Skip to content

fix: update pytest to drop dependency on vulnerable py package#354

Merged
jenstroeger merged 1 commit intostagingfrom
update-pytest
Oct 25, 2022
Merged

fix: update pytest to drop dependency on vulnerable py package#354
jenstroeger merged 1 commit intostagingfrom
update-pytest

Conversation

@jenstroeger
Copy link
Copy Markdown
Owner

See also: pytest-dev/py#287 (comment)

This PR supersedes #353

Copy link
Copy Markdown
Collaborator

@behnazh behnazh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving but I think we should take out make audit from build.yaml and dedicate a separate workflow for SCA analysis to prevent breaking builds in production.

@jenstroeger
Copy link
Copy Markdown
Owner Author

I think we should take out make audit from build.yaml and dedicate a separate workflow for SCA analysis to prevent breaking builds in production.

@behnazh agreed, and we’ll have a draft PR for such a change & discussion soon.

@jenstroeger jenstroeger merged commit db06702 into staging Oct 25, 2022
@jenstroeger jenstroeger deleted the update-pytest branch October 30, 2022 05:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants