chore: tighten Pipfile — security patches, test deps to dev, audit tooling - #3
Conversation
There was a problem hiding this comment.
Pull request overview
Updates Python dependency set to patched versions (notably Django/DRF) and adds dependency/security tooling, aiming to address security concerns and improve auditing for this Django REST API codebase.
Changes:
- Pin security-critical runtime dependencies (Django 5.2.13, DRF 3.17.1, django-cors-headers 4.9.0) and refresh lockfile resolutions.
- Add/upgrade dev tooling (black/isort) and introduce auditing/license tools (pip-audit, safety, pipdeptree, pip-licenses).
- Extend
.gitignoreto ignoreresults/andrequirements.txt.
Reviewed changes
Copilot reviewed 1 out of 3 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| Pipfile | Pins core deps; adds setuptools/wheel; adds dev audit/license tooling. |
| Pipfile.lock | Re-locks dependency graph to updated versions and new tooling deps. |
| .gitignore | Ignores results/ and requirements.txt. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Agent-Logs-Url: https://github.com/oreplay/oreplay-python/sessions/8ae75a3c-7e4b-4eba-a696-04f69c74215d Co-authored-by: udernaeb <118601411+udernaeb@users.noreply.github.com>
|
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 3 changed files in this pull request and generated 1 comment.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
@copilot apply changes based on the comments in this thread |
Updated the PR description to comprehensively cover all changes in the branch:
The PR description now accurately reflects the full scope of changes rather than just the test-dependency move. |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 3 changed files in this pull request and generated no new comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.



Addresses several Pipfile hygiene issues: security-vulnerable runtime deps, test tooling leaking into the production image, and a duplicate
pytest-djangoconstraint causing an unsatisfiable lockfile.Dependency changes
django→5.2.13,djangorestframework→3.17.1,django-cors-headers→4.9.0setuptools==82.0.1,wheel==0.46.3to[packages]black→26.3.1,isort→8.0.1pip-audit,safety,pipdeptree,pip-licensesTest deps moved to
[dev-packages]pytest,pytest-django,pytest-covwere under[packages], causing them to be installed in the runtime container (pipenv installindocker/Dockerfile). Also resolves the conflicting duplicatepytest-djangoentry:Other
.gitignore: addedresults/andrequirements.txtPipfile.lockregenerated