Skip to content

Locking down dependencies for www.python.org #2988

@sethmlarson

Description

@sethmlarson

Describe the bug

  • Install from a lock file with hashes.
  • Enable Dependabot with cooldowns to upgrade dependencies over time.
  • Using Python 3.12.6 (3.12.10 is available). Should figure out a reliable upgrade strategy.
  • Remove external dependencies that aren't needed:
    • Installing old pandoc from GitHub releases. Can we use pypandoc-binary?
    • Using ewdurbin/ngix-static Dockerfile, likely outdated. Can we manage Nginx separately?

To Reproduce

N/A

Expected behavior

N/A

URL to the issue

No response

Screenshots

N/A

Browsers

Other

Operating System

Other

Browser Version

No response

Relevant log output

Additional context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugThis is a bug!

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions