Upgrade software dependencies 2026-04-13 (#7925)#7934
Merged
dsotirho-ucsc merged 12 commits intodevelopfrom Apr 15, 2026
Merged
Upgrade software dependencies 2026-04-13 (#7925)#7934dsotirho-ucsc merged 12 commits intodevelopfrom
dsotirho-ucsc merged 12 commits intodevelopfrom
Conversation
39 tasks
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #7934 +/- ##
========================================
Coverage 85.04% 85.04%
========================================
Files 162 162
Lines 23303 23303
========================================
Hits 19819 19819
Misses 3484 3484 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
dsotirho-ucsc
added a commit
that referenced
this pull request
Apr 14, 2026
dsotirho-ucsc
added a commit
that referenced
this pull request
Apr 14, 2026
3877b42 to
ea878f3
Compare
dsotirho-ucsc
added a commit
that referenced
this pull request
Apr 14, 2026
dsotirho-ucsc
added a commit
that referenced
this pull request
Apr 14, 2026
ea878f3 to
cdafaa0
Compare
Contributor
Author
hannes-ucsc
requested changes
Apr 14, 2026
Contributor
Author
Tests pass with new (0.4.4-61) bigquery_emulator image. |
dsotirho-ucsc
added a commit
that referenced
this pull request
Apr 14, 2026
cdafaa0 to
b4313cf
Compare
Contributor
Author
hannes-ucsc
previously approved these changes
Apr 14, 2026
Member
Security design review
|
b4313cf to
d0eb2d9
Compare
hannes-ucsc
approved these changes
Apr 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Linked issue: #7925
Checklist
Author
developupgrades/yyyy-mm-ddUpgrade software dependencies yyyy-mm-ddAuthor (upgrading deployments)
make docker_images.jsonand committed the resulting changes or this PR does not modifyazul_docker_images, or any other variables referenced in the definition of that variableutag to commit title or this PR does not require upgrading deploymentsupgradeor does not require upgrading deploymentsdeploy:sharedor does not modifydocker_images.json, and does not require deploying thesharedcomponent for any other reasondeploy:gitlabor does not require deploying thegitlabcomponentbackup:gitlabdeploy:runneror does not require deploying therunnerimageAuthor (before every review)
develop, squashed fixups from prior reviewsmake requirements_updateor this PR does not modifyDockerfile,environment,requirements*.txt,common.mk,Makefileorenvironment.bootRtag to commit title or this PR does not modifyrequirements*.txtreqsor does not modifyrequirements*.txtAL2023_releasevariable in gitlab.tf.json.template.py to the most recent AL2023 release or no update is availablemake integration_testpasses in personal deployment or this PR does not modify functionality that could affect the IT outcomeSystem administrator (after approval)
no demoN reviewslabel is accurateOperator
developOperator (deploy
.sharedand.gitlabcomponents)_select dev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unusedor this PR is not labeleddeploy:shared_select dev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart(see operator manual for details) or this PR is not labeledbackup:gitlab_select dev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab applyor this PR is not labeleddeploy:gitlab_select anvildev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unusedor this PR is not labeleddeploy:shared_select anvildev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart(see operator manual for details) or this PR is not labeledbackup:gitlab_select anvildev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab applyor this PR is not labeleddeploy:gitlabdeploy:gitlabdeploy:gitlabSystem administrator (post-deploy of
.gitlabcomponent)dev.gitlabare complete or this PR is not labeleddeploy:gitlabanvildev.gitlabare complete or this PR is not labeleddeploy:gitlabOperator (deploy runner image)
_select dev.gitlab && make -C terraform/gitlab/runneror this PR is not labeleddeploy:runner_select anvildev.gitlab && make -C terraform/gitlab/runneror this PR is not labeleddeploy:runnerOperator (sandbox build)
sandboxlabeldevanvildevsandboxdeploymentanvilboxdeploymentsandboxdeploymentanvilboxdeploymentOperator (merge the branch)
ptagsOperator (main build)
devanvildevdevdevanvildevanvildev_select dev.shared && make -C terraform/shared applyor this PR is not labeleddeploy:shared_select anvildev.shared && make -C terraform/shared applyor this PR is not labeleddeploy:shareddevanvildevOperator
anvildev.sharedwas last deployedscripts/export_inspector_findings.pyagainstanvildev, imported results to Google Sheet and posted screenshot of relevant1 findings as a comment on the linked issue.deploy:shared,deploy:gitlab,deploy:runnerandbackup:gitlablabels to the next promotion PRs or this PR carries none of these labelsdeploy:shared,deploy:gitlab,deploy:runnerandbackup:gitlablabels, from the description of this PR to that of the next promotion PRs or this PR carries none of these labels1A relevant finding is a high or critical vulnerability in an image
that is used within the security boundary. Images not used within the boundary
are tracked in
azul.docker_imagesunder a key starting with_.System administrator
Shorthand for review comments
Lline is too longWline wrapping is wrongQbad quotesFother formatting problem