Skip to content
This repository was archived by the owner on Aug 25, 2026. It is now read-only.

fix(deps): clear all 94 open dependabot alerts (7 critical) - #7

Merged
izam-mohammed merged 1 commit into
mainfrom
fix/dependabot-alerts
Aug 25, 2026
Merged

izam-mohammed merged 1 commit into
mainfrom
fix/dependabot-alerts

Conversation

@izam-mohammed

Copy link
Copy Markdown
Owner

all 94 alerts live in the two django exercises. both migrate poetry -> uv on the way past.

week_04_django_1/web_sample ~ 32 alerts

package needed now
django >= 5.2.16 5.2.17
sqlparse >= 0.6.0 0.6.0

week_06_django_2/django-blog ~ 62 alerts

this one was on django 3.1.7 with every plugin pinned to an exact version, which is why it collected 5 of the 7 criticals.

package was now
django 3.1.7 6.1
pillow 8.1.2 12.3.0
sqlparse 0.4.1 0.6.0
django-ckeditor 6.0.0 6.7.3
django-cleanup 5.1.0 9.0.0
django-etc 1.3.0 1.4.0
django-hitcount 1.3.3 1.3.5
future 0.18.2 removed

future is gone rather than patched ~ it was a python 2 compat shim and nothing in the tree still wanted it.

verified: manage.py check reports no issues on both projects.

two things to know before merging

  1. django 3.1 -> 6.1 is five majors. check passes and the plugins resolve, but nothing here has tests, so runtime behaviour is unverified. these are bootcamp notes rather than a running service, so the risk is mostly theoretical ~ say the word if you'd rather i pin to 5.2 LTS instead.
  2. django-ckeditor still bundles CKEditor 4.22.1, which is EOL with unfixed security issues of its own. check raises ckeditor.W001 about it. dependabot won't flag it (vendored JS, not a package), and there's no version of django-ckeditor that fixes it ~ the upstream fix is switching to django-ckeditor-5. out of scope here, but worth knowing it survives this PR.

both projects move poetry -> uv and get their deps dragged into this decade.

week_04/web_sample (32 alerts):
- django 5.0.6 -> 5.2.17, sqlparse -> 0.6.0

week_06/django-blog (62 alerts):
- django 3.1.7 -> 6.1
- pillow 8.1.2 -> 12.3.0
- the django-* plugins all unpinned from exact versions and moved to
  their latest (ckeditor 6.7.3, cleanup 9.0.0, etc 1.4.0, hitcount 1.3.5)
- future dropped entirely ~ it was a python 2 shim nothing needed anymore

manage.py check passes on both. these are course notes, not running
anything, so the upgrade risk is mostly theoretical.
@github-actions

Copy link
Copy Markdown

Security scan

Stage Scope Findings Result
1 · Secrets gitleaks — blocking — ✅ success
2 · Dependencies osv-scanner 0 ✅ success
3 · SAST semgrep (python packs) 99 ✅ success
4 · Workflows zizmor 2 ✅ success

Stages 2–4 report only; they do not block. Artifacts are retained 14 days.

Updated 2026-08-25T06:52:48.019Z · run

@izam-mohammed
izam-mohammed merged commit da25855 into main Aug 25, 2026
6 checks passed
@izam-mohammed
izam-mohammed deleted the fix/dependabot-alerts branch August 25, 2026 10:31
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant