cds-snc / cds-snc/notification-utils

Dependency Dashboard

Open
#138 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
3
Forks
7
Avg merge
3h 2m
Merged PRs (30d)
3

Description

This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/cds-snc/notification-utils).

## Pending Approval

The following branches are pending approval. To create them, click on a checkbox below.

- [ ] chore(deps): update actions/checkout action to v7
- [ ] chore(deps): update actions/setup-python action to v7
- [ ] chore(deps): update dependency mypy to v2
- [ ] chore(deps): update dependency pytest-cov to v7
- [ ] chore(deps): update dependency pytest-xdist to v3
- [ ] chore(deps): update dependency types-bleach to v6
- [ ] chore(deps): update dependency types-cachetools to v7
- [ ] chore(deps): update dependency types-pytz to v2026
- [ ] chore(deps): update github/codeql-action action to v4
- [ ] fix(deps): update dependency cachetools to v7
- [ ] fix(deps): update dependency certifi to v2026
- [ ] fix(deps): update dependency markupsafe to v3
- [ ] fix(deps): update dependency phonenumbers to v9
- [ ] fix(deps): update dependency pre-commit to v4
- [ ] fix(deps): update dependency pypdf2 to v3
- [ ] fix(deps): update dependency python-json-logger to v4
- [ ] fix(deps): update dependency pytz to v2026
- [ ] fix(deps): update dependency statsd to v4
- [ ] πŸ” **Create all pending approval PRs at once** πŸ”

## PR Edited (Blocked)

The following updates have been manually edited so Renovate will no longer make changes. To discard all commits and start over, click on a checkbox below.

- [ ] [fix(deps): update all patch dependencies](../pull/418) (`boto3`, `types-PyYAML`, `types-python-dateutil`, `types-requests`, `werkzeug`)

## Open

The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.

- [ ] [chore(deps): update dependency click to v8.3.3 [security]](../pull/419)
- [ ] [fix(deps): update dependency bleach to v6.4.0 [security]](../pull/413)
- [ ] [fix(deps): update dependency requests to v2.33.0 [security]](../pull/371)
- [ ] [chore(deps): update dependency pytest to v9 [security]](../pull/408)
- [ ] [chore(deps): update dependency setuptools to v83 [security]](../pull/420)
- [ ] [fix(deps): update dependency flask to v3 [security]](../pull/396)
- [ ] [fix(deps): update dependency mistune to v3 [security]](../pull/410)
- [ ] [chore(deps): update all non-major github action dependencies](../pull/374) (`actions/checkout`, `python`)
- [ ] [fix(deps): update all minor dependencies](../pull/430) (`awscli`, `beautifulsoup4`, `certifi`, `fakeredis`, `python`, `ruff`)
- [ ] [chore(deps): lock file maintenance](../pull/221)
- [ ] **Click on this checkbox to rebase all open PRs at once**

## Detected Dependencies

dockerfile (3)

.devcontainer/Dockerfile (1)

- `mcr.microsoft.com/vscode/devcontainers/python 3.12` β†’ [Updates: `3.14`]

.github/actions/waffles/Dockerfile (1)

- `python 3.12` β†’ [Updates: `3.14.6`]

docker/Dockerfile (1)

- `python 3.5-slim@sha256:2348c9c9fa90808066919c036d59919fbf82c7f9277c2ff8b6b8cc6e72f5b9d7`

github-actions (4)

.github/workflows/check_pinned_actions.yml (2)

- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β†’ [Updates: `v4.4.0`, `v7.0.1`]
- `astral-sh/setup-uv v10.0.1@20cfd1bf945f4377ade1205e4dbc17946fc9a30d` β†’ [Updates: `v10.1.0`]

.github/workflows/ci.yaml (3)

- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β†’ [Updates: `v4.4.0`, `v7.0.1`]
- `actions/setup-python v2.3.4@e9aba2c848f5ebd159c070c61ea2c4e2b122355e` β†’ [Updates: `v7.0.0`]
- `python 3.12` β†’ [Updates: `3.14`]

.github/workflows/codeql.yml (4)

- `actions/checkout v3.6.0@f43a0e5ff2bd294095638e18286ca9a3d1956744` β†’ [Updates: `v3.7.0`, `v7.0.1`]
- `github/codeql-action v2.28.1@b8d3b6e8af63cde30bdc382c0bc28114f4346c88` β†’ [Updates: `v4.37.9`]
- `github/codeql-action v2.28.1@b8d3b6e8af63cde30bdc382c0bc28114f4346c88` β†’ [Updates: `v4.37.9`]
- `github/codeql-action v2.28.1@b8d3b6e8af63cde30bdc382c0bc28114f4346c88` β†’ [Updates: `v4.37.9`]

.github/workflows/seekret.yaml (2)

- `actions/checkout v4.2.2@11bd71901bbe5b1630ceea73d27597364c9af683` β†’ [Updates: `v4.4.0`, `v7.0.1`]
- `cdssnc/seekret-github-action sha256:0aee6df949373ef6df26d35f6207b56f897ddd1caa030646d7421b0afb717665`

pip_requirements (1)

.github/actions/waffles/requirements.txt (5)

- `docopt ==0.6.2`
- `Flask ==2.3.3` β†’ [Updates: `==3.1.3`]
- `markupsafe ==2.1.5` β†’ [Updates: `==3.0.3`]
- `setuptools ==78.1.1` β†’ [Updates: `==83.0.0`]
- `notifier-utils 53.2.34`

poetry (1)

pyproject.toml (43)

- `poetry-core >=1.3.2`
- `python ~3.12.7` β†’ [Updates: `~3.14.0`]
- `awscli 1.45.59` β†’ [Updates: `1.46.1`]
- `bleach 6.3.0` β†’ [Updates: `6.4.0`]
- `boto3 1.43.54` β†’ [Updates: `1.43.89`]
- `cachetools 4.2.4` β†’ [Updates: `7.1.8`]
- `certifi ^2024.0.0` β†’ [Updates: `^2024.0.0`, `^2026.0.0`]
- `Flask 2.3.3` β†’ [Updates: `3.1.3`]
- `Flask-Redis 0.4.0`
- `itsdangerous 2.2.0`
- `Jinja2 ^3.0.0`
- `markupsafe 2.1.5` β†’ [Updates: `3.0.3`]
- `mistune 0.8.4` β†’ [Updates: `3.3.0`]
- `ordered-set 4.1.0`
- `phonenumbers 8.13.55` β†’ [Updates: `9.0.38`]
- `pre-commit ^3.8.0` β†’ [Updates: `^4.0.0`]
- `py_w3c 0.3.1`
- `pypdf2 1.28.6` β†’ [Updates: `3.0.1`]
- `python-json-logger 2.0.7` β†’ [Updates: `4.2.0`]
- `pytz 2021.3` β†’ [Updates: `2026.3.post1`]
- `PyYAML 6.0.3`
- `requests 2.32.3` β†’ [Updates: `2.33.0`]
- `smartypants 2.0.2`
- `statsd 3.3.0` β†’ [Updates: `4.0.1`]
- `werkzeug 3.1.6` β†’ [Updates: `3.1.8`]
- `beautifulsoup4 ^4.12.3` β†’ [Updates: `^4.12.3`]
- `click 8.3.1` β†’ [Updates: `8.3.3`]
- `fakeredis ^2.24.1` β†’ [Updates: `^2.24.1`]
- `freezegun 1.5.5`
- `mypy 1.20.2` β†’ [Updates: `2.3.1`]
- `pytest 7.4.4` β†’ [Updates: `9.0.3`]
- `pytest-cov 2.12.1` β†’ [Updates: `7.1.0`]
- `pytest-mock 3.15.1`
- `pytest-xdist 2.5.0` β†’ [Updates: `3.8.0`]
- `requests-mock 1.12.1`
- `ruff ^0.15.0` β†’ [Updates: `^0.16.0`]
- `types-bleach 5.0.3.1` β†’ [Updates: `6.4.0.20260728`]
- `types-cachetools 5.5.0.20240820` β†’ [Updates: `7.0.0.20260713`]
- `types-python-dateutil 2.9.0.20260518` β†’ [Updates: `2.9.0.20260807`]
- `types-pytz 2022.7.1.2` β†’ [Updates: `2026.3.1.20260727`]
- `types-PyYAML 6.0.12.20260518` β†’ [Updates: `6.0.12.20260906`]
- `types-redis 4.6.0.20241004`
- `types-requests 2.33.0.20260712` β†’ [Updates: `2.33.0.20260906`]

renovate-config (1)

renovate.json

---

- [ ] Check this box to trigger a request for Renovate to run again on this repository

Contributor guide

Open the contributing guide

Research direction

Start with pyproject.toml and the listed Dockerfiles and GitHub Actions workflows to review the pending dependency updates. Existing pull requests already cover several updates, so check their status before doing anything else. Done would mean the selected dependency updates are applied or approved and the repository checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, github-actions, python
Domain
build-system, ci-cd, devops
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
10/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.