Update slack-sdk requirement from >=3.41.0 to >=3.42.0 in /listener #35
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#35
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "dependabot/pip/listener/slack-sdk-gte-3.42.0"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Updates the requirements on slack-sdk to permit the latest version.
Release notes
Sourced from slack-sdk's releases.
Commits
4f7eeeechore(release): version 3.42.0 (#1876)e69ba32feat: add highlight_type to files.completeUploadExternal and files_upload_v2 ...beecde2feat(models): add BlockChunk type to chat.{start,append,stop}Stream methods (...73d255afeat(blocks): add Card, Carousel, and Alert block types (#1865)60bd43dfeat: add authorship arguments to assistant threads and chat stream (#1862)726538cchore(deps): bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0 (#1870)5338c2dchore(deps): bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 (#1868)632a205chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#1871)bec3906chore(deps): bump slackapi/slack-github-action from 3.0.1 to 3.0.2 (#1869)69163d6fix: resolve OAuth installation store bugs and typos (#1864)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)LGTM, straightforward Dependabot minor version bump.
Extended reasoning...
Overview
This PR is a Dependabot dependency update that bumps the
slack-sdkminimum version constraint from>=3.41.0to>=3.42.0inlistener/requirements.txt. The change is a single-line edit in a requirements file with no code changes.Security risks
Minor version bumps from upstream Slack SDK releases. The v3.42.0 release notes include bug fixes (Socket Mode stability, OAuth installation store fixes, SSL default in aiohttp) and additive features. No breaking changes flagged. Since this is a
>=constraint, the actual resolved version was already permitted to float above 3.41.0; this just raises the floor.Level of scrutiny
Low. This is a mechanical Dependabot PR touching only a requirements pin. No production logic is altered, and the change is well within the normal automated dependency-update flow.
Other factors
No bugs were reported by the bug hunting system. No prior reviews exist on this PR. The change pattern matches recent merged Dependabot PRs in this repo (e.g., #31-#34).