Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 24 additions & 24 deletions requirements/base.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2,75 +2,75 @@
# Multiple entries for the same package (with different version constraints) are grouped together.

aiohttp>=3.13.5,<3.14.0; python_version < '3.10'
aiohttp>=3.14.2; python_version >= '3.10'
aiohttp>=3.14.3; python_version >= '3.10'
apache-libcloud>=3.8.0,<3.9.1; python_version < '3.10'
apache-libcloud>=3.9.1; python_version >= '3.10'
# attrs and charset-normalizer are pulled in transitively by aiohttp/requests.
# Explicit floors on py>=3.10 keep them at the current CVE-patched line.
attrs>=26.1.0; python_version >= '3.10'
certifi>=2026.5.20
cffi>=2.0.0
charset-normalizer>=3.4.7; python_version >= '3.10'
certifi>=2026.7.22
cffi>=2.1.1
charset-normalizer>=3.5.1; python_version >= '3.10'
# cheroot 8.5.2 fails to build with modern setuptools due to setuptools_scm_git_archive dependency
cheroot>=11.1.2
cherrypy>=18.10.0
# We need contextvars for salt-ssh
contextvars
croniter!=0.3.22,>=6.2.2; sys_platform != 'win32'
croniter!=0.3.22,>=6.2.4; sys_platform != 'win32'
# cryptography 48.0.0 drops support for Python 3.9.0 and 3.9.1
# (only >3.9.1 is accepted), but the py3.9 lock files are compiled
# with --python-version=3.9 which includes those releases. Cap at the
# last 46.x release for Python 3.9 so uv pip compile can still resolve.
cryptography>=46.0.7,<48.0.0; python_version < '3.10'
cryptography>=48.0.0; python_version >= '3.10'
cryptography>=50.0.1; python_version >= '3.10'
distro>=1.9.0
frozenlist>=1.8.0; python_version < '3.11'
frozenlist>=1.5.0; python_version >= '3.11'
gitpython>=3.1.50
idna>=3.18
gitpython>=3.1.60
idna>=3.19
immutables>=0.21
importlib-metadata>=8.7.0,<9.0.0; python_version < '3.10'
importlib-metadata>=9.0.0; python_version >= '3.10'
# jaraco.functools 4.5.0 and jaraco.context 6.1.2 drop Python 3.9; keep the
# last 3.9-compatible releases there and let py>=3.10 float forward.
jaraco.functools>=4.4.0,<4.5.0; python_version < '3.10'
jaraco.functools>=4.4.0; python_version >= '3.10'
jaraco.functools>=4.6.0; python_version >= '3.10'
jaraco.context>=6.1.1,<6.1.2; python_version < '3.10'
jaraco.context>=6.1.1; python_version >= '3.10'
jaraco.text>=4.2.0
jaraco.context>=6.1.2; python_version >= '3.10'
jaraco.text>=4.3.0
Jinja2>=3.1.6
jmespath>=1.1.0
looseversion
lxml>=6.1.1; sys_platform == 'win32'
lxml>=6.1.2; sys_platform == 'win32'
MarkupSafe<4.0.0
# more-itertools 11.0.0 drops Python 3.9; keep the last 3.9-compatible release there.
more-itertools>=10.8.0,<11.0.0; python_version < '3.10'
more-itertools>=10.8.0; python_version >= '3.10'
more-itertools>=11.1.0; python_version >= '3.10'
# multidict 6.0.4 fails to source-build under clang 17+ with strict int/pointer
# conversion checks (macOS 15 onedir builds compile from sdist via
# --no-binary=:all:). 6.6+ fixed the C source compatibility.
multidict>=6.6.0
multidict>=6.7.1
# msgpack 1.2.1 drops Python 3.9; keep the last 3.9-compatible release there.
msgpack>=1.1.2,<1.2.1; python_version < '3.10'
msgpack>=1.1.2; python_version >= '3.10'
msgpack>=1.2.1; python_version >= '3.10'
# Packaging 24.1 imports annotations from __future__ which breaks salt ssh
# tests on target hosts with older python versions.
packaging==26.2
packaging==26.3
psutil<6.0.0; python_version <= '3.9'
psutil>=5.0.0; python_version >= '3.10'
psutil>=7.2.2; python_version >= '3.10'
pyasn1>=0.6.4
# pycparser 3.0 drops Python 3.9; keep the last 3.9-compatible release there.
pycparser>=2.23,<3.0; python_version < '3.10'
pycparser>=3.0; python_version >= '3.10'
# pymssql 2.3.12+ dropped win32 (32-bit Windows) wheels; salt 3007.x
# still builds a Windows x86 onedir, so pin to the last release that
# ships cp3X-win32 wheels.
pymssql==2.3.11; sys_platform == 'win32'
pymssql==2.3.13; sys_platform == 'win32'
pymysql>=1.2.0; sys_platform == 'win32'
# pyopenssl 26.3.0 requires cryptography>=49 which drops Python 3.9; keep the
# last 3.9-compatible release there and let py>=3.10 float forward.
pyopenssl>=26.2.0,<26.3.0; python_version < '3.10'
pyopenssl>=26.2.0; python_version >= '3.10'
pyopenssl>=26.4.0; python_version >= '3.10'
python-dateutil>=2.9.0.post0
python-gnupg>=0.5.6
# pythonnet 3.1.0 drops Python 3.9; keep the last 3.9-compatible release there.
Expand All @@ -81,10 +81,10 @@ pywin32>=312; sys_platform == 'win32'
pycryptodomex>=3.23.0
PyYAML>=6.0.3
requests>=2.32.5; python_version < '3.10'
requests<2.32.0 ; python_version >= '3.10' and python_version < '3.11'
requests<2.35.0 ; python_version >= '3.10' and python_version < '3.11'
requests>=2.32.5 ; python_version >= '3.11'
setproctitle>=1.3.7
tornado>=6.5.6
tornado>=6.5.8
# Python 3.9 stays on urllib3 1.26.x because botocore on py3.9 hard
# requires urllib3 < 2 and Salt 3007.x still builds a py3.9 onedir.
# The Python 3.10+ floor carries the urllib3 2.6.3 CVE backports
Expand All @@ -93,13 +93,13 @@ urllib3>=1.26.20,<2.0.0; python_version < '3.10'
urllib3>=2.7.0; python_version >= '3.10'
# virtualenv 21.5.1 drops Python 3.9; keep the last 3.9-compatible release there.
virtualenv>=21.4.2,<21.5.1; python_version < '3.10'
virtualenv>=21.4.2; python_version >= '3.10'
virtualenv>=21.7.5; python_version >= '3.10'
# Transitive of virtualenv; some uv resolver caches pin a stale 3.25
# version that conflicts with the CI floor of 3.29.1 on Python 3.10+.
filelock>=3.29.1; python_version >= '3.10'
filelock>=3.32.4; python_version >= '3.10'
filelock>=3.19.1,<3.29.0; python_version < '3.10'
wmi>=1.5.1; sys_platform == 'win32'
xmltodict>=1.0.4; sys_platform == 'win32'
# zipp 4.1.0 drops Python 3.9; keep the last 3.9-compatible release there.
zipp>=3.23.1,<4.1.0; python_version < '3.10'
zipp>=3.23.1; python_version >= '3.10'
zipp>=4.1.0; python_version >= '3.10'
2 changes: 1 addition & 1 deletion requirements/build.txt
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
twine
build>=1.4.4
build>=1.5.0
10 changes: 5 additions & 5 deletions requirements/constraints.txt
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# IMPORTANT: The versions here must be compatible with the environment where
# uv-pre-commit hooks run. We do not pin setuptools in .pre-commit-config.yaml
# to allow uv to resolve a version that satisfies these constraints.
wheel >= 0.47.0
wheel >= 0.48.0
# Floor at the CVE fix: 78.1.1 patches GHSA-5rjg-fvgr-3xxf
# (PYSEC-2025-49) -- path traversal in setuptools.PackageIndex.download.
# A higher floor (e.g. 80.x) makes the 3.13 onedir build fail with
Expand All @@ -11,21 +11,21 @@ wheel >= 0.47.0
# setuptools; this floor only relaxes what the onedir-bundled pip is
# allowed to use.
setuptools >= 78.1.1
# Cap setuptools-scm < 10 in PEP 517 build envs. 10.1.1 (2026-06-22) split
# Cap setuptools-scm < 11 in PEP 517 build envs. 10.1.1 (2026-06-22) split
# version inference out into the ``vcs-versioning`` package; that path raises
# ``LookupError: setuptools-scm was unable to detect version`` for source
# tarballs that ship a ``PKG-INFO`` but no ``.git`` (e.g. cheroot 11.1.2 on
# PyPI), breaking ``--no-binary=:all:`` onedir builds. PIP_CONSTRAINT
# propagates to PEP 517 build envs since pip 22.1, so capping here keeps
# build envs on the pre-split 9.x series for every source build.
setuptools-scm < 10
setuptools-scm < 11
# Cap Cython < 3.3. Cython 3.3.0 (released 2026-08-22) rejects local
# variable re-annotation inside functions ("hint redeclared",
# "c_addr redeclared"), which breaks the pyzmq 27.1.0 source build
# used by the Python 3.13 onedir (``--no-binary=:all:``). Keeping
# build envs on Cython 3.2.x until pyzmq ships a compatible release.
cython < 3.3
pip == 26.0.1
cython < 3.4
pip == 26.2.1
markdown-it-py < 3.0.0; python_version == "3.9"
# myst-docutils 4.x (the latest supporting Python 3.10) requires
# markdown-it-py ~=3.0; the 5.x line that pairs with markdown-it-py 4.x
Expand Down
4 changes: 2 additions & 2 deletions requirements/pytest.txt
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
mock >= 5.2.0
# PyTest
docker >= 7.1.0; python_version >= '3.8'
docker >= 7.2.0; python_version >= '3.8'
docker < 7.1.0; python_version < '3.8'
pytest >= 8.4.2, <9
pytest >= 9.1.1, < 10
pytest-salt-factories >= 1.0.5
pytest-helpers-namespace >= 2021.12.29
pytest-subtests
Expand Down
28 changes: 14 additions & 14 deletions requirements/static/ci/common.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

# aiohttp is a dependency of etcd3-py
aiohttp>=3.13.5,<3.14.0; python_version < '3.10'
aiohttp>=3.14.1; python_version >= '3.10'
aiohttp>=3.14.3; python_version >= '3.10'
apache-libcloud>=3.8.0,<3.9.1; sys_platform != 'win32' and python_version < '3.10'
apache-libcloud>=3.9.1; sys_platform != 'win32' and python_version >= '3.10'
# bcrypt is an extra requirement for passlib, and we shouldn't use extras, like, passlib[bcrypt]
Expand All @@ -14,22 +14,22 @@ bcrypt
# our urllib3 floor is 2.6.3 so we skip the boto3 cloud module tests on
# 3.9 by not pinning it here. The bare `boto3` package is still
# available transitively for any tool that needs it.
boto3>=1.43.24; python_version >= '3.10'
boto3>=1.43.81; python_version >= '3.10'
boto>=2.49.0
# botocore 1.43.24 requires Python>=3.10. The only versions available on
# 3.9 (botocore<1.43) hard-pin urllib3<1.27, which conflicts with our
# urllib3>=2.6.3 floor. Drop botocore on 3.9 like boto3.
botocore>=1.43.24; python_version >= '3.10'
botocore>=1.43.81; python_version >= '3.10'
cryptography>=46.0.7,<48.0.0; python_version < '3.10'
cryptography>=48.0.0; python_version >= '3.10'
cffi>=2.0.0
cryptography>=50.0.1; python_version >= '3.10'
cffi>=2.1.1
cherrypy>=18.10.0
clustershell
dnspython
etcd3-py==0.1.6
filelock>=3.19.1 ; python_version < '3.10'
filelock>=3.29.1 ; python_version >= '3.10'
gitpython>=3.1.50
filelock>=3.32.4 ; python_version >= '3.10'
gitpython>=3.1.60
google-auth==2.35.0; python_version == '3.9'
jmespath>=1.1.0
jsonschema
Expand All @@ -40,38 +40,38 @@ kazoo; sys_platform != 'win32' and sys_platform != 'darwin'
keyring==25.7.0
pyasn1-modules==0.4.0; python_version == '3.9'
kubernetes>=35.0.0,<36.0.0; python_version < '3.10'
kubernetes>=36.0.2; python_version >= '3.10'
kubernetes>=36.0.3; python_version >= '3.10'
libnacl>=2.1.0; sys_platform != 'win32' and sys_platform != 'darwin'
# markdown-it-py constraint for py3.9: myst-docutils (docs requirement) needs <3.0.0,
# but netmiko (from napalm, only in py3.9) pulls in rich which wants 3.0.0+
markdown-it-py<3.0.0; python_version == '3.9'
moto>=5.1.8,<5.2.0; python_version < '3.10'
moto>=5.2.2; python_version >= '3.10'
moto>=5.2.3; python_version >= '3.10'
# Napalm pulls in pyeapi which does not work on Py3.10
napalm; sys_platform != 'win32' and python_version < '3.10'
paramiko>=5.0.0; sys_platform != 'win32' and sys_platform != 'darwin'
passlib>=1.7.4
pycryptodomex
pynacl>=1.5.0
pynacl>=1.6.2
pyinotify>=0.9.6; sys_platform != 'win32' and sys_platform != 'darwin' and platform_system != "openbsd"
