build(deps): bump library/python from 3.13.14-slim-bookworm to 3.14.6-slim-bookworm - #63
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps library/python from 3.13.14-slim-bookworm to 3.14.6-slim-bookworm. --- updated-dependencies: - dependency-name: library/python dependency-version: 3.14.6-slim-bookworm dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
## Outcome Consolidates the broken one-file Dependabot updates into one verified maintenance change and removes the wildcard review rule that automatically requested a personal review on every repository change. ## Changes - upgrades the Python runtime/development groups from #64 and #65 with a regenerated lock; - coordinates the uv 0.12.8 pin from #61 across Docker, CI, release, acceptance and documentation; - adapts the MCP 2.1 anticipated-error boundary so unavailable sources remain sanitized and fail closed; - adds stdio MCP to the isolated live four-source CLI/REST/CRM parity gate; - fixes the Redocly 2.49.0 execution pin left inconsistent after #62; - scopes CODEOWNERS to governed/security-sensitive paths; - moves version-update cadence to quarterly, limits concurrent update PRs, and disables uncoordinated Docker version PRs while retaining security updates; - adds the dependency labels referenced by Dependabot. Python 3.14 from #63 is intentionally not included: it is a runtime major migration, not a patch update, and its Compose acceptance currently fails the repository's supported Python 3.13.14 contract. ## Verification - `./scripts/check.sh`: 2,088 tests, 100% statement/branch coverage, package/docs/OpenAPI/secret/dependency checks pass; no known vulnerabilities. - `./scripts/test_compose.sh`: full PostgreSQL 18.4 reference deployment passes with zero project residue. - `./scripts/test_official_screening_live.sh`: current four-source refresh/replay and CLI/REST/CRM/MCP parity pass with zero residue (EU FSF 6,234; Annex I 384; OFAC SDN 19,321; Consolidated 481). - Stale-source and invalid-input MCP paths remain fail closed; no mutating/clearance tool is exposed. Evidence: `docs/evidence/dependency-and-mcp-smoke-2026-09-02.md`. Relates to #47. Supersedes #61, #64 and #65 after merge.
|
Closed without merge. Python 3.14 is a runtime major migration, not a routine image patch, and this PR fails the supported Python 3.13.14 Compose contract. #66 retains 3.13.14 and disables uncoordinated Docker version PRs; security-update PRs remain enabled. A future 3.14 migration should be planned and tested across runtime, dependencies, CI, packaging and acceptance as one change. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Warning
Cooldown could not be applied because no publication date was available from the registry.
Bumps library/python from 3.13.14-slim-bookworm to 3.14.6-slim-bookworm.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)