Skip to content

VLN-1341: remediate missing-dependency-cooldown#1534

Closed
picatz wants to merge 1 commit into
mainfrom
camper/missing-dependency-cooldown-finding-cooldown-sdk-python
Closed

VLN-1341: remediate missing-dependency-cooldown#1534
picatz wants to merge 1 commit into
mainfrom
camper/missing-dependency-cooldown-finding-cooldown-sdk-python

Conversation

@picatz
Copy link
Copy Markdown
Contributor

@picatz picatz commented May 15, 2026

🏕️ This pull request was created by camper, an automated security campaign tool.

Finding

Rulemissing-dependency-cooldown
SeverityHIGH
Repositorytemporalio/sdk-python
TicketVLN-1341

Summary

  • pyproject.toml: Updated [tool.uv] exclude-newer from "1 week" to "2 weeks" without changing other settings in that section.
  • .github/dependabot.yml: Added Dependabot configuration for pip and github-actions with weekly schedules and cooldown.default-days: 14 for each ecosystem.

Instructions

  • Approve to merge this fix
  • Request changes to trigger a new remediation attempt
  • /camper rebase — rebase onto the base branch
  • /camper close — close this PR without merging
  • /camper retry — close and retry with a new fix

@picatz picatz requested a review from a team as a code owner May 15, 2026 16:29
@tconley1428
Copy link
Copy Markdown
Contributor

/camper rebase

@picatz picatz closed this May 21, 2026
@picatz
Copy link
Copy Markdown
Contributor Author

picatz commented May 21, 2026

Closing this PR: superseded: SDK team feedback: use uv ecosystem instead of pip, add open-pull-requests-limit: 0 to suppress version bump noise

@picatz
Copy link
Copy Markdown
Contributor Author

picatz commented May 21, 2026

@tconley1428 new PR is up over here: #1551

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants