← All tasks
pythonpython-telegram-bot/python-telegram-bot #5195Not a task: already works

Don't upgrade packages less than 7 days old

envgap__python-telegram-bot__python-telegram-bot-5195

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
1a83d47fb32e0d5892ef208309e4e03721539f39
Manifest
pyproject.toml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

python-telegram-bot/python-telegram-bot #5195 · read the original issue
There have been many supply chain attacks recently involving compromised dependencies. E.g. the recent axios attack ([this video](https://youtu.be/yiLIZLPNEm8?si=ie4XgFDVqfFhLucw) does a nice job explaining that situation).

In general, good security practices for dependencies state that you shouldn't update your dependencies instantly - having a buffer period of something like 7 days allows the community to audit packages for malicious behaviour. 

### Proposal

Set the [`minimumReleaseAge` config option in Renovate.](https://docs.renovatebot.com/key-concepts/minimum-release-age/#minimum-release-age). Additionally, they also recommend setting that in your package manager for transitive dependencies and for lockfiles. `pip` does not have support for such a thing, but `uv` does via the [`exclude-newer` flag ](https://docs.astral.sh/uv/reference/settings/#exclude-newer). 

It's unlikely that our users would be affected by security bugs mostly because our release cycle is rather long. This change would benefit anyone developing for the library, because we would be pulling in the latest changes from master.

What do you think, is this a reasonable thing to do or is it rather aggressive? 
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]