build: bump python from 86f975a to 23c5939 in /docker - #421
Conversation
|
ZETETIC-REVIEW: REQUEST_CHANGES Stakes: Low (single-line digest bump, Digest verification (point 1)Resolved Blocking — comment block above the changed line is wrong (§8 source discipline)Not introduced by this diff, but sitting directly in the same block this PR modifies (
The actual pinned tag on both Blocking — branch is stale against
|
Bumps python from `86f975a` to `23c5939`. --- updated-dependencies: - dependency-name: python dependency-version: 3.14-slim-bookworm dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
The digest-verification comment above the FROM line named python:3.12-slim-bookworm while the actual pinned tag is 3.14-slim-bookworm (has been since the image moved off 3.12 per the runtime-stage COPY-path incident note lower in this file). Re-fetched the docker-content-digest header against the correct 3.14-slim-bookworm manifest and confirmed it matches the pinned sha unchanged. Co-Authored-By: Claude <noreply@anthropic.com>
a717479 to
7ebbaaf
Compare
|
Note for reviewers (non-blocking): this repo pins three separate Dockerfiles to python:3.14, but on two different base-image variants — deliberately, not by drift.
Each Dockerfile is refreshed independently by its own Dependabot |
|
ZETETIC-REVIEW: APPROVE Move 0: no ledger applicable (digest-only Dockerfile pin update); no seen-defect rationalization present. Verified on head 7ebbaaf (merge-base with origin/main == origin/main HEAD cdf084b — branch is current):
Mergeable as-is. |
Bumps python from
86f975ato23c5939.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)