Dependency Dashboard
- Dominant language
- Python
- Stars
- 9
- Forks
- 20
- PR merge metrics
- No merged PRs in 30d
Description
This issue lists Renovate updates and detected dependencies. Read the [Dependency Dashboard](https://docs.renovatebot.com/key-concepts/dashboard/) docs to learn more.
[View this repository on the Mend.io Web Portal](https://developer.mend.io/github/finos/pylegend).
## Repository Problems
These problems occurred while renovating this repository. [View logs](https://developer.mend.io//github/finos/pylegend).
- ⚠️ WARN: Package lookup failures
---
> [!WARNING]
> Renovate failed to look up the following dependencies: `Failed to look up gitlab-tags package data-engineering/data-architecture-qubits/alloy-sdlc-ci-utils: no-result`.
>
> Files affected: `.gitlab-ci.yml`
---
## Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
- [ ] [Update dependency requests to v2.33.0 [SECURITY]](../pull/326)
- [ ] [Update dependency cryptography to v50 [SECURITY]](../pull/313)
- [ ] [Update dependency pytest to v9 [SECURITY]](../pull/327)
- [ ] [Update codecov/codecov-action action to v6.0.2](../pull/302)
- [ ] [Update apache/skywalking-eyes action to v0.9.0](../pull/325)
- [ ] [Update dependency uv_build to >=0.12.15,<0.13.0](../pull/317)
- [ ] [Update actions/checkout action to v7](../pull/312)
- [ ] [Update actions/setup-java action to v6](../pull/324)
- [ ] [Update actions/setup-python action to v7](../pull/316)
- [ ] [Update codecov/codecov-action action to v7](../pull/310)
- [ ] **Click on this checkbox to rebase all open PRs at once**
## PR Closed (Blocked)
The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.
- [ ] [Update dependency wrapt to v2](../pull/198)
- [ ] [Update ubuntu Docker tag to v26](../pull/299)
## Detected Dependencies
dockerfile (2)
deployment/snapshot/Dockerfile (1)
- `ubuntu 22.04` → [Updates: `26.04`]
deployment/tag/Dockerfile (1)
- `ubuntu 22.04` → [Updates: `26.04`]
github-actions (7)
.github/workflows/actions/pytest/action.yml (1)
- `actions/setup-java v5` → [Updates: `v6`]
.github/workflows/actions/setup/action.yml (1)
- `actions/setup-python v6` → [Updates: `v7`]
.github/workflows/build-ci.yml (19)
- `actions/checkout v6` → [Updates: `v7`]
- `astral-sh/ruff-action v4.1.0`
- `apache/skywalking-eyes v0.8.0` → [Updates: `v0.9.0`]
- `actions/checkout v6` → [Updates: `v7`]
- `actions/checkout v6` → [Updates: `v7`]
- `actions/upload-artifact v7`
- `actions/upload-artifact v7`
- `codecov/codecov-action v6.0.0` → [Updates: `v6.0.2`, `v7.1.0`]
- `actions/upload-artifact v7`
- `actions/checkout v6` → [Updates: `v7`]
- `actions/upload-artifact v7`
- `actions/checkout v6` → [Updates: `v7`]
- `aquasecurity/trivy-action v0.36.0`
- `docker/login-action v4`
- `actions/checkout v6` → [Updates: `v7`]
- `actions/upload-artifact v7`
- `actions/configure-pages v6`
- `actions/upload-pages-artifact v5`
- `actions/deploy-pages v5`.github/workflows/cve-scanning.yml (1)
- `actions/checkout v6` → [Updates: `v7`]
.github/workflows/license-scanning.yml (1)
- `actions/checkout v6` → [Updates: `v7`]
.github/workflows/release.yml (10)
- `actions/checkout v6` → [Updates: `v7`]
- `actions/checkout v6` → [Updates: `v7`]
- `astral-sh/ruff-action v4.1.0`
- `apache/skywalking-eyes v0.8.0` → [Updates: `v0.9.0`]
- `actions/checkout v6` → [Updates: `v7`]
- `actions/checkout v6` → [Updates: `v7`]
- `actions/checkout v6` → [Updates: `v7`]
- `actions/checkout v6` → [Updates: `v7`]
- `aquasecurity/trivy-action v0.36.0`
- `docker/login-action v4`.github/workflows/test-result.yml (1)
- `EnricoMi/publish-unit-test-result-action v2`
gitlabci-include (1)
.gitlab-ci.yml (1)
- `data-engineering/data-architecture-qubits/alloy-sdlc-ci-utils release-1.15.0`
pep621 (1)
pyproject.toml (22)
- `python >=3.9,<3.15`
- `requests >=2.27.1` → [Updates: `>=2.27.1`]
- `ijson >=3.1.4`
- `pandas >=1.0.0 `
- `pandas >=2.1.1 `
- `numpy >=1.20.0 `
- `numpy >=1.26.0 `
- `testcontainers >=3.0.0`
- `pytest >=7.0.0,<9.0.0 ` → [Updates: `>=9.0.3,<9.1.0`]
- `pytest >=7.0.0 ` → [Updates: `>=7.0.0 `]
- `pytest-cov >=3.0.0`
- `mockito >=1.0.0`
- `sqlalchemy >=2.0.0`
- `pg8000 >=1.0.0`
- `pymysql >=1.0.0`
- `cryptography >=40.0.0` → [Updates: `>=40.0.0`]
- `wrapt <2.0.0` → [Updates: `<2.4.2`]
- `mypy >=1.0.0`
- `types-requests >=2.28.0`
- `pandas-stubs >=1.5.0`
- `ruff >=0.14.0`
- `uv_build >=0.11.2,<0.12.0` → [Updates: `>=0.12.15,<0.13.0`]
---
- [ ] Check this box to trigger a request for Renovate to run again on this repository
Contributor guide
Research direction
This is an automated Renovate dashboard rather than a single scoped task. Review the listed dependency updates in pyproject.toml, .github/workflows/, deployment/snapshot/Dockerfile, deployment/tag/Dockerfile, and .gitlab-ci.yml, then inspect the linked pull requests and Renovate logs. The dashboard is done when the intended updates are handled and the package lookup warning has a documented outcome.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, github-actions, gitlab, python
- Domain
- build-system, ci-cd, devops
- Issue type
- Refactor
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100