Skip to content

Release 2.3.21 - #1376

Merged
sambles merged 7 commits into
stable/2.3.xfrom
release/2.3.21
Jul 2, 2026
Merged

Release 2.3.21#1376
sambles merged 7 commits into
stable/2.3.xfrom
release/2.3.21

Conversation

@sambles

@sambles sambles commented Apr 2, 2026

Copy link
Copy Markdown
Contributor

* add cert packages to images

* ampqs support

* test files

* Fix

* update testing files

* Add run script and rename compose file

* Fix Rabbit management api connection

* test setting rabbitmq mangement port

* Fix port

* Is example broken not code?

* example finally working

* remove older stable from example -- wont work without this PR
@sambles
sambles marked this pull request as draft April 2, 2026 15:28
@sambles
sambles changed the base branch from main to stable/2.3.x April 2, 2026 15:29
benhayes21 and others added 3 commits June 29, 2026 15:02
* Handle missing S3 log files in handle_task_failure

When a worker is killed with SIGKILL (e.g. OOM) during input generation,
it never writes its log files to S3. The hasattr(..., 'read') guard was
insufficient because RelatedFile always has a read method; the
FileNotFoundError is only raised lazily when the file is opened on first
access inside read(). Fixes #1408.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* retest

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Sam Gamble <hexadessa@gmail.com>
* Update py packs

* Pin tests to matching stable branches

* Fix oasislmf used for auth

* Update package

* f

* retest

* f

* f

* (Cladue) Fix CVEs in requirements files (cryptography, msgpack, pyarrow, pyopenssl, twisted)

- cryptography: pinned >=48.0.1 (fixes CVE-2026-26007, GHSA-537c-gmf6-5ccf)
- pyopenssl: raised lower bound to >=26.0.0 (fixes CVE-2026-27459)
- twisted: pinned >=26.4.0rc2 (fixes CVE-2026-42304)
- pyarrow: raised lower bound to >=23.0.1 (fixes CVE-2026-25087)
- msgpack: fixed indirectly by upgrading channels + channels-redis from 2.x
  to 4.x, which requires msgpack ~=1.0 (fixes GHSA-6v7p-g79w-8964)

Django CVEs (CVE-2025-64459, CVE-2025-57833, CVE-2025-64458) require a
major version upgrade (3.x -> 4.x) which is deferred pending migration
testing; added .trivyignore.yaml entries for these.

Note: channels 4.x has breaking API changes versus 2.x — consumer and
routing code will need updating separately.

* Fix trivy ignore

* set py 3.12

* keep db check at 3.11

fails with  ModuleNotFoundError: No module named 'pkg_resources'
drf_yasg is importing pkg_resources (from setuptools) which is absent in the CI environment.
This is a known issue with drf-yasg<=1.21.5 — newer versions switched to importlib.metadata.
The fix is to lift the upper bound.

However drf-yasg needs to be pinned due to schema change issues. keep
tests at p3.11

* Revert "set py 3.12"

This reverts commit 1fe9c5c.

* ffs
Comment thread requirements.txt Dismissed
@sambles
sambles marked this pull request as ready for review July 1, 2026 13:07
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@sambles
sambles merged commit 59b757f into stable/2.3.x Jul 2, 2026
@sambles
sambles deleted the release/2.3.21 branch July 2, 2026 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants