Skip to content
This repository has been archived by the owner on Feb 22, 2023. It is now read-only.

Update all dependencies of the analytics codebase #287

Merged
merged 1 commit into from
Oct 11, 2021
Merged

Conversation

dhruvkb
Copy link
Member

@dhruvkb dhruvkb commented Oct 9, 2021

Description

This PR replaces 11 Dependabot PRs that would need to be merged indivdiually with who-knows-how-many merge conflicts and rebases required along the way.

  1. Bump confluent-kafka from 1.6.1 to 1.7.0 in /analytics #276
  2. Bump boto3 from 1.18.56 to 1.18.57 in /ingestion_server #277
  3. Bump requests from 2.25.1 to 2.26.0 in /analytics #278
  4. Bump psycopg2 from 2.8.6 to 2.9.1 in /analytics #279
  5. Bump pyjwt from 2.1.0 to 2.2.0 in /openverse_api #280
  6. Bump sqlalchemy from 1.4.13 to 1.4.25 in /analytics #281
  7. Bump falcon from 3.0.0 to 3.0.1 in /analytics #282
  8. Bump django from 3.2.7 to 3.2.8 in /openverse_api #283
  9. Bump django-storages from 1.11.1 to 1.12 in /openverse_api #284
  10. Bump python-decouple from 3.4 to 3.5 in /openverse_api #285
  11. Bump django-cors-headers from 3.9.0 to 3.10.0 in /openverse_api #286

Dependabot currently does not support grouping depenedency updates into 1 PR. dependabot/dependabot-core#1190

Renovate (which is an external app) does.

Testing Instructions

CI runs tests for analytics so passing CI should validate the PR.

run: docker exec -i openverse-api_analytics_1 /bin/bash -c 'PYTHONPATH=. pipenv run pytest tests.py'

Checklist

  • My pull request has a descriptive title (not a vague title like Update index.md).
  • My pull request targets the default branch of the repository (main) or a parent feature branch.
  • My commit messages follow best practices.
  • My code follows the established code style of the repository.
  • I added or updated tests for the changes I made (if applicable).
  • I added or updated documentation (if applicable).
  • I tried running the project locally and verified that there are no visible errors.

Developer Certificate of Origin

Developer Certificate of Origin
Developer Certificate of Origin
Version 1.1

Copyright (C) 2004, 2006 The Linux Foundation and its contributors.
1 Letterman Drive
Suite D4700
San Francisco, CA, 94129

Everyone is permitted to copy and distribute verbatim copies of this
license document, but changing it is not allowed.


Developer's Certificate of Origin 1.1

By making a contribution to this project, I certify that:

(a) The contribution was created in whole or in part by me and I
    have the right to submit it under the open source license
    indicated in the file; or

(b) The contribution is based upon previous work that, to the best
    of my knowledge, is covered under an appropriate open source
    license and I have the right under that license to submit that
    work with modifications, whether created in whole or in part
    by me, under the same open source license (unless I am
    permitted to submit under a different license), as indicated
    in the file; or

(c) The contribution was provided directly to me by some other
    person who certified (a), (b) or (c) and I have not modified
    it.

(d) I understand and agree that this project and the contribution
    are public and that a record of the contribution (including all
    personal information I submit with it, including my sign-off) is
    maintained indefinitely and may be redistributed consistent with
    this project or the open source license(s) involved.

@dhruvkb dhruvkb requested a review from a team as a code owner October 9, 2021 05:25
@dhruvkb dhruvkb added dependencies Pull requests that update a dependency file python 💻 aspect: code Concerns the software code in the repository 🧰 goal: internal improvement Improvement that benefits maintainers, not users labels Oct 9, 2021
Copy link
Member

@zackkrida zackkrida left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you 👍

@dhruvkb dhruvkb enabled auto-merge October 9, 2021 12:53
@dhruvkb dhruvkb merged commit 54d0165 into main Oct 11, 2021
@dhruvkb dhruvkb deleted the dependabot_replace branch October 11, 2021 05:32
@sarayourfriend
Copy link
Contributor

I'm going to close the related PRs to avoid any confusion 👍

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
💻 aspect: code Concerns the software code in the repository dependencies Pull requests that update a dependency file 🧰 goal: internal improvement Improvement that benefits maintainers, not users
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants