Skip to content

chore: Upgrade Python requirements - #711

Open
edx-requirements-bot wants to merge 1 commit into
masterfrom
repo-tools/upgrade-python-requirements-8d25048
Open

edx-requirements-bot wants to merge 1 commit into
masterfrom
repo-tools/upgrade-python-requirements-8d25048

Conversation

@edx-requirements-bot

Copy link
Copy Markdown
Contributor

Python requirements update. Please review the changelogs for the upgraded packages.

Deleted obsolete pull_requests:
#709

@edx-requirements-bot

Copy link
Copy Markdown
Contributor Author

List of packages in the PR without any issue.

  • amqp changes from 5.3.1 to 5.4.0
  • boto3 changes from 1.43.96 to 1.43.102
  • botocore changes from 1.43.96 to 1.43.102
  • diff-cover changes from 10.5.1 to 10.6.0
  • edx-rest-api-client changes from 7.0.0 to 7.1.0
  • platformdirs changes from 4.11.9 to 4.11.12
  • pycodestyle changes from 2.14.0 to 2.15.0
  • pyjwt changes from 2.14.0 to 2.15.0
  • pyjwt[crypto] changes from 2.14.0 to 2.15.0
  • pylint changes from 4.0.8 to 4.0.9
  • pymongo changes from 4.18.1 to 4.18.2
  • pyproject-api changes from 1.11.1 to 1.11.2
  • python-discovery changes from 1.6.0 to 1.6.1
  • python-slugify changes from 9.0.0 to 9.1.1
  • pytz changes from 2026.3.post1 to 2026.4
  • snowflake-connector-python changes from 4.7.4 to 4.7.5
  • tox changes from 4.61.5 to 4.64.2
  • virtualenv changes from 21.7.10 to 21.12.1
  • wcwidth changes from 0.8.3 to 0.9.1

@edx-requirements-bot

Copy link
Copy Markdown
Contributor Author

These Packages need manual review..

  • [MAJOR] filelock changes from 3.32.7 to 4.0.3
  • [NEW] jeepney (0.9.0) added to the requirements
  • [NEW] secretstorage (3.5.0) added to the requirements

@brobro10000

Copy link
Copy Markdown
Member

🤖 Automated Requirements Analysis — 2026-09-28

CI Status: ✅ Green (All checks passed)
Recommendation: ⚠️ NEEDS CLOSER LOOK (Deploy to Staging First)

Dependency Changes

Package From To Bump Env Risk Release Notes
edx-rest-api-client 7.0.0 7.1.0 MINOR prod Moderate PyPI
pyjwt[crypto] 2.14.0 2.15.0 MINOR prod Moderate PyPI
amqp 5.3.1 5.4.0 MINOR prod Moderate PyPI
boto3 1.43.96 1.43.102 PATCH prod Low PyPI
botocore 1.43.96 1.43.102 PATCH prod Low PyPI
pymongo 4.18.1 4.18.2 PATCH prod Low PyPI
pytz 2026.3.post1 2026.4 NON-STANDARD prod Low PyPI
snowflake-connector-python 4.7.4 4.7.5 PATCH prod Low PyPI
wcwidth 0.8.3 0.9.1 MINOR prod Low PyPI
filelock 3.32.7 4.0.3 MAJOR tooling Low PyPI
tox 4.61.5 4.64.2 MINOR tooling Low PyPI

Findings

  • Critical Runtime Subsystems: pyjwt (Authentication/Cryptography) and amqp (Task Queue/Celery transport) are updated via MINOR bumps. These are critical runtime subsystems.
  • API Client Update: edx-rest-api-client is bumped from 7.0.0 to 7.1.0 (MINOR). This affects REST API communications.
  • Tooling Major Bump: filelock is bumped from 3.32.7 to 4.0.3 (MAJOR) in CI/dev environments, which is safe for production but may affect local/CI test runs.

Recommended Validation

  • Deploy to staging and validate core data ingestion/reporting pipelines.
  • Verify Celery task execution and broker connectivity (due to amqp bump).
  • Verify REST API client authentication flows (due to pyjwt and edx-rest-api-client bumps).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants