securedrop.org icon indicating copy to clipboard operation
securedrop.org copied to clipboard

Quarterly Dependency Review

Open chigby opened this issue 2 years ago • 0 comments

Production

Major Version Upgrade

name version latest notes
bleach 4.1.0 5.0.1
django-modelcluster 5.2 6.0
wagtail-factories 2.0.1 3.1.0
wagtail-metadata 3.4.1 4.0.2
whitenoise 5.3.0 6.2.0 Check with @maeve-fpf

Minor Version Upgrade

name version latest
django-anymail 8.4 8.6
django-storages 1.12.3 1.13.1
django-webpack-loader 1.4.1 1.6.0
djangorestframework 3.12.4 3.14.0
pillow 9.0.1 9.3.0
pygments 2.10.0 2.13.0
requests 2.26.0 2.28.1
tinycss2 1.1.0 1.2.1
tldextract 3.1.2 3.4.0
unittest-xml-reporting 3.0.4 3.2.0
wagtail-autocomplete 0.8.1 0.9.0
wagtailmedia 0.8.0 0.12.0

Micro Version Upgrade

name version latest
feedparser 6.0.8 6.0.10
python-json-logger 2.0.2 2.0.4
urllib3 1.26.10 1.26.12

Upgrade Outside of Version Specifier

name version latest specifier notes
django 3.2.15 4.1.3 <3.3,>=3.2.16
psycopg2 2.8.6 2.9.5 <2.9,>=2.8.4
pyopenssl 19.0.0 22.1.0 ==19.0.0 check if this is still necessary for pshtt to work—maybe we can remove
structlog 21.2.0 22.1.0 <22,>=21
wagtail 2.15.2 4.1 <2.16,>=2.15.2

Up To Date

django-csp, django-settings-export, factory_boy, gunicorn, lxml, zxcvbn-python (note: remove this)

URI Packages (No Version)

pshtt

Development

Major Version Upgrade

name version latest notes
flake8 4.0.1 5.0.4
safety 1.10.3 2.3.1 Remove—we don't seem to run locally

Minor Version Upgrade

name version latest
coverage 6.1.1 6.5.0
django-debug-toolbar 3.2.2 3.7.0
vcrpy 4.1.1 4.2.1

Micro Version Upgrade

name version latest notes
bandit 1.7.1 1.7.4 Remove—we don't seem to run locally
colorama 0.4.4 0.4.6

Up To Date

ipdb

chigby avatar Nov 10 '22 15:11 chigby