Skip to content

build: bump setuptools from 83.0.0 to 84.0.0 in /requirements - #759

Open
blaipr wants to merge 1 commit into
ctrliq:mainfrom
blaipr:build/bump-setuptools-84.0.0-requirements
Open

build: bump setuptools from 83.0.0 to 84.0.0 in /requirements#759
blaipr wants to merge 1 commit into
ctrliq:mainfrom
blaipr:build/bump-setuptools-84.0.0-requirements

Conversation

@blaipr

@blaipr blaipr commented Aug 26, 2026

Copy link
Copy Markdown
Contributor
SUMMARY

Bumps setuptools from 83.0.0 to 84.0.0 in requirements/requirements.txt. It is the build backend the image uses for every source distribution it installs.

The Python requirements are outside Dependabot's scope on purpose: #675 turned on version updates for github-actions and for npm in /awx/ui and left this file out, because it is compiled by requirements/updater.sh rather than hand-pinned. So this was produced the same way make requirements produces it:

# requirements.in:  setuptools==83.0.0  ->  setuptools==84.0.0   (comment kept)
requirements/updater.sh run

run inside the ascender_devel image, which is where that script insists on running. Pinned with == in requirements.in, so upgrade cannot move it: the pin is edited first and run recompiles against it. The result is 1 added / 1 removed in each of the two files.

The # CVE-2026-59890 comment is deliberately kept on the pin. 83.0.0 is where that fix landed, so 84.0.0 stays above it and the reason for pinning still reads true; the comment would only be wrong if the pin ever moved down.

Like the other build-toolchain bumps in this batch, the unit suite passing says less here than it does for a library: setuptools is exercised when the image builds a source distribution, not by the tests. The real check is a green image build, which happens once the workflow is approved on this fork pull request.

ISSUE TYPE
  • Bug, Docs Fix or other nominal change
COMPONENT NAME
  • API
ASCENDER VERSION
25.5.1

Tests

Tested before opening, in the same image, with setuptools 84.0.0 installed into the AWX venv:

py.test awx/main/tests/unit awx/conf/tests/unit awx/sso/tests/unit
  1404 passed, 1 skipped in 12.84s

CI does not run on pull requests from a fork until a maintainer approves the workflow, so this is what stands behind the change until then.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant