Update slack-sdk requirement from >=3.42.0 to >=3.43.0 in /listener #65
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#65
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "dependabot/pip/listener/slack-sdk-gte-3.43.0"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Updates the requirements on slack-sdk to permit the latest version.
Release notes
Sourced from slack-sdk's releases.
Commits
3a5cec2chore(release): version 3.43.0 (#1902)0ffc13ffeat: make thread_ts optional for assistant.threads.setSuggestedPrompts (#1901)e23b181docs: restore canonical security policy over bot-added SECURITY.md (#1897)ecb8ae9docs: fixing broken links to security concepts (#1896)74a9330docs: removing external links for unified nav (#1895)0b4f57bchore(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 (#1894)d3058cadocs: audit and fix docs/english markdown files (#1883)2491a2dchore(deps): update flake8 requirement from <8,>=5.0.4 to >=7.3.0,<8 (#1889)c955baechore(deps): update pytest-cov requirement from <8,>=2 to >=7.1.0,<8 (#1885)fdfdd21chore(deps): bump docutils from 0.22.4 to 0.23 (#1886)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Open SWE Review found 1 potential issue.
Open in Web
@ -1,3 +1,3 @@slack-bolt>=1.28.0slack-sdk>=3.42.0slack-sdk>=3.43.0boto3>=1.43.24🟠 slack-sdk 3.43.0 requires slack-bolt >=1.29.0
The slack-sdk 3.43.0 release notes (quoted in the PR description) state: "A signing secret is now required to exist when validating requests. Apps that receive events with Socket Mode should update to Bolt for Python 1.29.0 to avoid errors at initialization."
This repo's listener uses Socket Mode (
slack_bolt.adapter.socket_mode.SocketModeHandler) and initializesApp(token=...)without asigning_secret. It currently pinsslack-bolt>=1.28.0, which is below the required 1.29.0. After this dependency bump,pipcan resolve a combination such asslack-sdk==3.43.0+slack-bolt==1.28.0, which will fail at startup with a signing-secret validation error.Bump the slack-bolt requirement to
>=1.29.0in the same file to keep the Socket Mode listener compatible with the new slack-sdk version.(Refers to line 2)
Your feedback helps Open SWE learn. React with 👍 or 👎 to tell us if this review comment was useful.
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting
@dependabot ignore this major versionor@dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding anignorecondition with the desiredupdate_typesto your config file.If you change your mind, just re-open this PR and I'll resolve any conflicts on it.