Skip to content

Dependency updates#94

Merged
GitTimeraider merged 21 commits intomainfrom
develop
Apr 10, 2026
Merged

Dependency updates#94
GitTimeraider merged 21 commits intomainfrom
develop

Conversation

@GitTimeraider
Copy link
Copy Markdown
Owner

Dependency updates

dependabot Bot and others added 21 commits March 26, 2026 02:05
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps python from 3.13-slim to 3.14-slim.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.14-slim
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [werkzeug](https://github.com/pallets/werkzeug) from 3.1.6 to 3.1.7.
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.6...3.1.7)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-version: 3.1.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [requests](https://github.com/psf/requests) from 2.32.5 to 2.33.0.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.32.5...v2.33.0)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v3...v4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 25.1.0 to 25.2.0.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](benoitc/gunicorn@25.1.0...25.2.0)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 25.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…ests-2.33.0

Bump requests from 2.32.5 to 2.33.0
…evelop/github/codeql-action-4

Bump github/codeql-action from 3 to 4
…zeug-3.1.7

Bump werkzeug from 3.1.6 to 3.1.7
…evelop/actions/checkout-6

Bump actions/checkout from 4 to 6
…ython-3.14-slim

Bump python from 3.13-slim to 3.14-slim
…corn-25.2.0

Bump gunicorn from 25.1.0 to 25.2.0
Updated pull request branch for Docker build workflow.
Bumps [requests](https://github.com/psf/requests) from 2.33.0 to 2.33.1.
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.33.0...v2.33.1)

---
updated-dependencies:
- dependency-name: requests
  dependency-version: 2.33.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gunicorn](https://github.com/benoitc/gunicorn) from 25.2.0 to 25.3.0.
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](benoitc/gunicorn@25.2.0...25.3.0)

---
updated-dependencies:
- dependency-name: gunicorn
  dependency-version: 25.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…corn-25.3.0

Bump gunicorn from 25.2.0 to 25.3.0
…ests-2.33.1

Bump requests from 2.33.0 to 2.33.1
Bumps [werkzeug](https://github.com/pallets/werkzeug) from 3.1.7 to 3.1.8.
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.7...3.1.8)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-version: 3.1.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) from 2.0.48 to 2.0.49.
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

---
updated-dependencies:
- dependency-name: sqlalchemy
  dependency-version: 2.0.49
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…zeug-3.1.8

Bump werkzeug from 3.1.7 to 3.1.8
…lchemy-2.0.49

Bump sqlalchemy from 2.0.48 to 2.0.49
Copilot AI review requested due to automatic review settings April 10, 2026 06:31
@GitTimeraider GitTimeraider merged commit d4a371f into main Apr 10, 2026
3 checks passed
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates runtime and tooling dependencies for the Flask app’s containerized deployment and CI workflows.

Changes:

  • Bumped several Python package versions in requirements.txt (e.g., Werkzeug, Requests, SQLAlchemy, Gunicorn).
  • Updated the Docker base image from Python 3.13 to Python 3.14.
  • Adjusted GitHub Actions workflows (docker-build PR targeting branch and CodeQL action versions).

Reviewed changes

Copilot reviewed 3 out of 4 changed files in this pull request and generated 1 comment.

File Description
requirements.txt Updates pinned Python dependency versions.
Dockerfile Moves container base image to python:3.14-slim.
.github/workflows/docker-build.yml Changes which base branch triggers Docker builds on PRs.
.github/workflows/codeql.yml Updates CodeQL and checkout action versions.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

tags: [ 'v*' ]
pull_request:
branches: [ main ]
branches: [ develop ]
Copy link

Copilot AI Apr 10, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changing the docker-build workflow to run on pull requests targeting only develop means PRs opened against main will no longer get a Docker build (and may fail required-status checks if this workflow is expected on main). If this repo still accepts PRs to main, consider including main here (or explain/migrate branch protection accordingly).

Suggested change
branches: [ develop ]
branches: [ main, develop ]

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants