Skip to content

Conversation

@boilsquid
Copy link
Contributor

@boilsquid boilsquid commented Jun 19, 2025

Why

This PR will create a new major version v5 which will deprecate python versions 3.8 and 3.9

How

  • Upgrade dependencies cryptography, responses, flake8 and black
  • Update the CI to remove legacy python versions
  • Replace type checks with isinstance()

@changeset-bot
Copy link

changeset-bot bot commented Jun 19, 2025

🦋 Changeset detected

Latest commit: 7d55b5f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
evervault-python Major

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@socket-security
Copy link

socket-security bot commented Jun 19, 2025

@socket-security
Copy link

socket-security bot commented Jun 19, 2025

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert (click for details)
Warn High
pypi/urllib3@2.5.0 has a License Policy Violation.

License: MPL-2.0 (urllib3-2.5.0/test/contrib/emscripten/templates/pyodide-console.html)

From: poetry.lockpypi/urllib3@2.5.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/urllib3@2.5.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@boilsquid boilsquid force-pushed the eoin/patch-dependencies branch from db4b20b to 59f5cf1 Compare June 19, 2025 11:46
@boilsquid boilsquid force-pushed the eoin/patch-dependencies branch from 59f5cf1 to 8dd0dfb Compare June 19, 2025 11:47
@boilsquid boilsquid marked this pull request as ready for review June 19, 2025 11:59
@boilsquid boilsquid requested a review from a team as a code owner June 19, 2025 11:59
@boilsquid boilsquid merged commit 0698497 into master Jun 19, 2025
8 checks passed
@boilsquid boilsquid deleted the eoin/patch-dependencies branch June 19, 2025 12:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants