Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump pytest to 7.2.0 #116

Merged
merged 1 commit into from
Mar 31, 2024
Merged

Bump pytest to 7.2.0 #116

merged 1 commit into from
Mar 31, 2024

Conversation

aisk
Copy link
Owner

@aisk aisk commented Mar 31, 2024

The main reason to upgrade pytest is that GitHub said this repo has a security issue: https://github.com/wong2/pick/security/dependabot/1

The security issue is in the py library and it's included by pytest. As mentioned in the issue, pytest doesn't trigger the security issue so we should be totally fine. But I think we should still resolve it to dismiss the security alert, otherwise someone else using pick may get the same security alert.

As mentioned in the security issue, the simple way to resolve it is just to upgrade pytest's version, which removed the py dependency.

@aisk aisk merged commit 783bc3f into master Mar 31, 2024
36 checks passed
@aisk aisk deleted the upgrade-pytest branch March 31, 2024 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants