Update image dependencies and make PyCharm reviews reproducible - #92
Conversation
Bumps the infrastructure group with 4 updates: [astral-sh/uv](https://github.com/astral-sh/uv), alpine/git, alpine/curl and ubuntu. Updates `astral-sh/uv` from 0.12.16 to 0.12.19 - [Release notes](https://github.com/astral-sh/uv/releases) - [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md) - [Commits](astral-sh/uv@0.12.16...0.12.19) Updates `alpine/git` from `0b5f57d` to `ae0f6f4` Updates `alpine/curl` from `d7720f8` to `a39f52c` Updates `ubuntu` from `b3cc40b` to `008173c` --- updated-dependencies: - dependency-name: astral-sh/uv dependency-version: 0.12.19 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: infrastructure - dependency-name: alpine/git dependency-version: v2.54.0 dependency-type: direct:production dependency-group: infrastructure - dependency-name: alpine/curl dependency-version: 8.22.0 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: infrastructure - dependency-name: ubuntu dependency-version: noble dependency-type: direct:production dependency-group: infrastructure ... Signed-off-by: dependabot[bot] <support@github.com>
|
Dependency-update review on 2026-09-25 at Local arm64 validation passed: runtime and runtime-devtools image builds, both smoke scripts, database initialization and Launchplane health checks, and downstream helper tests. The required whole-project PyCharm assessment is RED, with 31 findings. These include unresolved This PR remains open because the requested clean-only merge sweep could not establish a clean full-project inspection. Next: prepare the IDE's documented dependencies/source roots, triage the remaining findings, then rerun the required inspection before merging. The isolated review checkout and inspection evidence are retained for that follow-up; temporary verification image tags are removed after testing. |
|
Merged at Local changed-files and whole-project PyCharm inspections were GREEN with zero findings; runtime/devtools builds, smoke checks, database initialization/health, and downstream helper checks passed before push. Validation receipts and captured build inputs are retained under Alert-inventory visibility remains limited for the automation App (code-scanning/Dependabot alert APIs return 403; the redacted secret-scanning helper reports its public-repository API unavailable). Passing workflow scans are verified; this is not a claim that every repository alert inventory was readable. No tenant runtime was deployed. |
Updates the pinned uv, Git, curl, and Ubuntu build images and makes the required PyCharm checks reproducible in isolated worktrees.
The shared inspection profile and scopes remain versioned. Worktree-specific interpreter/module files are generated locally from the locked development environment, with a documented path to clean, pinned external Odoo 19 sources. Helper path and response types are explicit, and the inspection cleanup preserves strict boolean workspace admission, bare-URL rejection, dependency provenance, and runtime layout.
Validation:
b3e4ddcbcc3a6a5a28f18f70342dcd584432faef.Warning
Cooldown could not be applied because no publication date was available from the registry.
Bumps the infrastructure group with 4 updates: astral-sh/uv, alpine/git, alpine/curl and ubuntu.
Updates
astral-sh/uvfrom 0.12.16 to 0.12.19Release notes
Sourced from astral-sh/uv's releases.
... (truncated)
Changelog
Sourced from astral-sh/uv's changelog.
... (truncated)
Commits
bea1384Bump version to 0.12.19 (#21975)299a93dSync latest Python releases (#21970)30de9e2Preserve query parameters in direct URL metadata (#21971)0e7433eFilter distribution hashes in tests (#21941)c73db78Omit unused runtime settings from lockfiles (#21913)ad12342Add a preview feature for lazy build backend imports (#21967)dd965a2RestoreFlatDistributionsfor downstream resolvers (#21965)214d7f6Use Astra for PR security reviews (#21959)3db6652Disable incremental compilation when publishing docs (#21955)e18f413Reproduce editable project relocation failure (#21948)Updates
alpine/gitfrom0b5f57dtoae0f6f4Updates
alpine/curlfromd7720f8toa39f52cUpdates
ubuntufromb3cc40bto008173cDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions