Skip to content

Bump the taskcluster-pip group across 1 directory with 2 updates#11439

Merged
oskirby merged 1 commit into
mainfrom
dependabot/pip/taskcluster/taskcluster-pip-10599f28a8
Jul 21, 2026
Merged

Bump the taskcluster-pip group across 1 directory with 2 updates#11439
oskirby merged 1 commit into
mainfrom
dependabot/pip/taskcluster/taskcluster-pip-10599f28a8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 16, 2026

Copy link
Copy Markdown
Contributor

Bumps the taskcluster-pip group with 2 updates in the /taskcluster directory: mozilla-taskgraph and taskcluster.

Updates mozilla-taskgraph from 4.2.0 to 4.4.0

Release notes

Sourced from mozilla-taskgraph's releases.

4.4.0

What's Changed

Full Changelog: mozilla-releng/mozilla-taskgraph@4.3.0...4.4.0

4.3.0

What's Changed

Full Changelog: mozilla-releng/mozilla-taskgraph@4.2.0...4.3.0

Changelog

Sourced from mozilla-taskgraph's changelog.

4.4.0 (2026-07-07)

Added

  • include partial_versions in get_release_config (#234)

4.3.0 (2026-07-02)

Added

  • copy_attributes_from_dependent_job utility (#222)
Commits
  • 2985a3b Merge pull request #235 from bhearsum/chore-version-bump-4.4.0
  • acf9643 chore: version bump 4.4.0
  • 5f1f497 Merge pull request #234 from kryoseu/feat-release-config-partials
  • 8ca1262 refactor: always inject partial_versions when PARTIAL_UPDATES is set
  • 774a0e5 feat: include partial_versions in get_release_config
  • 68eca01 Merge pull request #232 from bhearsum/chore-version-bump-4.3.0
  • 5cc20af chore: version bump 4.3.0
  • 3b8bf8a chore(deps): lock file maintenance (pep621) (#231)
  • 6530ec1 chore(deps): update actions/checkout action to v7 (#229)
  • d25cfec chore(deps): update mozillareleases/taskgraph docker tag to v24 (#227)
  • Additional commits viewable in compare view

Updates taskcluster from 100.5.0 to 101.1.0

Release notes

Sourced from taskcluster's releases.

v101.1.0

DEPLOYERS

▶ [patch] Remove support for google analytics (GA_TRACKING_ID doesn't do anything anymore) in the UI as it's been unsupported and untested for years.

WORKER-DEPLOYERS

▶ [patch] #8664 When a worker-manager checkWorker call times out, the scanner now aborts the in-flight provider API call and logs a warning instead of reporting an error, since the worker is re-checked on the next loop. Other checkWorker failures are still reported as errors.

▶ [patch] The Google provider in worker-manager now logs a single transient GCP compute 5xx at notice rather than warning level.

USERS

▶ [patch] bug 2053178 Fix a way for PRs from forks to bypass the public_restricted policy by declaring version: 0 in their own taskcluster.yml

▶ [patch] bug 2053380 Fix login CSRF in the github login flow by validating the oauth state parameter

▶ [patch] #8171 Task creation in the UI now calls the Queue API directly instead of routing through GraphQL, fixing 413 errors when creating tasks with large payloads (up to the Queue API's 10MB limit).

DEVELOPERS

▶ [minor] Switch the UI build system to vite. Switch tests to vitest

OTHER

▶ Additional change not described here: #4007.

Automated Package Updates

  • build(deps): bump body-parser from 1.20.3 to 2.3.0 (2cde87843e)

v101.0.0

ADMINS

... (truncated)

Changelog

Sourced from taskcluster's changelog.

v101.1.0

DEPLOYERS

▶ [patch] Remove support for google analytics (GA_TRACKING_ID doesn't do anything anymore) in the UI as it's been unsupported and untested for years.

WORKER-DEPLOYERS

▶ [patch] #8664 When a worker-manager checkWorker call times out, the scanner now aborts the in-flight provider API call and logs a warning instead of reporting an error, since the worker is re-checked on the next loop. Other checkWorker failures are still reported as errors.

▶ [patch] The Google provider in worker-manager now logs a single transient GCP compute 5xx at notice rather than warning level.

USERS

▶ [patch] bug 2053178 Fix a way for PRs from forks to bypass the public_restricted policy by declaring version: 0 in their own taskcluster.yml

▶ [patch] bug 2053380 Fix login CSRF in the github login flow by validating the oauth state parameter

▶ [patch] #8171 Task creation in the UI now calls the Queue API directly instead of routing through GraphQL, fixing 413 errors when creating tasks with large payloads (up to the Queue API's 10MB limit).

DEVELOPERS

▶ [minor] Switch the UI build system to vite. Switch tests to vitest

OTHER

▶ Additional change not described here: #4007.

Automated Package Updates

  • build(deps): bump body-parser from 1.20.3 to 2.3.0 (2cde87843e)

v101.0.0

... (truncated)

Commits
  • caf47f0 v101.1.0
  • 8a146bd Merge pull request #8857 from Eijebong/react-17
  • 2ba691a Merge pull request #8856 from Eijebong/kill-ga-with-fire
  • 0c27261 Merge pull request #8260 from nitishagar/fix/8171-graphql-payload-limit
  • 1da501f Update react from 16 to 17.0.2
  • d4e0787 Remove google analytics support
  • 8729279 Switch to vitest
  • a0c2084 Merge pull request #8854 from taskcluster/dependabot/lower-dependabot-task-pr...
  • 2cff86f Merge pull request #8853 from Eijebong/cleaning-up-unused-stuff
  • 257ef1a Merge pull request #8852 from Eijebong/proptypes-typo
  • Additional commits viewable in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
taskcluster [>= 57.1.a, < 57.2]

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 16, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 16, 2026 05:24
@dependabot
dependabot Bot requested review from hneiva and removed request for a team July 16, 2026 05:24
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 16, 2026
@firefoxci-taskcluster

Copy link
Copy Markdown
Uh oh! Looks like an error!

Client ID static/taskcluster/github does not have sufficient scopes and is missing the following scopes:

{
  "AnyOf": [
    "queue:rerun-task:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg/JOpnqPQhQXarpGhKsnpE6Q",
    "queue:rerun-task-in-project:none",
    {
      "AllOf": [
        "queue:rerun-task",
        "assume:scheduler-id:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg"
      ]
    }
  ]
}

This request requires the client to satisfy the following scope expression:

{
  "AnyOf": [
    "queue:rerun-task:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg/JOpnqPQhQXarpGhKsnpE6Q",
    "queue:rerun-task-in-project:none",
    {
      "AllOf": [
        "queue:rerun-task",
        "assume:scheduler-id:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg"
      ]
    }
  ]
}

  • method: rerunTask
  • errorCode: InsufficientScopes
  • statusCode: 403
  • time: 2026-07-20T16:53:52.668Z

@firefoxci-taskcluster

Copy link
Copy Markdown
Uh oh! Looks like an error!

Client ID static/taskcluster/github does not have sufficient scopes and is missing the following scopes:

{
  "AnyOf": [
    "queue:rerun-task:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg/O4TtjotdQA2kiOZy4ULiRQ",
    "queue:rerun-task-in-project:none",
    {
      "AllOf": [
        "queue:rerun-task",
        "assume:scheduler-id:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg"
      ]
    }
  ]
}

This request requires the client to satisfy the following scope expression:

{
  "AnyOf": [
    "queue:rerun-task:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg/O4TtjotdQA2kiOZy4ULiRQ",
    "queue:rerun-task-in-project:none",
    {
      "AllOf": [
        "queue:rerun-task",
        "assume:scheduler-id:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg"
      ]
    }
  ]
}

  • method: rerunTask
  • errorCode: InsufficientScopes
  • statusCode: 403
  • time: 2026-07-20T16:53:57.804Z

@firefoxci-taskcluster

Copy link
Copy Markdown
Uh oh! Looks like an error!

Client ID static/taskcluster/github does not have sufficient scopes and is missing the following scopes:

{
  "AnyOf": [
    "queue:rerun-task:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg/O4TtjotdQA2kiOZy4ULiRQ",
    "queue:rerun-task-in-project:none",
    {
      "AllOf": [
        "queue:rerun-task",
        "assume:scheduler-id:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg"
      ]
    }
  ]
}

This request requires the client to satisfy the following scope expression:

{
  "AnyOf": [
    "queue:rerun-task:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg/O4TtjotdQA2kiOZy4ULiRQ",
    "queue:rerun-task-in-project:none",
    {
      "AllOf": [
        "queue:rerun-task",
        "assume:scheduler-id:mozillavpn-level-1/FtV_Vw5zTl6-3gIPQaFidg"
      ]
    }
  ]
}

  • method: rerunTask
  • errorCode: InsufficientScopes
  • statusCode: 403
  • time: 2026-07-20T16:54:32.367Z

@hneiva

hneiva commented Jul 20, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps the taskcluster-pip group with 2 updates in the /taskcluster directory: [mozilla-taskgraph](https://github.com/mozilla-releng/mozilla-taskgraph) and [taskcluster](https://github.com/taskcluster/taskcluster).


Updates `mozilla-taskgraph` from 4.2.0 to 4.4.0
- [Release notes](https://github.com/mozilla-releng/mozilla-taskgraph/releases)
- [Changelog](https://github.com/mozilla-releng/mozilla-taskgraph/blob/main/CHANGELOG.md)
- [Commits](mozilla-releng/mozilla-taskgraph@4.2.0...4.4.0)

Updates `taskcluster` from 100.5.0 to 101.1.0
- [Release notes](https://github.com/taskcluster/taskcluster/releases)
- [Changelog](https://github.com/taskcluster/taskcluster/blob/main/CHANGELOG.md)
- [Commits](taskcluster/taskcluster@v100.5.0...v101.1.0)

---
updated-dependencies:
- dependency-name: mozilla-taskgraph
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: taskcluster-pip
- dependency-name: taskcluster
  dependency-version: 101.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: taskcluster-pip
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the taskcluster-pip group in /taskcluster with 2 updates Bump the taskcluster-pip group across 1 directory with 2 updates Jul 20, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/taskcluster/taskcluster-pip-10599f28a8 branch from 8af9118 to f805dde Compare July 20, 2026 17:02
@hneiva

hneiva commented Jul 20, 2026

Copy link
Copy Markdown
Collaborator

@oskirby some CI jobs failing on this. Is it ok to merge?

@oskirby

oskirby commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

@hneiva Yes, we are free to merge. These functional tests are known to be a bit flaky

@oskirby
oskirby merged commit f4570f8 into main Jul 21, 2026
194 of 197 checks passed
@oskirby
oskirby deleted the dependabot/pip/taskcluster/taskcluster-pip-10599f28a8 branch July 21, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants