image: bump python from 3.12-slim to 3.14-slim - #27
Conversation
Bumps python from 3.12-slim to 3.14-slim. --- updated-dependencies: - dependency-name: python dependency-version: 3.14-slim dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
… measurement (#32) Four Dependabot pull requests (#27–#30) had been open here since 12 August, all four green. Three are worth taking and one breaks the image — and **none of them could survive where they were opened**, which is the part worth saying. This repository is derived. The publish step makes it exactly equal to the source tree, and every file those four touch comes from there — the `Dockerfile` and four of the workflows are copied, and `.github/workflows/ci.yml` is *generated* from the source repository's own CI. Merging one here is a change that lives until the next publication and then disappears without a word, and Dependabot reopens it. So the bumps were applied upstream and arrive by the ordinary route. **Taken**, each SHA checked against the tag it claims to be, through the API rather than trusted from the diff: * `actions/checkout` v4 → **v7.0.1** * `actions/setup-python` v5 → **v7.0.0** * `actions/upload-artifact` v4 → **v7.0.1** The third is taken on weaker evidence and this says so: it appears only in `scorecard.yml`, which by a decision written into that file runs on `push: main` and weekly and never on a pull request — so #28 being green proved nothing about the bump inside it. It is taken because the next push to `main` exercises it and a failure there is loud rather than silent. **Declined:** `python:3.12-slim` → `3.14-slim`. `requires-python` is `>=3.12,<3.13` and the build stage installs with the base image's interpreter, so the image does not build: ``` ERROR: Package 'hullwork' requires a different Python: 3.14.7 not in '<3.13,>=3.12' ``` Its checks were green because no workflow that runs on a pull request builds the image — only the release and edge workflows do, on a tag and on a schedule. The first sign would have been a release failing. The Dockerfile already said *"Dependabot proposes the bump; a human takes it"*, which is a rule that depends on the human being awake. There is now a test tying the base image of **both stages** to `requires-python`, so the same proposal fails in `gates` in three seconds instead of at the next release. It reads both files and restates neither — verified by rewriting it to hard-code the version, which fails. Three reintroductions, three caught. Signed-off-by: Javier Miralles Rancaño <68760931+FlagshipDev@users.noreply.github.com>
|
Declined, and measured rather than assumed.
So this image does not build. The checks on this pull request were green because no workflow that runs on a pull request builds the image — only the release and edge workflows do, on a tag and on a schedule, so the first sign would have been a release failing. The Dockerfile already said "Dependabot proposes the bump; a human takes it", which is a rule that depends on the human being awake. There is now a test tying the base image of both stages to Thanks for raising it: the version really has moved, and the gap it exposed was ours. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps python from 3.12-slim to 3.14-slim.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)