Skip to content

Bump python from 3.11.8-slim to 3.14.7-slim - #1

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/python-3.14.7-slim
Open

Bump python from 3.11.8-slim to 3.14.7-slim#1
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/python-3.14.7-slim

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor

Bumps python from 3.11.8-slim to 3.14.7-slim.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps python from 3.11.8-slim to 3.14.7-slim.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.14.7-slim
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Aug 23, 2026
pip-install-python added a commit that referenced this pull request Aug 23, 2026
Mirrors dash-documentation-boilerplate ab22fd7, and this fork is the
reason that commit exists: the inaugural push opened five floor-raise PRs
in one morning.

The file's stated purpose is catching network-package drift as ONE
grouped, reviewable PR. As written it also proposed raising the floor on
every other requirement, weekly. Those are different things, and the
second is worse than noise:

  gunicorn >=23.0.0 -> >=26.1.0   the floor IS the CVE fact
                                  (CVE-2024-6827, CVE-2024-1135, both
                                  fixed in 23.0, stated above the pin).
                                  Raising it asserts 23-25 are unsafe,
                                  which is false, and discards the reason.
  pandas   >=1.2.3  -> >=3.0.5    works-on-3 is not requires-3. This app
                                  runs pandas 3.0.5 under the >=1.2.3
                                  floor today — that is evidence the floor
                                  is RIGHT, not that it should move. The
                                  raise forbids every 1.x/2.x environment
                                  for no API anyone can name.
  dotenv, typing-extensions, python-frontmatter
                                  compatibility floors with nothing behind
                                  the raise; the resolver already installs
                                  latest under them.

All five closed with those reasons rather than rebased or merged — the
change itself was the problem, not its base.

The allow-list restricts pip VERSION-updates to dash*/plotly*/markdown2dash.
Security updates are unaffected: they arrive through GitHub's separate
security-update channel regardless of this list. The github-actions and
docker ecosystems are untouched — PR #1 (python 3.11.8 -> 3.14.7 base
image) and #2 (actions group) are real decisions and stay open for the
owner.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants