Repository navigation
deps: Update stripe requirement from <16,>=15.6.1 to >=16.0.0,<17 - #204
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [stripe](https://github.com/stripe/stripe-python) to permit the latest version. - [Release notes](https://github.com/stripe/stripe-python/releases) - [Changelog](https://github.com/stripe/stripe-python/blob/master/CHANGELOG.md) - [Commits](stripe/stripe-python@v15.6.1...v16.0.0) --- updated-dependencies: - dependency-name: stripe dependency-version: 16.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
MrChengLen
added a commit
that referenced
this pull request
Oct 8, 2026
…ntil their ports Both majors need code changes first: WeasyPrint 70 reworks the url_fetcher interface the SSRF guard relies on, and stripe 16 pins an API version that rejects payment_method_types on Checkout session creation. Excluded from the python-all group, they arrived as standalone PRs (#191, #204) that could only sit red. Like the existing cyclonedx-bom and pikepdf caps, they are now `ignore`d by version range (>=70, >=16); Dependabot raises floors below a cap and keeps the cap (seen with b75b56c on pikepdf/cyclonedx-bom). Patch and minor releases below the caps now come in the weekly batch. New guard test_dependabot_ignores_sit_on_live_caps: every pip ignore range must match a cap in requirements*.txt, so a port that lifts a cap but forgets the ignore fails CI instead of freezing the package silently (mutation- checked). requirements.txt's cap comments say so too. Two earlier unreleased fragments and the dependabot.yml header are corrected for the new behaviour. Dependabot security updates and alerts are off on this repo, so the ignores suppress nothing security-wise; pip-audit on requirements.lock stays the CVE gate. Verified: full suite 1734 passed / 123 skipped; ruff clean; gitleaks and the pre-commit scope guard clean. Code review done, findings applied. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
Looks like stripe is no longer being updated by Dependabot, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on stripe to permit the latest version.
Release notes
Sourced from stripe's releases.
Changelog
Sourced from stripe's changelog.
... (truncated)
Commits
2936309Bump version to 16.0.0797b959Add v16 migration guidance links (#1935)4848f6fMerge pull request #1932 from stripe/latest-codegen-master000b6f2Update generated code for v2526 and 588801ef34f7b5f7d6a784d3354f5f93d2a26ffb78aebc7Update generated code for v2526 and adad04916772f880317eac10d8c026b401863f1d ...b48375aPin stripe-mock to the SDK OpenAPI version (#1927)b7ba58eMerge pull request #1917 from stripe/sdk-release/next-major8427c15Revise migration guide for SDK v16 API changes6529349Make remaining overloaded method args positional only and remove unecessary s...872b1aeRename Reversal to TransferReversal (#1915)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)