Repository navigation
Upgrade software dependencies 2026-09-28 (#8335) - #8356
Merged
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #8356 +/- ##
========================================
Coverage 84.92% 84.92%
========================================
Files 170 170
Lines 25593 25592 -1
========================================
Hits 21734 21734
+ Misses 3859 3858 -1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
54 tasks done
54 tasks done
achave11-ucsc
force-pushed
the
upgrades/2026-09-28
branch
2 times, most recently
from
October 1, 2026 17:14
4821548 to
c3dcd2a
Compare
Member
Author
|
|
hannes-ucsc
previously approved these changes
Oct 5, 2026
Member
Security design review
|
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
achave11-ucsc
force-pushed
the
upgrades/2026-09-28
branch
from
October 6, 2026 00:46
c3dcd2a to
fa3e231
Compare
hannes-ucsc
approved these changes
Oct 6, 2026
87 of 91 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Linked issue: #8335
Checklist
Author
A01PR is assigned to the authorA02Status of PR is In progressA03Target branch isdevelopA04Name of PR branch matchesupgrades/yyyy-mm-ddA05PR is linked to the upgrade issue it resolvesA06Status of linked issue is In progressA07PR description links to linked issueA08PR title matchesUpgrade software dependencies yyyy-mm-ddA09PR title references the linked issueAuthor (upgrading deployments)
F01Ranmake docker_images.jsonand committed the resulting changes or this PR does not modifyazul_docker_images, or any other variables referenced in the definition of that variableF02Documented upgrading of deployments in UPGRADING.rst or this PR does not require upgrading deploymentsF03Addedutag to commit title or this PR does not require upgrading deploymentsF04This PR is labeledupgradeor does not require upgrading deploymentsF05This PR is labeleddeploy:sharedor does not modifydocker_images.json, and does not require deploying thesharedcomponent for any other reasonF06This PR is labeleddeploy:gitlabor does not require deploying thegitlabcomponentF07This PR is labeledbackup:gitlabF08This PR is labeleddeploy:runneror does not require deploying therunnerimageAuthor (before every review)
H01Rebased PR branch ondevelop, squashed fixups from prior reviewsH02Ranmake requirements_updateor this PR does not modifypyproject.tomlH03AddedRtag to commit title or this PR does not modifyuv.lockH04This PR is labeledreqsor does not modifyuv.lockH05Updated theAL2023_releasevariable in gitlab.tf.json.template.py to the most recent AL2023 release or no update is availableH06make integration_testpasses inpersonaltempdev deployment or this PR does not modify functionality that could affect the IT outcomeH07PR is not a draftH08PR is awaiting requested review from system administratorH09Status of PR is Review requestedH10PR is assigned to only the system administrator and the authorSystem administrator (after approval)
K01Actually approved the PRK02Labeled linked issue asno demoK03A comment to this PR details the completed security design reviewK04PR title is appropriate as title of merge commitK05N reviewslabel is accurateK06Status of PR is ApprovedK07PR is assigned to only the operator and the authorOperator
L01Squashed PR branch and rebased ontodevelopL02Sanity-checked historyL03Pushed PR branch to GitHubOperator (deploy
.sharedand.gitlabcomponents)M01Ran_select dev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unusedor this PR is not labeleddeploy:sharedM02Ran_select dev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart(see operator manual for details) or this PR is not labeledbackup:gitlabM03Ran_select dev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab apply(an error from _login_docker_gitlab is benign if the instance was stopped for backup) or this PR is not labeleddeploy:gitlabM04Ran_select anvildev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unusedor this PR is not labeleddeploy:sharedM05Ran_select anvildev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart(see operator manual for details) or this PR is not labeledbackup:gitlabM06Ran_select anvildev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab apply(an error from _login_docker_gitlab is benign if the instance was stopped for backup) or this PR is not labeleddeploy:gitlabM07Checked the items in the next section or this PR is labeleddeploy:gitlabM08PR is assigned to only the system administrator and the author or this PR is not labeleddeploy:gitlabSystem administrator (post-deploy of
.gitlabcomponent)N01Background migrations fordev.gitlabare complete or this PR is not labeleddeploy:gitlabN02Background migrations foranvildev.gitlabare complete or this PR is not labeleddeploy:gitlabN03PR is assigned to only the operator and the authorOperator (deploy runner image)
P01Ran_select dev.gitlab && make -C terraform/gitlab/runneror this PR is not labeleddeploy:runnerP02Ran_select anvildev.gitlab && make -C terraform/gitlab/runneror this PR is not labeleddeploy:runnerOperator (sandbox build)
Q01AddedsandboxlabelQ02Pushed PR branch to GitLabdevQ03Pushed PR branch to GitLabanvildevQ04Build passes insandboxdeploymentQ05Build passes inanvilboxdeploymentQ06Reviewed build logs for anomalies insandboxdeploymentQ07Reviewed build logs for anomalies inanvilboxdeploymentQ08Applied upgrade instructions from UPGRADING.rst tosandboxor this PR is not labeledupgrade, or upgrade instructions do not apply tosandboxQ09Applied upgrade instructions from UPGRADING.rst toanvilboxor this PR is not labeledupgrade, or upgrade instructions do not apply toanvilboxOperator (merge the branch)
R01All status checks passed and the PR is mergeableR02The title of the merge commit starts with the title of this PRR03Added PR # reference to merge commit titleR04Collected commit title tags in merge commit title but excluded anyptagsR05Closed related Dependabot PRs with a comment referencing the corresponding commit in this PR or this PR does not include any such commitsR06Pushed merge commit to GitHubR07Status of PR is Merged lowerR08Status of blocked issues is Triage or no issues are blocked on the linked issueOperator (main build)
S01Pushed merge commit to GitLabdevS02Pushed merge commit to GitLabanvildevS03Build passes on GitLabdevS04Reviewed build logs for anomalies on GitLabdevS05Build passes on GitLabanvildevS06Reviewed build logs for anomalies on GitLabanvildevS07Applied upgrade instructions from UPGRADING.rst todevor this PR is not labeledupgrade, or upgrade instructions do not apply todevS08Applied upgrade instructions from UPGRADING.rst toanvildevor this PR is not labeledupgrade, or upgrade instructions do not apply toanvildevS09Notified developers to apply upgrade instructions from UPGRADING.rst to their personal deployments or this PR is not labeledupgrade, or upgrade instructions do not apply to personal deploymentsS10Ran_select dev.shared && make -C terraform/shared applyor this PR is not labeleddeploy:sharedS11Ran_select anvildev.shared && make -C terraform/shared applyor this PR is not labeleddeploy:sharedS12Deleted PR branch from GitHubS13PR is assigned to only the operatorS14Deleted PR branch from GitLabdevS15Deleted PR branch from GitLabanvildevS16Status of linked issue is LowerOperator
V01At least 24 hours have passed sinceanvildev.sharedwas last deployedV02Ranscripts/export_inspector_findings.pyagainstanvildev, imported results to Google Sheet and posted screenshot of relevant1 findings as a comment on the linked issue.V03Propagated theupgrade,API,deploy:shared,deploy:gitlab,deploy:runnerandbackup:gitlablabels to any open promotion PRs or this PR carries none of these labels, or is not included in an open promotion PRV04Propagated any specific instructions related to those labels, from the description of this PR to that of any open promotion PRs or this PR carries none of those labels, or is not included in an open promotion PRV05PR is assigned to only the system administrator1A relevant finding is a high or critical vulnerability in an image
that is used within the security boundary. Images not used within the boundary
are tracked in
azul.docker_imagesunder a key starting with_.System administrator
W01No currently reported vulnerability requires immediate attentionW02PR is assigned to no oneShorthand for review comments
Lline is too longWline wrapping is wrongQbad quotesFother formatting problem