Long overdue maintenance - #146
Merged
Merged
Conversation
Updated requirements.txt Removed runtime.txt -> migrated to .python-version Updated token serializers with specific salts for reset/tokens Replaced flask_recaptcha with recaptcha_helper Capped bcrypt 5 password at 72 bytes before hashing/checking Removed taskapp_email variable and old base.html Add pytest
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Starting to put some more work in on TaskApp. Bringing some packages up to date and adding some long overdue automations.
Changes Overview
requirements.txtis now generated with hashes (that's most of the 12k additions), pip-audit comes back clean.URLSafeTimedSerializer.flask_recaptchais unmaintained and breaks on current Jinja, so it's swapped for a smallrecaptcha_helper.py.recaptcha.verify()works the same as before.base.html.requirements.txtstill matchesrequirements.in, and runs pip-audit. Also re-audits master every Monday for new CVEs.runtime.txtis deprecated, so it's migrated to.python-version. Set to3.14so Heroku picks up patch releases on its own.Adding a package
Add it to
requirements.in(orrequirements-dev.inif it's only for tests), then regenerate the matching.txtand commit both files.pip-tools
uv
To bump a single package without touching the rest, add
--upgrade-package <name>to either command.@rmobis @cringland I'll hold off on merging until later this weekend to give y'all a chance to review in case I borked anything. Mostly updates and some tests AI whipped up; I'm far too lazy to write my own tests.