Skip to content

Conversation

@janbrasna
Copy link
Contributor

I've been running this locally together with #522 (4.2.x) for some time and don't see anything obviously wrong — reckon both bumps would add some peace of mind given their long support cycle.

Bugfixes stopped at 3.11.9 (2024-04-02) and it's only security updates since so should be uneventful.

BTW the image is slightly smaller in size, and has less vulns:

Screenshot 2025-05-19 at 19 44 23

Copy link
Contributor Author

@janbrasna janbrasna left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Or even not pinning the patch version at all:

(The particular version was added in #410 and never updated since — perhaps an alternative would be have dependabot remind image updates with PRs? But even kitsune switched away to using whatever's latest: mozilla/kitsune@7066323)

akatsoulas and others added 2 commits May 28, 2025 11:06
Co-authored-by: Jan Brasna <1784648+janbrasna@users.noreply.github.com>
Co-authored-by: Jan Brasna <1784648+janbrasna@users.noreply.github.com>
@akatsoulas akatsoulas merged commit 99c4df9 into mozilla:main May 28, 2025
2 checks passed
@janbrasna janbrasna deleted the python-bump branch May 28, 2025 10:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants