Update slack-sdk requirement from >=3.42.0 to >=3.43.0 in /listener #65

Closed
dependabot[bot] wants to merge 1 commit from dependabot/pip/listener/slack-sdk-gte-3.43.0 into main
Showing only changes of commit 89cc8626c7 - Show all commits

View file

@ -1,3 +1,3 @@
slack-bolt>=1.28.0
slack-sdk>=3.42.0
slack-sdk>=3.43.0
boto3>=1.43.24
seahaven-openswe[bot] commented 2026-07-04 16:24:27 +00:00 (Migrated from github.com)
Review

🟠 slack-sdk 3.43.0 requires slack-bolt >=1.29.0

The slack-sdk 3.43.0 release notes (quoted in the PR description) state: "A signing secret is now required to exist when validating requests. Apps that receive events with Socket Mode should update to Bolt for Python 1.29.0 to avoid errors at initialization."

This repo's listener uses Socket Mode (slack_bolt.adapter.socket_mode.SocketModeHandler) and initializes App(token=...) without a signing_secret. It currently pins slack-bolt>=1.28.0, which is below the required 1.29.0. After this dependency bump, pip can resolve a combination such as slack-sdk==3.43.0 + slack-bolt==1.28.0, which will fail at startup with a signing-secret validation error.

Bump the slack-bolt requirement to >=1.29.0 in the same file to keep the Socket Mode listener compatible with the new slack-sdk version.

(Refers to line 2)


Your feedback helps Open SWE learn. React with 👍 or 👎 to tell us if this review comment was useful.

slack-bolt>=1.29.0
slack-sdk>=3.43.0
boto3>=1.43.24
<!-- open-swe-review-comment {"id":"f_8716e36d6a","file_path":"listener/requirements.txt","start_line":2,"end_line":2,"side":"RIGHT"} --> 🟠 **slack-sdk 3.43.0 requires slack-bolt >=1.29.0** The slack-sdk 3.43.0 release notes (quoted in the PR description) state: *"A signing secret is now required to exist when validating requests. Apps that receive events with Socket Mode should update to Bolt for Python 1.29.0 to avoid errors at initialization."* This repo's listener uses Socket Mode (`slack_bolt.adapter.socket_mode.SocketModeHandler`) and initializes `App(token=...)` without a `signing_secret`. It currently pins `slack-bolt>=1.28.0`, which is below the required 1.29.0. After this dependency bump, `pip` can resolve a combination such as `slack-sdk==3.43.0` + `slack-bolt==1.28.0`, which will fail at startup with a signing-secret validation error. Bump the slack-bolt requirement to `>=1.29.0` in the same file to keep the Socket Mode listener compatible with the new slack-sdk version. *(Refers to line 2)* --- *Your feedback helps Open SWE learn. React with 👍 or 👎 to tell us if this review comment was useful.* ```suggestion slack-bolt>=1.29.0 slack-sdk>=3.43.0 boto3>=1.43.24 ```