Skip to content

Upgrade software dependencies 2026-09-28 (#8335) - #8356

Merged
achave11-ucsc merged 19 commits into
developfrom
upgrades/2026-09-28
Oct 7, 2026
Merged

achave11-ucsc merged 19 commits into
developfrom
upgrades/2026-09-28

Conversation

@achave11-ucsc

@achave11-ucsc achave11-ucsc commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Linked issue: #8335

Checklist

Author

  • A01 PR is assigned to the author
  • A02 Status of PR is In progress
  • A03 Target branch is develop
  • A04 Name of PR branch matches upgrades/yyyy-mm-dd
  • A05 PR is linked to the upgrade issue it resolves
  • A06 Status of linked issue is In progress
  • A07 PR description links to linked issue
  • A08 PR title matches Upgrade software dependencies yyyy-mm-dd
  • A09 PR title references the linked issue

Author (upgrading deployments)

  • F01 Ran make docker_images.json and committed the resulting changes or this PR does not modify azul_docker_images, or any other variables referenced in the definition of that variable
  • F02 Documented upgrading of deployments in UPGRADING.rst or this PR does not require upgrading deployments
  • F03 Added u tag to commit title or this PR does not require upgrading deployments
  • F04 This PR is labeled upgrade or does not require upgrading deployments
  • F05 This PR is labeled deploy:shared or does not modify docker_images.json, and does not require deploying the shared component for any other reason
  • F06 This PR is labeled deploy:gitlab or does not require deploying the gitlab component
  • F07 This PR is labeled backup:gitlab
  • F08 This PR is labeled deploy:runner or does not require deploying the runner image

Author (before every review)

  • H01 Rebased PR branch on develop, squashed fixups from prior reviews
  • H02 Ran make requirements_update or this PR does not modify pyproject.toml
  • H03 Added R tag to commit title or this PR does not modify uv.lock
  • H04 This PR is labeled reqs or does not modify uv.lock
  • H05 Updated the AL2023_release variable in gitlab.tf.json.template.py to the most recent AL2023 release or no update is available
  • H06 make integration_test passes in personal tempdev deployment or this PR does not modify functionality that could affect the IT outcome
  • H07 PR is not a draft
  • H08 PR is awaiting requested review from system administrator
  • H09 Status of PR is Review requested
  • H10 PR is assigned to only the system administrator and the author

System administrator (after approval)

  • K01 Actually approved the PR
  • K02 Labeled linked issue as no demo
  • K03 A comment to this PR details the completed security design review
  • K04 PR title is appropriate as title of merge commit
  • K05 N reviews label is accurate
  • K06 Status of PR is Approved
  • K07 PR is assigned to only the operator and the author

Operator

  • L01 Squashed PR branch and rebased onto develop
  • L02 Sanity-checked history
  • L03 Pushed PR branch to GitHub

Operator (deploy .shared and .gitlab components)

  • M01 Ran _select dev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unused or this PR is not labeled deploy:shared
  • M02 Ran _select dev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart (see operator manual for details) or this PR is not labeled backup:gitlab
  • M03 Ran _select dev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab apply(an error from _login_docker_gitlab is benign if the instance was stopped for backup) or this PR is not labeled deploy:gitlab
  • M04 Ran _select anvildev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unused or this PR is not labeled deploy:shared
  • M05 Ran _select anvildev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart (see operator manual for details) or this PR is not labeled backup:gitlab
  • M06 Ran _select anvildev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab apply(an error from _login_docker_gitlab is benign if the instance was stopped for backup) or this PR is not labeled deploy:gitlab
  • M07 Checked the items in the next section or this PR is labeled deploy:gitlab
  • M08 PR is assigned to only the system administrator and the author or this PR is not labeled deploy:gitlab

System administrator (post-deploy of .gitlab component)

  • N01 Background migrations for dev.gitlab are complete or this PR is not labeled deploy:gitlab
  • N02 Background migrations for anvildev.gitlab are complete or this PR is not labeled deploy:gitlab
  • N03 PR is assigned to only the operator and the author

Operator (deploy runner image)

  • P01 Ran _select dev.gitlab && make -C terraform/gitlab/runner or this PR is not labeled deploy:runner
  • P02 Ran _select anvildev.gitlab && make -C terraform/gitlab/runner or this PR is not labeled deploy:runner

Operator (sandbox build)

  • Q01 Added sandbox label
  • Q02 Pushed PR branch to GitLab dev
  • Q03 Pushed PR branch to GitLab anvildev
  • Q04 Build passes in sandbox deployment
  • Q05 Build passes in anvilbox deployment
  • Q06 Reviewed build logs for anomalies in sandbox deployment
  • Q07 Reviewed build logs for anomalies in anvilbox deployment
  • Q08 Applied upgrade instructions from UPGRADING.rst to sandbox or this PR is not labeled upgrade, or upgrade instructions do not apply to sandbox
  • Q09 Applied upgrade instructions from UPGRADING.rst to anvilbox or this PR is not labeled upgrade, or upgrade instructions do not apply to anvilbox

Operator (merge the branch)

  • R01 All status checks passed and the PR is mergeable
  • R02 The title of the merge commit starts with the title of this PR
  • R03 Added PR # reference to merge commit title
  • R04 Collected commit title tags in merge commit title but excluded any p tags
  • R05 Closed related Dependabot PRs with a comment referencing the corresponding commit in this PR or this PR does not include any such commits
  • R06 Pushed merge commit to GitHub
  • R07 Status of PR is Merged lower
  • R08 Status of blocked issues is Triage or no issues are blocked on the linked issue

Operator (main build)

  • S01 Pushed merge commit to GitLab dev
  • S02 Pushed merge commit to GitLab anvildev
  • S03 Build passes on GitLab dev
  • S04 Reviewed build logs for anomalies on GitLab dev
  • S05 Build passes on GitLab anvildev
  • S06 Reviewed build logs for anomalies on GitLab anvildev
  • S07 Applied upgrade instructions from UPGRADING.rst to dev or this PR is not labeled upgrade, or upgrade instructions do not apply to dev
  • S08 Applied upgrade instructions from UPGRADING.rst to anvildev or this PR is not labeled upgrade, or upgrade instructions do not apply to anvildev
  • S09 Notified developers to apply upgrade instructions from UPGRADING.rst to their personal deployments or this PR is not labeled upgrade, or upgrade instructions do not apply to personal deployments
  • S10 Ran _select dev.shared && make -C terraform/shared apply or this PR is not labeled deploy:shared
  • S11 Ran _select anvildev.shared && make -C terraform/shared apply or this PR is not labeled deploy:shared
  • S12 Deleted PR branch from GitHub
  • S13 PR is assigned to only the operator
  • S14 Deleted PR branch from GitLab dev
  • S15 Deleted PR branch from GitLab anvildev
  • S16 Status of linked issue is Lower

Operator

  • V01 At least 24 hours have passed since anvildev.shared was last deployed
  • V02 Ran scripts/export_inspector_findings.py against anvildev, imported results to Google Sheet and posted screenshot of relevant1 findings as a comment on the linked issue.
  • V03 Propagated the upgrade, API, deploy:shared, deploy:gitlab, deploy:runner and backup:gitlab labels to any open promotion PRs or this PR carries none of these labels, or is not included in an open promotion PR
  • V04 Propagated any specific instructions related to those labels, from the description of this PR to that of any open promotion PRs or this PR carries none of those labels, or is not included in an open promotion PR
  • V05 PR is assigned to only the system administrator

1A relevant finding is a high or critical vulnerability in an image
that is used within the security boundary. Images not used within the boundary
are tracked in azul.docker_images under a key starting with _.

System administrator

  • W01 No currently reported vulnerability requires immediate attention
  • W02 PR is assigned to no one

Shorthand for review comments

  • L line is too long
  • W line wrapping is wrong
  • Q bad quotes
  • F other formatting problem

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.92%. Comparing base (c173ed2) to head (25ec9f8).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #8356   +/-   ##
========================================
  Coverage    84.92%   84.92%           
========================================
  Files          170      170           
  Lines        25593    25592    -1     
========================================
  Hits         21734    21734           
+ Misses        3859     3858    -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@coveralls

coveralls commented Sep 30, 2026 •

Copy link
Copy Markdown

Coverage Status

coverage: 84.998% (+0.003%) from 84.995% — upgrades/2026-09-28 into develop

@achave11-ucsc achave11-ucsc linked an issue Sep 30, 2026 that may be closed by this pull request
54 tasks done
@achave11-ucsc achave11-ucsc self-assigned this Sep 30, 2026
@achave11-ucsc achave11-ucsc added reqs [process] PR includes commit requiring ``make requirements`` deploy:gitlab [process] PR requires deploying `gitlab` component deploy:shared [process] PR requires deploying `shared` component deploy:runner [process] PR requires deploying `runner` component backup:gitlab [process] PR requires backing up GitLab instances labels Sep 30, 2026
@achave11-ucsc
achave11-ucsc force-pushed the upgrades/2026-09-28 branch 2 times, most recently from 4821548 to c3dcd2a Compare October 1, 2026 17:14
@achave11-ucsc

achave11-ucsc commented Oct 2, 2026 •

Copy link
Copy Markdown
Member Author

tempdev pipeline succeeded for this PR.

Screenshot 2026-10-02 at 09 29 06

hannes-ucsc
hannes-ucsc previously approved these changes Oct 5, 2026
@hannes-ucsc

Copy link
Copy Markdown
Member

Security design review

  • Security design review completed; this PR does not …
    • … affect authentication; for example:
      • OAuth 2.0 with the application (API or Swagger UI)
      • Authentication of developers with Google Cloud APIs
      • Authentication of developers with AWS APIs
      • Authentication with a GitLab instance in the system
      • Password and 2FA authentication with GitHub
      • API access token authentication with GitHub
      • Authentication with Terra
    • … affect the permissions of internal users like access to
      • Cloud resources on AWS and GCP
      • GitLab repositories, projects and groups, administration
      • an EC2 instance via SSH
      • GitHub issues, pull requests, commits, commit statuses, wikis, repositories, organizations
    • … affect the permissions of external users like access to
      • TDR snapshots
    • … affect permissions of service or bot accounts
      • Cloud resources on AWS and GCP
    • … affect audit logging in the system, like
      • adding, removing or changing a log message that represents an auditable event
      • changing the routing of log messages through the system
    • … affect monitoring of the system
    • … introduce a new software dependency like
      • Python packages on PYPI
      • Command-line utilities
      • Docker images
      • Terraform providers
    • … add an interface that exposes sensitive or confidential data at the security boundary
    • … affect the encryption of data at rest
    • … require persistence of sensitive or confidential data that might require encryption at rest
    • … require unencrypted transmission of data within the security boundary
    • … affect the network security layer; for example by
      • modifying, adding or removing firewall rules
      • modifying, adding or removing security groups
      • changing or adding a port a service, proxy or load balancer listens on
  • Documentation on any unchecked boxes is provided in comments below

@hannes-ucsc hannes-ucsc added the 0 reviews [process] Lead didn't request any changes label Oct 5, 2026
@hannes-ucsc hannes-ucsc removed their assignment Oct 5, 2026
achave11-ucsc and others added 11 commits October 5, 2026 17:45
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
achave11-ucsc and others added 7 commits October 5, 2026 17:45
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@achave11-ucsc achave11-ucsc added the sandbox [process] Resolution is being verified in sandbox deployment label Oct 6, 2026
@achave11-ucsc
achave11-ucsc merged commit bc7fcc1 into develop Oct 7, 2026
10 checks passed
@achave11-ucsc
achave11-ucsc deleted the upgrades/2026-09-28 branch October 7, 2026 16:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

0 reviews [process] Lead didn't request any changes backup:gitlab [process] PR requires backing up GitLab instances deploy:gitlab [process] PR requires deploying `gitlab` component deploy:runner [process] PR requires deploying `runner` component deploy:shared [process] PR requires deploying `shared` component reqs [process] PR includes commit requiring ``make requirements`` sandbox [process] Resolution is being verified in sandbox deployment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upgrade software dependencies 2026-09-28

3 participants