Skip to content

build(deps): bump django-denorm-iplweb 1.12.1 -> 1.12.2#384

Open
mpasternak wants to merge 2 commits into
devfrom
worktree-denorm-bump
Open

build(deps): bump django-denorm-iplweb 1.12.1 -> 1.12.2#384
mpasternak wants to merge 2 commits into
devfrom
worktree-denorm-bump

Conversation

@mpasternak

Copy link
Copy Markdown
Member

Co i dlaczego

Aktualizacja django-denorm-iplweb do najnowszej wersji 1.12.2 (opublikowana 2026-06-18). Dotychczas pin był >=1.12.1, lock zamrażał 1.12.1.

To patch release biblioteki denormalizacyjnej. Metadane zależności są identyczne względem 1.12.1:

  • Django>=5.2, celery, celery-singleton, tqdm
  • requires-python >=3.10

→ brak nowych zależności tranzytywnych, niskie ryzyko.

Zmiany

  • pyproject.toml: django-denorm-iplweb>=1.12.1>=1.12.2
  • uv.lock: re-resolve (uv lock --upgrade-package django-denorm-iplweb), 1.12.11.12.2

Walidacja lokalna

Uruchomione testy zależne od denorm (denorm zasila zmaterializowany cache przez triggery DB):

  • src/bpp/tests/test_cache/74 passed, 1 skipped
  • test_autor_dyscyplina + ewaluacja_optymalizacja discipline pins — 22 passed

Pełna suita pytest (sharded) + build test-runner image — przez CI tego PR-a.

🤖 Generated with Claude Code

mpasternak and others added 2 commits June 18, 2026 21:51
Patch release of the denormalization library. Dependency metadata is
identical to 1.12.1 (Django>=5.2, celery, celery-singleton, tqdm;
requires-python >=3.10), so this is a low-risk, no-transitive-change
bump.

Validated locally against the denorm-backed test surface:
- src/bpp/tests/test_cache/ (materialized cache via DB triggers):
  74 passed, 1 skipped
- test_autor_dyscyplina + ewaluacja_optymalizacja discipline pins:
  22 passed

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
pip-audit flagged pypdf 6.13.2 (GHSA-jm82-fx9c-mx94, fixed in 6.13.3).
pypdf is a transitive dep (via xhtml2pdf) constrained through
constraint-dependencies; raise the security floor so future `uv lock`
cannot regress below the patched version, and record the advisory in
the audit comment alongside the existing CVEs.

Verified: `uv export --no-dev | pip-audit` (same invocation as the
dependency-audit.yml gate) reports "No known vulnerabilities found".

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant