Skip to content

Comments

Bump black, ipython in poetry verification test resources#1666

Merged
JamieMagee merged 2 commits intomainfrom
fix/update-poetry-verification-deps
Feb 18, 2026
Merged

Bump black, ipython in poetry verification test resources#1666
JamieMagee merged 2 commits intomainfrom
fix/update-poetry-verification-deps

Conversation

@JamieMagee
Copy link
Member

@JamieMagee JamieMagee commented Feb 18, 2026

Bumps dev dependencies in the poetry verification test fixture:

  • black ^21.10b0 -> ^24.3.0
  • ipython ^7.7 -> ^8.10

The old ipython version has an arbitrary code execution vulnerability (CVE-2023-24816).

Copilot AI review requested due to automatic review settings February 18, 2026 19:12
@JamieMagee JamieMagee requested a review from a team as a code owner February 18, 2026 19:12
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates dev dependencies in the poetry verification test fixture to address a security vulnerability and modernize dependency versions. The changes affect test resources used by VerificationTest.ps1 to validate the poetry detector's functionality against real-world package configurations.

Changes:

  • Bumps black from ^21.10b0 to ^24.3.0 (lock file: 21.12b0 → 24.10.0)
  • Bumps ipython from ^7.7 to ^8.10 (lock file: 7.16.3 → 8.31.0) to fix CVE-2023-24816 arbitrary code execution vulnerability
  • Updates transitive dependencies in poetry.lock (py, pydantic, pygments, zipp)

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
test/Microsoft.ComponentDetection.VerificationTests/resources/poetry/pyproject.toml Updates black and ipython version constraints in dev-dependencies
test/Microsoft.ComponentDetection.VerificationTests/resources/poetry/poetry.lock Regenerated lock file with updated versions of black, ipython, and their transitive dependencies

@codecov
Copy link

codecov bot commented Feb 18, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.8%. Comparing base (2ecde67) to head (5f3effa).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##            main   #1666     +/-   ##
=======================================
- Coverage   90.8%   90.8%   -0.1%     
=======================================
  Files        451     451             
  Lines      40148   40148             
  Branches    2443    2443             
=======================================
- Hits       36461   36460      -1     
  Misses      3188    3188             
- Partials     499     500      +1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@github-actions
Copy link

👋 Hi! It looks like you modified some files in the Detectors folder.
You may need to bump the detector versions if any of the following scenarios apply:

  • The detector detects more or fewer components than before
  • The detector generates different parent/child graph relationships than before
  • The detector generates different devDependencies values than before

If none of the above scenarios apply, feel free to ignore this comment 🙂

@JamieMagee JamieMagee merged commit 90cf439 into main Feb 18, 2026
27 checks passed
@JamieMagee JamieMagee deleted the fix/update-poetry-verification-deps branch February 18, 2026 20:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants