chore(deps): bump pytest from 7.0.1 to 9.0.3 in /scripts#4866
chore(deps): bump pytest from 7.0.1 to 9.0.3 in /scripts#4866dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [pytest](https://github.com/pytest-dev/pytest) from 7.0.1 to 9.0.3. - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@7.0.1...9.0.3) --- updated-dependencies: - dependency-name: pytest dependency-version: 9.0.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit e457133. Configure here.
| deepdiff==5.8.1 | ||
| PyGithub==1.57 | ||
| pytest==7.0.1 | ||
| pytest==9.0.3 |
There was a problem hiding this comment.
Pytest 9.0.3 incompatible with CI's Python 3.7
High Severity
pytest==9.0.3 requires Python 3.10+, but the consistency-check.yaml CI workflow installs this requirements file under python-version: 3.7. This will cause pip install to fail (or install an incompatible package), breaking the RBAC consistency check CI job entirely.
Reviewed by Cursor Bugbot for commit e457133. Configure here.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e457133936
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| deepdiff==5.8.1 | ||
| PyGithub==1.57 | ||
| pytest==7.0.1 | ||
| pytest==9.0.3 |
There was a problem hiding this comment.
Keep pytest compatible with the workflow Python version
This bump breaks the existing consistency-check workflow because it sets up Python 3.7 (.github/workflows/consistency-check.yaml, lines 143-149) and then installs scripts/requirements.txt; pytest==9.0.3 is not installable on Python 3.7, so the dependency install step fails before scripts/rbac_test.py can run. Please either keep pytest on a 3.7-compatible major version or upgrade the workflow’s Python version in the same change.
Useful? React with 👍 / 👎.


Bumps pytest from 7.0.1 to 9.0.3.
Release notes
Sourced from pytest's releases.
... (truncated)
Commits
a7d58d7Prepare release version 9.0.3089d981Merge pull request #14366 from bluetech/revert-14193-backport8127eafRevert "Fix: assertrepr_compare respects dict insertion order (#14050) (#14193)"99a7e60Merge pull request #14363 from pytest-dev/patchback/backports/9.0.x/95d8423bd...ddee02aMerge pull request #14343 from bluetech/cve-2025-71176-simple74eac69doc: Update training info (#14298) (#14301)f92dee7Merge pull request #14267 from pytest-dev/patchback/backports/9.0.x/d6fa26c62...7ee58acMerge pull request #12378 from Pierre-Sassoulas/fix-implicit-str-concat-and-d...37da870Merge pull request #14259 from mitre88/patch-4 (#14268)c34bfa3Add explanation for string context diffs (#14257) (#14266)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.