Skip to content

Bump python from 3.11.11-slim-bookworm to 3.13.3-slim-bookworm #12230

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 14, 2025

Bumps python from 3.11.11-slim-bookworm to 3.13.3-slim-bookworm.

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
python [>= 3.9.a, < 3.10]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file docker labels Apr 14, 2025
@dependabot dependabot bot requested review from Maffooch and mtesauro as code owners April 14, 2025 12:06
Copy link

dryrunsecurity bot commented Apr 14, 2025

DryRun Security

This pull request involves potential risks related to Python version upgrades and base image changes, which require thorough security verification and testing to ensure compatibility and mitigate potential vulnerabilities.

💭 Unconfirmed Findings (4)
Vulnerability Potential Dependency Compatibility Risk
Description Major version jumps from Python 3.11.x to 3.13.x might introduce breaking changes and could expose applications to unexpected runtime vulnerabilities if not thoroughly tested.
Vulnerability Potential Unverified Image Integrity
Description Changes to image SHA256 hash require verification of official source, and it is critical to ensure new images have been properly vetted for security vulnerabilities.
Vulnerability Potential Unverified Dependency Upgrade
Description Upgrades may introduce security improvements, but lack explicit verification. There is a risk of unresolved vulnerabilities or unexpected behavioral changes in new Python versions.
Vulnerability Potential Unverified Base Image Security
Description New base image hash indicates potential changes in image composition, with a lack of explicit details about security improvements in the new base image.

All finding details can be found in the DryRun Security Dashboard.

@Maffooch
Copy link
Contributor

I think python 3.12 was breaking a few things, so I am not surprised that 3.13 is as well

Copy link
Contributor

@Maffooch Maffooch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Forgot to mark as blocked

Copy link
Contributor Author

dependabot bot commented on behalf of github Apr 21, 2025

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

@dependabot dependabot bot force-pushed the dependabot/docker/dev/python-3.13.3-slim-bookworm branch from a6aeebc to 50107b9 Compare April 28, 2025 16:29
Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 on what Maffooch said ☝️

Bumps python from 3.11.11-slim-bookworm to 3.13.3-slim-bookworm.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.13.3-slim-bookworm
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/docker/dev/python-3.13.3-slim-bookworm branch from 50107b9 to 42fa109 Compare May 5, 2025 16:59
Copy link
Contributor Author

dependabot bot commented on behalf of github Jun 9, 2025

Superseded by #12570.

@dependabot dependabot bot closed this Jun 9, 2025
@dependabot dependabot bot deleted the dependabot/docker/dev/python-3.13.3-slim-bookworm branch June 9, 2025 13:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file docker
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants