Update boto3 requirement from >=1.43.6 to >=1.43.9 in /listener #33
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#33
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "dependabot/pip/listener/boto3-gte-1.43.9"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Updates the requirements on boto3 to permit the latest version.
Commits
6d47260Merge branch 'release-1.43.9'7fb9872Bumping version to 1.43.91881c7fAdd changelog entries from botocore7a82579Merge branch 'release-1.43.8'9ff48ecMerge branch 'release-1.43.8' into develop06a1d63Bumping version to 1.43.82b6e7bdAdd changelog entries from botocoree6aee5dMerge branch 'release-1.43.7'05566d2Merge branch 'release-1.43.7' into develop37e8136Bumping version to 1.43.7Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)LGTM — straightforward Dependabot patch-level version bump for boto3.
Extended reasoning...
Overview
This PR updates a single line in
listener/requirements.txt, bumping the boto3 minimum version constraint from>=1.43.6to>=1.43.9. The change is a Dependabot patch-level update spanning three patch releases (1.43.7, 1.43.8, 1.43.9).Security risks
None. This is a minimum-version bump in a requirements file. Patch-level boto3 releases typically include bug fixes and AWS service model updates rather than breaking changes or security-relevant API changes. If anything, picking up newer patch releases is generally beneficial for security.
Level of scrutiny
Minimal scrutiny is warranted. This is a one-line constraint loosening in a dependency manifest — exactly the pattern of routine Dependabot PRs that are safe to auto-merge. Recent commits show the same pattern (boto3 1.43.2 → 1.43.6, google-auth, google-api-python-client, python-ulid) being merged on this repo.
Other factors
The bug hunting system found no issues. No outstanding reviewer comments. The PR follows the established convention in the repo for dependency bumps.