python-etcd>=0.4.5
pyvmomi
rfc3987
sqlparse>=0.5.5
sqlparse>=0.6.0
strict_rfc3339>=0.7
textfsm
toml
# vcert 0.18.x adds hard pins on cryptography, pynacl, and six that
# conflict with every other CI requirement; stay on 0.9.x.
vcert~=0.9.0; sys_platform != 'win32'
vcert~=0.9.1; sys_platform != 'win32'
virtualenv>=21.4.2,<21.5.1; python_version < '3.10'
virtualenv>=21.4.2; python_version >= '3.10'
virtualenv>=21.7.5; python_version >= '3.10'
watchdog>=6.0.0
websocket-client>=1.9.0
# werkzeug is a dependency of moto
werkzeug>=3.1.8
xmldiff>=2.7.0,<3.0; python_version < '3.10'
xmldiff>=2.7.0; python_version >= '3.10'
xmldiff>=3.0; python_version >= '3.10'
# Available template libraries that can be used
genshi>=0.7.11
cheetah3>=3.2.6.post1
Expand Down
6 changes: 3 additions & 3 deletions requirements/static/ci/darwin.txt
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
pygit2>=1.13.1,<1.18.0; python_version < '3.11'
pygit2>=1.19.2; python_version >= '3.11'
pygit2>=1.20.0; python_version >= '3.11'
yamllint
mercurial>=7.2.2
mercurial>=7.2.4
hglib
# Pin versions to match 3007.x
apache-libcloud>=3.8.0,<3.9.1; python_version < '3.10'
apache-libcloud>=3.9.1; python_version >= '3.10'
gitpython>=3.1.50
gitpython>=3.1.60
2 changes: 1 addition & 1 deletion requirements/static/ci/freebsd.txt
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# FreeBSD static CI requirements

yamllint
mercurial>=7.2.2
mercurial>=7.2.4
hglib
4 changes: 2 additions & 2 deletions requirements/static/ci/lint.txt
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
# Lint requirements

docker >= 7.1.0; python_version >= '3.8'
docker >= 7.2.0; python_version >= '3.8'
docker < 7.1.0; python_version < '3.8'
# pylint 4 introduces new default-on E0606/E0601/E0602 checks that the
# Salt 3007.x codebase has not been audited for; the lint job logs are
# full of pre-existing possibly-used-before-assignment warnings now
# turning into errors across salt/, tools/, and tests/. Stay on the
# 3.1.x line for 3007.x. (pylint 4 also requires Python>=3.10, so the
# 3.x line is the only choice on the py3.9 onedir target anyway.)
pylint~=3.1.0
pylint~=3.3.9
SaltPyLint>=2024.2.5
toml
10 changes: 5 additions & 5 deletions requirements/static/ci/linux.txt
Original file line number Diff line number Diff line change
@@ -1,20 +1,20 @@
# Linux static CI requirements
pyiface
pygit2>=1.13.1,<1.18.0; python_version < '3.11'
pygit2>=1.19.2; python_version >= '3.11'
pygit2>=1.20.0; python_version >= '3.11'
pymysql>=1.2.0
# ansible release lines support different Python versions:
# ansible-core / ansible 10.x — Python 3.10+
# ansible 12.x — Python 3.11+
# ansible 14.x — Python 3.12+
ansible>=10.7.0,<11.0.0; python_version >= '3.10' and python_version < '3.11'
ansible>=12.3.0,<13.0.0; python_version >= '3.11' and python_version < '3.12'
ansible>=14.0.0; python_version >= '3.12'
twilio>=9.10.9
ansible>=14.3.1; python_version >= '3.12'
twilio>=9.11.0
python-telegram-bot>=20.3,<22.0; python_version < '3.10'
python-telegram-bot>=22.7; python_version >= '3.10'
python-telegram-bot>=22.8; python_version >= '3.10'
yamllint
mercurial>=7.2.2
mercurial>=7.2.4
hglib
redis-py-cluster
python-consul
Expand Down
2 changes: 1 addition & 1 deletion requirements/static/ci/py3.10/changelog.lock
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ markupsafe==2.1.5
# via
# -c requirements/static/ci/py3.10/linux.lock
# jinja2
packaging==26.2
packaging==26.3
# via
# -c requirements/static/ci/py3.10/linux.lock
# -r requirements/static/ci/changelog.txt
Expand Down
Loading
Loading