Keep selenium/redis bumps, hold black & pylint for Python 3.9 - #3991
Merged
Merged
Conversation
Updates the requirements on [selenium](https://github.com/SeleniumHQ/Selenium), [black](https://github.com/psf/black), [pylint](https://github.com/pylint-dev/pylint) and [redis](https://github.com/redis/redis-py) to permit the latest version. Updates `selenium` to 4.48.0 - [Release notes](https://github.com/SeleniumHQ/Selenium/releases) - [Commits](SeleniumHQ/selenium@selenium-4.11.0...selenium-4.48.0) Updates `black` from 22.3.0 to 26.5.1 - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@22.3.0...26.5.1) Updates `pylint` from 3.0.3 to 4.0.8 - [Release notes](https://github.com/pylint-dev/pylint/releases) - [Commits](pylint-dev/pylint@v3.0.3...v4.0.8) Updates `redis` to 8.1.0 - [Release notes](https://github.com/redis/redis-py/releases) - [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES) - [Commits](redis/redis-py@3.5.3...v8.1.0) --- updated-dependencies: - dependency-name: selenium dependency-version: 4.48.0 dependency-type: direct:production dependency-group: pip-dependencies - dependency-name: black dependency-version: 26.5.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: pip-dependencies - dependency-name: pylint dependency-version: 4.0.8 dependency-type: direct:production update-type: version-update:semver-major dependency-group: pip-dependencies - dependency-name: redis dependency-version: 8.1.0 dependency-type: direct:production dependency-group: pip-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
The Dependabot group bumped black to 26.5.1 and pylint to 4.0.8, both of which require Python >=3.10 and cannot install on the Python 3.9 CI jobs (Dash still supports 3.9), so every 3.9 job failed at pip install. Revert those two pins to their current versions and keep the selenium and redis range-cap bumps, which resolve to 3.9-compatible builds. Add a Dependabot ignore so the py3.10-only black/pylint versions stop being re-proposed.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Supersedes #3990.
Problem
The Dependabot group in #3990 bumped four pip deps at once. It failed every Python 3.9 CI job at
pip install(before any test ran):black==26.5.1andpylint==4.0.8both dropped Python 3.9 (they require>=3.10). Because they are exact==pins, pip cannot fall back to an older release, so the install aborts. Dash still supports and tests Python 3.9 (python_requires=">=3.9", 3.9 in the CI matrix).Selenium was not the cause: its
<=4.48.0bump is a range cap, so pip resolves a 3.9-compatible build. That is why only the 3.9 jobs failed, and only at install. Theredis <=8.1.0bump is the same (resolves to redis 7.0.0 on 3.9).Change
requirements/ci.txt: keepblack==22.3.0andpylint==3.0.3(current versions). Bumping these to the latest releases would force a repo-wide reformat and new lint findings, and drops 3.9 support; that should be a deliberate change, not a Dependabot bump.requirements/testing.txt/requirements/redis.txt: keep theseleniumandrediscap bumps from Bump the pip-dependencies group with 4 updates #3990 (harmless on 3.9)..github/dependabot.yml: ignoreblack >=25.12.0andpylint >=4.0.0(the first releases that require Python >=3.10) so they stop being re-proposed while Dash supports 3.9.Notes
The ignore is scoped to the Python-3.10-only versions. It still permits a future bump to
black 25.11.0/pylint 3.3.9(last 3.9-compatible releases), which would need a deliberate reformat / lint pass; broaden the ignore later if we want to hold the linters completely.