Skip to content

chore: tighten Pipfile — security patches, test deps to dev, audit tooling - #3

Merged
freefri merged 3 commits into
developfrom
fix/security-deps
Apr 9, 2026
Merged

freefri merged 3 commits into
developfrom
fix/security-deps

Conversation

@udernaeb

@udernaeb udernaeb commented Apr 8, 2026 •

Copy link
Copy Markdown
Contributor

Addresses several Pipfile hygiene issues: security-vulnerable runtime deps, test tooling leaking into the production image, and a duplicate pytest-django constraint causing an unsatisfiable lockfile.

Dependency changes

  • Security patches: django → 5.2.13, djangorestframework → 3.17.1, django-cors-headers → 4.9.0
  • Build tooling: added setuptools==82.0.1, wheel==0.46.3 to [packages]
  • Dev tooling upgrades: black → 26.3.1, isort → 8.0.1
  • New dev tools: pip-audit, safety, pipdeptree, pip-licenses

Test deps moved to [dev-packages]

pytest, pytest-django, pytest-cov were under [packages], causing them to be installed in the runtime container (pipenv install in docker/Dockerfile). Also resolves the conflicting duplicate pytest-django entry:

# Before
[packages]
pytest = "*"
pytest-django = "*"   # conflicts with dev-packages pin below
pytest-cov = "*"

[dev-packages]
pytest-django = "4.8.0"  # lockfile was resolving ==4.12.0 — unsatisfiable

# After
[packages]
# test tooling removed

[dev-packages]
pytest = "*"
pytest-django = "4.8.0"
pytest-cov = "*"

Other

  • .gitignore: added results/ and requirements.txt
  • Pipfile.lock regenerated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates Python dependency set to patched versions (notably Django/DRF) and adds dependency/security tooling, aiming to address security concerns and improve auditing for this Django REST API codebase.

Changes:

  • Pin security-critical runtime dependencies (Django 5.2.13, DRF 3.17.1, django-cors-headers 4.9.0) and refresh lockfile resolutions.
  • Add/upgrade dev tooling (black/isort) and introduce auditing/license tools (pip-audit, safety, pipdeptree, pip-licenses).
  • Extend .gitignore to ignore results/ and requirements.txt.

Reviewed changes

Copilot reviewed 1 out of 3 changed files in this pull request and generated 3 comments.

File Description
Pipfile Pins core deps; adds setuptools/wheel; adds dev audit/license tooling.
Pipfile.lock Re-locks dependency graph to updated versions and new tooling deps.
.gitignore Ignores results/ and requirements.txt.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread Pipfile Outdated
Comment thread Pipfile
Comment thread Pipfile
@sonarqubecloud

sonarqubecloud Bot commented Apr 8, 2026

Copy link
Copy Markdown

Copilot AI changed the title chore: update security-critical dependencies (Django, DRF, setuptools, wheel) chore: move test dependencies from [packages] to [dev-packages] Apr 8, 2026
@udernaeb
udernaeb requested a review from Copilot April 8, 2026 17:21

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 3 changed files in this pull request and generated 1 comment.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread Pipfile
@udernaeb

udernaeb commented Apr 8, 2026

Copy link
Copy Markdown
Contributor Author

@copilot apply changes based on the comments in this thread

Copilot AI commented Apr 8, 2026

Copy link
Copy Markdown

@copilot apply changes based on the comments in this thread

Updated the PR description to comprehensively cover all changes in the branch:

  • Security-critical runtime dependency upgrades (Django 5.2.13, DRF 3.17.1, django-cors-headers 4.9.0) with rationale
  • Addition of setuptools/wheel to [packages]
  • Move of test deps (pytest, pytest-django, pytest-cov) to [dev-packages]
  • Dev tooling upgrades (black, isort) and new audit tools (pip-audit, safety, etc.)
  • .gitignore and Pipfile.lock updates

The PR description now accurately reflects the full scope of changes rather than just the test-dependency move.

Copilot AI changed the title chore: move test dependencies from [packages] to [dev-packages] chore: tighten Pipfile — security patches, test deps to dev, audit tooling Apr 8, 2026
@udernaeb
udernaeb requested a review from Copilot April 8, 2026 17:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 3 changed files in this pull request and generated no new comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@freefri
freefri self-requested a review April 9, 2026 07:41

@freefri freefri left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i blindly approve this

@freefri
freefri merged commit 306b9ac into develop Apr 9, 2026
11 checks passed
@udernaeb
udernaeb deleted the fix/security-deps branch April 9, 2026 15:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants