the minor/patch group never caught them. #191-#195 arrived
one by one, and four of them sat red until a lockfile recompile. The pip
group is now `python-all` (patterns: *): one PR a week, one lockfile pass,
after a 3-day cooldown. WeasyPrint stays out of the group (held below 70
until the SSRF url_fetcher guard is ported; it keeps arriving as its own
reminder PR). cyclonedx-bom (>=6) and pikepdf (>=11) are ignored by version
range, because `update-types` cannot match range requirements.
Not consolidated, on purpose: secret-scan and scope-check (two required
contexts, different jobs), lockfile-drift (non-required by design),
deps-latest (weekly unpinned early warning), docker-pr (token isolation from
the push build), the post-merge CI run on main (with non-strict checks, the
only test of the merge result).
Verified on main 93c6ff1: full suite 1663 passed / 80 skipped; workflow guard
tests and the changelog-fragment guard green; YAML parses; ruff clean;
gitleaks and the pre-commit scope guard clean. Security and code review
(commit-review gate) done; their findings are in.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
afc7dcd to
b51281d
Compare
Updates the requirements on [weasyprint](https://github.com/Kozea/WeasyPrint) to permit the latest version. - [Release notes](https://github.com/Kozea/WeasyPrint/releases) - [Changelog](https://github.com/Kozea/WeasyPrint/blob/main/docs/changelog.rst) - [Commits](Kozea/WeasyPrint@v69.0...v70.0) --- updated-dependencies: - dependency-name: weasyprint dependency-version: '70.0' dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
b51281d to
b93ce4c
Compare
…ntil their ports Both majors need code changes first: WeasyPrint 70 reworks the url_fetcher interface the SSRF guard relies on, and stripe 16 pins an API version that rejects payment_method_types on Checkout session creation. Excluded from the python-all group, they arrived as standalone PRs (#191, #204) that could only sit red. Like the existing cyclonedx-bom and pikepdf caps, they are now `ignore`d by version range (>=70, >=16); Dependabot raises floors below a cap and keeps the cap (seen with b75b56c on pikepdf/cyclonedx-bom). Patch and minor releases below the caps now come in the weekly batch. New guard test_dependabot_ignores_sit_on_live_caps: every pip ignore range must match a cap in requirements*.txt, so a port that lifts a cap but forgets the ignore fails CI instead of freezing the package silently (mutation- checked). requirements.txt's cap comments say so too. Two earlier unreleased fragments and the dependabot.yml header are corrected for the new behaviour. Dependabot security updates and alerts are off on this repo, so the ignores suppress nothing security-wise; pip-audit on requirements.lock stays the CVE gate. Verified: full suite 1734 passed / 123 skipped; ruff clean; gitleaks and the pre-commit scope guard clean. Code review done, findings applied. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Closing: WeasyPrint stays below 70 until the |
|
Looks like weasyprint is no longer being updated by Dependabot, so this is no longer needed. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Updates the requirements on weasyprint to permit the latest version.
Release notes
Sourced from weasyprint's releases.
... (truncated)
Changelog
Sourced from weasyprint's changelog.
... (truncated)
Commits
4d3b7b6Version 70.0289e278Always use original URL fetcher when availableaeb3be7Merge remote-tracking branch 'security/main'4835724Merge pull request #2915 from havelaer/fix-nested-svg-viewport-restore0331051Restore nested SVG viewport size on the SVG object, not the drawing functione4b8b45Add harfbuzz-vector requirement for Fedora371e4deMerge pull request #2905 from Kozea/notes590bf63Merge pull request #2913 from Kozea/fast-svg-pathsf6570c3Use a faster regex-based parser for SVG pathsbc05162Use faster deque for SVG vertices