Skip to content

Bump urllib3, pyjwt, cryptography and aiohttp; ruff cleanup - #91

Merged
byjg merged 10 commits into
masterfrom
test/dependabot-all
Oct 5, 2026
Merged

byjg merged 10 commits into
masterfrom
test/dependabot-all

Conversation

@byjg

@byjg byjg commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Combines the open Dependabot PRs into a single merge:

PR Package From To Used by
#89 urllib3 2.7.0 2.8.0 requests, docker, kubernetes (runtime)
#88 pyjwt 2.13.0 2.15.0 E2E tests (dev)
#83 cryptography 49.0.0 50.0.0 pyOpenSSL in certbot.py (runtime), E2E tests
#82 aiohttp 3.14.1 3.14.3 kubernetes client (runtime)

Only uv.lock changes. The branches merged without conflicts and uv lock --check passes.

cryptography 50 is a major bump. pyOpenSSL 26.4.0 accepts cryptography>=49,<51, and the certbot tests that create real certificates and load them through crypto.load_certificate pass.

Tested locally

Check Result
Unit tests 183 passed
Docker image build (runs the unit tests inside the image) OK
E2E Docker Compose 43 passed
E2E static 12 passed
E2E proxy headers 8 passed
E2E Swarm 13 passed
E2E Kubernetes (kind) 25 passed

The failing check on #82 was Tests-E2E-Swarm timing out while pulling haproxy:3.3-alpine from Docker Hub, not the aiohttp bump.

Merging with a merge commit (not squash) keeps the Dependabot commits in master, so GitHub marks #82, #83, #88 and #89 as merged.

Ruff cleanup

Also fixes the existing ruff errors (63 → 5). These are code-style changes only; unit tests still pass (183).

  • a3c40ed Auto-fixes (ruff check --fix): missing newline at end of file, unused imports, import order, redundant open() modes.
  • 302d6f9 E712/E741 in tests: is True / is False instead of ==, which keeps the assertions strict, and l → line.
  • fcb5da7 pyproject.toml: @classproperty passes the class, so classmethod-decorators makes ruff expect cls like @classmethod (N805, and it still flags self), and extend-ignore-names allows the lowercase decorator name (N801) while keeping the default ignore list.

The 5 remaining F841 (unused variables in tests) are left for a follow-up.

dependabot Bot and others added 10 commits August 4, 2026 20:50
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to 3.14.3.
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.1...v3.14.3)

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [cryptography](https://github.com/pyca/cryptography) from 49.0.0 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@49.0.0...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Missing newline at end of file, unused imports, import order and
redundant open() modes (ruff check --fix).
Use identity checks (is True / is False) instead of == comparisons,
keeping the assertions strict, and rename the ambiguous variable l.
@classproperty passes the class, so check its methods for cls like
@classmethod (N805), and allow its lowercase decorator-style name (N801).
@byjg byjg changed the title Bump urllib3, pyjwt, cryptography and aiohttp Bump urllib3, pyjwt, cryptography and aiohttp; ruff cleanup Oct 5, 2026
@byjg
byjg merged commit 4cbddb5 into master Oct 5, 2026
10 checks passed
@byjg
byjg deleted the test/dependabot-all branch October 5, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant