Update slack-sdk requirement from >=3.42.0 to >=3.43.0 in /listener #65

Closed
dependabot[bot] wants to merge 1 commit from dependabot/pip/listener/slack-sdk-gte-3.43.0 into main
dependabot[bot] commented 2026-07-04 16:22:51 +00:00 (Migrated from github.com)

Updates the requirements on slack-sdk to permit the latest version.

Release notes

Sourced from slack-sdk's releases.

v3.43.0

What's Changed

⚠️ Warning: A signing secret is now required to exist when validating requests. Apps that receive events with Socket Mode should update to Bolt for Python 1.29.0 to avoid errors at initialization. Please refer to this issue: slackapi/python-slack-sdk#1903

🚀 Enhancements

📚 Documentation

🔒 Security

📦 Other changes

New Contributors

Full Changelog: https://github.com/slackapi/python-slack-sdk/compare/v3.42.0...v3.43.0 Milestone: https://github.com/slackapi/python-slack-sdk/milestone/119

Commits
  • 3a5cec2 chore(release): version 3.43.0 (#1902)
  • 0ffc13f feat: make thread_ts optional for assistant.threads.setSuggestedPrompts (#1901)
  • e23b181 docs: restore canonical security policy over bot-added SECURITY.md (#1897)
  • ecb8ae9 docs: fixing broken links to security concepts (#1896)
  • 74a9330 docs: removing external links for unified nav (#1895)
  • 0b4f57b chore(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 (#1894)
  • d3058ca docs: audit and fix docs/english markdown files (#1883)
  • 2491a2d chore(deps): update flake8 requirement from <8,>=5.0.4 to >=7.3.0,<8 (#1889)
  • c955bae chore(deps): update pytest-cov requirement from <8,>=2 to >=7.1.0,<8 (#1885)
  • fdfdd21 chore(deps): bump docutils from 0.22.4 to 0.23 (#1886)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Updates the requirements on [slack-sdk](https://github.com/slackapi/python-slack-sdk) to permit the latest version. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/slackapi/python-slack-sdk/releases">slack-sdk's releases</a>.</em></p> <blockquote> <h2>v3.43.0</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <blockquote> <p>⚠️ Warning: A signing secret is now required to exist when validating requests. Apps that receive events with Socket Mode should update to Bolt for Python <code>1.29.0</code> to avoid errors at initialization. Please refer to this issue: <a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1903">slackapi/python-slack-sdk#1903</a></p> </blockquote> <h3>🚀 Enhancements</h3> <ul> <li>feat(web): expose public ts property on ChatStream by <a href="https://github.com/srtaalej"><code>@​srtaalej</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1880">slackapi/python-slack-sdk#1880</a></li> <li>feat: make thread_ts optional for assistant.threads.setSuggestedPrompts by <a href="https://github.com/zimeg"><code>@​zimeg</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1901">slackapi/python-slack-sdk#1901</a></li> </ul> <h3>📚 Documentation</h3> <ul> <li>docs: add security policy by <a href="https://github.com/WilliamBergamin"><code>@​WilliamBergamin</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1881">slackapi/python-slack-sdk#1881</a></li> <li>docs: removing external links for unified nav by <a href="https://github.com/haleychaas"><code>@​haleychaas</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1895">slackapi/python-slack-sdk#1895</a></li> <li>docs: fixing broken links to security concepts by <a href="https://github.com/haleychaas"><code>@​haleychaas</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1896">slackapi/python-slack-sdk#1896</a></li> <li>docs: restore canonical security policy over bot-added SECURITY.md by <a href="https://github.com/WilliamBergamin"><code>@​WilliamBergamin</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1897">slackapi/python-slack-sdk#1897</a></li> </ul> <h3>🔒 Security</h3> <ul> <li>fix(signature): validate signing_secret is a non-empty string by <a href="https://github.com/WilliamBergamin"><code>@​WilliamBergamin</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1884">slackapi/python-slack-sdk#1884</a></li> </ul> <h3>📦 Other changes</h3> <ul> <li>chore(deps): update aiohttp requirement from &lt;4,&gt;=3.7.3 to &gt;=3.13.5,&lt;4 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1867">slackapi/python-slack-sdk#1867</a></li> <li>chore(deps): update sqlalchemy requirement from &lt;3,&gt;=1.4 to &gt;=2.0.49,&lt;3 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1866">slackapi/python-slack-sdk#1866</a></li> <li>Add missing <code>style</code> attribute to RichTextElementParts.Date &amp; friends by <a href="https://github.com/Lexicality"><code>@​Lexicality</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1882">slackapi/python-slack-sdk#1882</a></li> <li>chore(deps): bump codecov/codecov-action from 6.0.0 to 6.0.1 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1891">slackapi/python-slack-sdk#1891</a></li> <li>chore(deps): bump slackapi/slack-github-action from 3.0.2 to 3.0.3 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1892">slackapi/python-slack-sdk#1892</a></li> <li>chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1893">slackapi/python-slack-sdk#1893</a></li> <li>chore(deps): bump actions/stale from 10.2.0 to 10.3.0 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1890">slackapi/python-slack-sdk#1890</a></li> <li>chore(deps): update moto requirement from &lt;6,&gt;=4.0.13 to &gt;=4.2.14,&lt;6 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1887">slackapi/python-slack-sdk#1887</a></li> <li>chore(deps): update asyncpg requirement from &lt;1,&gt;=0.27 to &gt;=0.31.0,&lt;1 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1888">slackapi/python-slack-sdk#1888</a></li> <li>chore(deps): bump docutils from 0.22.4 to 0.23 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1886">slackapi/python-slack-sdk#1886</a></li> <li>chore(deps): update pytest-cov requirement from &lt;8,&gt;=2 to &gt;=7.1.0,&lt;8 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1885">slackapi/python-slack-sdk#1885</a></li> <li>chore(deps): update flake8 requirement from &lt;8,&gt;=5.0.4 to &gt;=7.3.0,&lt;8 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1889">slackapi/python-slack-sdk#1889</a></li> <li>docs: audit and fix docs/english markdown files by <a href="https://github.com/lukegalbraithrussell"><code>@​lukegalbraithrussell</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1883">slackapi/python-slack-sdk#1883</a></li> <li>chore(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 by <a href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot] in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1894">slackapi/python-slack-sdk#1894</a></li> <li>chore(release): version 3.43.0 by <a href="https://github.com/zimeg"><code>@​zimeg</code></a> in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1902">slackapi/python-slack-sdk#1902</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/haleychaas"><code>@​haleychaas</code></a> made their first contribution in <a href="https://redirect.github.com/slackapi/python-slack-sdk/pull/1895">slackapi/python-slack-sdk#1895</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/slackapi/python-slack-sdk/compare/v3.42.0...v3.43.0">https://github.com/slackapi/python-slack-sdk/compare/v3.42.0...v3.43.0</a> <strong>Milestone</strong>: <a href="https://github.com/slackapi/python-slack-sdk/milestone/119">https://github.com/slackapi/python-slack-sdk/milestone/119</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/3a5cec2e79ebe58467c2c65781492a42938fdbfa"><code>3a5cec2</code></a> chore(release): version 3.43.0 (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1902">#1902</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/0ffc13f09d4b746def944e7bd1161dc7779afa27"><code>0ffc13f</code></a> feat: make thread_ts optional for assistant.threads.setSuggestedPrompts (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1901">#1901</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/e23b1814306d2e6c90eaab509d2724fd7406cff7"><code>e23b181</code></a> docs: restore canonical security policy over bot-added SECURITY.md (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1897">#1897</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/ecb8ae968f0c07d337c43ecd59ad72f36c494961"><code>ecb8ae9</code></a> docs: fixing broken links to security concepts (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1896">#1896</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/74a9330ed13f5e945e10eb840f8f00d46e952280"><code>74a9330</code></a> docs: removing external links for unified nav (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1895">#1895</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/0b4f57b3e9625dcb5a8c0223e0ae03b00cc66ab6"><code>0b4f57b</code></a> chore(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1894">#1894</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/d3058ca2e5d01fd08ef7b78b10098b097a39b70b"><code>d3058ca</code></a> docs: audit and fix docs/english markdown files (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1883">#1883</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/2491a2d77f3464a3c148b815fe2acd99ddb8faec"><code>2491a2d</code></a> chore(deps): update flake8 requirement from &lt;8,&gt;=5.0.4 to &gt;=7.3.0,&lt;8 (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1889">#1889</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/c955bae4310ed864790c396e14cbac46411e8afa"><code>c955bae</code></a> chore(deps): update pytest-cov requirement from &lt;8,&gt;=2 to &gt;=7.1.0,&lt;8 (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1885">#1885</a>)</li> <li><a href="https://github.com/slackapi/python-slack-sdk/commit/fdfdd2103906b0b64840c0bd190f90db83fa0868"><code>fdfdd21</code></a> chore(deps): bump docutils from 0.22.4 to 0.23 (<a href="https://redirect.github.com/slackapi/python-slack-sdk/issues/1886">#1886</a>)</li> <li>Additional commits viewable in <a href="https://github.com/slackapi/python-slack-sdk/compare/v3.42.0...v3.43.0">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details>
seahaven-openswe[bot] (Migrated from github.com) reviewed 2026-07-04 16:24:27 +00:00
seahaven-openswe[bot] (Migrated from github.com) left a comment

Open SWE Review found 1 potential issue.

Open in Web

**Open SWE Review** found 1 potential issue. [Open in Web](https://openswe.seahaven.com/agents/reviews/Sea-Haven-Industries/exec-aide/65) <!-- open-swe-reviewer pr=65 -->
@ -1,3 +1,3 @@
slack-bolt>=1.28.0
slack-sdk>=3.42.0
slack-sdk>=3.43.0
boto3>=1.43.24
seahaven-openswe[bot] (Migrated from github.com) commented 2026-07-04 16:24:27 +00:00

🟠 slack-sdk 3.43.0 requires slack-bolt >=1.29.0

The slack-sdk 3.43.0 release notes (quoted in the PR description) state: "A signing secret is now required to exist when validating requests. Apps that receive events with Socket Mode should update to Bolt for Python 1.29.0 to avoid errors at initialization."

This repo's listener uses Socket Mode (slack_bolt.adapter.socket_mode.SocketModeHandler) and initializes App(token=...) without a signing_secret. It currently pins slack-bolt>=1.28.0, which is below the required 1.29.0. After this dependency bump, pip can resolve a combination such as slack-sdk==3.43.0 + slack-bolt==1.28.0, which will fail at startup with a signing-secret validation error.

Bump the slack-bolt requirement to >=1.29.0 in the same file to keep the Socket Mode listener compatible with the new slack-sdk version.

(Refers to line 2)


Your feedback helps Open SWE learn. React with 👍 or 👎 to tell us if this review comment was useful.

slack-bolt>=1.29.0
slack-sdk>=3.43.0
boto3>=1.43.24
<!-- open-swe-review-comment {"id":"f_8716e36d6a","file_path":"listener/requirements.txt","start_line":2,"end_line":2,"side":"RIGHT"} --> 🟠 **slack-sdk 3.43.0 requires slack-bolt >=1.29.0** The slack-sdk 3.43.0 release notes (quoted in the PR description) state: *"A signing secret is now required to exist when validating requests. Apps that receive events with Socket Mode should update to Bolt for Python 1.29.0 to avoid errors at initialization."* This repo's listener uses Socket Mode (`slack_bolt.adapter.socket_mode.SocketModeHandler`) and initializes `App(token=...)` without a `signing_secret`. It currently pins `slack-bolt>=1.28.0`, which is below the required 1.29.0. After this dependency bump, `pip` can resolve a combination such as `slack-sdk==3.43.0` + `slack-bolt==1.28.0`, which will fail at startup with a signing-secret validation error. Bump the slack-bolt requirement to `>=1.29.0` in the same file to keep the Socket Mode listener compatible with the new slack-sdk version. *(Refers to line 2)* --- *Your feedback helps Open SWE learn. React with 👍 or 👎 to tell us if this review comment was useful.* ```suggestion slack-bolt>=1.29.0 slack-sdk>=3.43.0 boto3>=1.43.24 ```
dependabot[bot] commented 2026-07-04 20:27:04 +00:00 (Migrated from github.com)

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting `@dependabot ignore this major version` or `@dependabot ignore this minor version`. You can also ignore all major, minor, or patch releases for a dependency by adding an [`ignore` condition](https://docs.github.com/en/code-security/supply-chain-security/configuration-options-for-dependency-updates#ignore) with the desired `update_types` to your config file. If you change your mind, just re-open this PR and I'll resolve any conflicts on it.
This repo is archived. You cannot comment on pull requests.
No description provided.