Skip to content

chore(deps): consolidate pending dependency updates #118

Description

@ericpaulsen

The five open dependency pull requests need a combined compatibility and security review: #96, #98, #99, #110, and #111. I am claiming this work under the requested implement-spec workflow.

Scope

  • Update the pi shim to pi-coding-agent 0.86.1 and adapt the affected test harnesses.
  • Apply the Python 3.12.14 and PostgreSQL 17.11 image digest updates.
  • Update the uv builder images to 0.12.19.
  • Apply setup-uv v10.2.0 and TruffleHog v3.97.6 action pins.
  • Investigate failed checks and obtain fresh security scan evidence for expired reviews. Keep security gates intact.

Dependencies and acceptance

The pi shim and workflow updates can proceed independently. Python and uv touch the same Dockerfile and integrate serially. Full security validation follows integration of the image and dependency pins.

One integration pull request must contain all five updates, pass relevant tests and required checks, and receive an independent review. If an upstream fix or authority is missing, document that blocker and keep the pull request draft. Issue #112 remains the tracker for the Python archive-extraction fix unless this work verifies a fix.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions