Skip to content

Conversation

@dvacca-onfido
Copy link
Contributor

@dvacca-onfido dvacca-onfido commented Jul 23, 2025

Patch library to solve dependabot error reported below:

Dependabot encountered '1' error(s) during execution, please check the logs for more details.
+----------------------------------------------------------------------------+
|                                   Errors                                   |
+------------------------------+---------------------------------------------+
| Type                         | Details                                     |
+------------------------------+---------------------------------------------+
| security_update_not_possible | {                                           |
|                              |   "dependency-name": "urllib3",             |
|                              |   "latest-resolvable-version": "2.2.3",     |
|                              |   "lowest-non-vulnerable-version": "2.5.0", |
|                              |   "conflicting-dependencies": []            |
|                              | }                                           |
+------------------------------+---------------------------------------------+

This requires updating urllib3 to version 2.5.0 which is not supporting python 3.8 (EOL Oct 2024).

Taking the opportunity for adding support for python 3.13 and dropping the package-mode = false poetry option (which was incorrect).

@dvacca-onfido dvacca-onfido force-pushed the fix-dependabot-warning branch from e38758a to 519bfb9 Compare July 24, 2025 08:13
@dvacca-onfido dvacca-onfido merged commit 064cd0e into master Jul 25, 2025
19 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants