Skip to content

chore(deps): bump strawberry-graphql from 0.323.2 to 0.327.2 - #2309

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/strawberry-graphql-0.327.2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/strawberry-graphql-0.327.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps strawberry-graphql from 0.323.2 to 0.327.2.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 7, 2026
@claude

claude Bot commented Sep 7, 2026

Copy link
Copy Markdown

Review

This is a routine Dependabot version bump (strawberry-graphql 0.323.2 → 0.327.2, semver-minor), scoped to a single line in requirements/base.txt. The change itself is clean:

  • Single, minimal diff — no unrelated changes.
  • The existing inline comment (# code-first GraphQL; replaced graphene-django (schema parity pinned by config/graphql/schema.graphql)) is preserved correctly.
  • No other file pins strawberry-graphql separately, so there's nothing else to keep in sync.
  • Not flagged as a security update by Dependabot, so no CVE urgency here.

Risk worth flagging before merging

Per this repo's architecture notes, strawberry-graphql isn't a thin dependency here — config/graphql/core/ contains a hand-built "graphene-parity" port (relay global IDs, connection factories, filter-arg mapping, permission resolvers), and config/graphql/schema.graphql is a golden SDL contract: opencontractserver/tests/test_schema_parity.py fails on any shape drift. A 4-minor-version jump (0.323 → 0.327) is exactly the kind of change that could shift SDL output, directive handling, generic scalar behavior, or extension APIs (AddValidationRules is used directly in schema.py) in subtle ways that a generic dependency-update CI run might not catch if it doesn't specifically exercise the GraphQL test suite.

Before merging, I'd suggest explicitly confirming (rather than relying on default CI green):

  1. test_schema_parity.py still passes — if it doesn't, this warrants a deliberate SDL regen (per that test's docstring), not just a rubber-stamp merge.
  2. The broader GraphQL test suite (queries/mutations/permissions) passes, since permission-annotation resolution (myPermissions, isPublished, etc.) and the JWT auth backends layer on top of strawberry's request context handling.
  3. Nothing in strawberry 0.324–0.327 changelogs affects AddValidationRules/extensions usage in config/graphql/schema.py or the relay connection helpers pinned alongside graphql-relay==3.2.0.

No test coverage changes are expected/needed for a pure dependency bump — that's fine as-is. Overall: safe to merge once the GraphQL-specific test suite (not just default CI) is verified, given how deeply this dependency is embedded rather than used as a black box.

Bumps [strawberry-graphql](https://github.com/sponsors/strawberry-graphql) from 0.323.2 to 0.327.2.
- [Commits](https://github.com/sponsors/strawberry-graphql/commits)

---
updated-dependencies:
- dependency-name: strawberry-graphql
  dependency-version: 0.327.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/strawberry-graphql-0.327.2 branch from aa3902d to 1645254 Compare September 8, 2026 05:30
@claude

claude Bot commented Sep 8, 2026

Copy link
Copy Markdown

Review

This is a routine dependabot dependency bump (strawberry-graphql 0.323.2 → 0.327.2), a single line in requirements/base.txt with no other changes.

Consistency check: I compared this against the two prior merged strawberry-graphql bump PRs (#2198, #2179) — both were also single-line version bumps with no changelog fragment or other changes, so this PR follows established precedent for this repo.

Main risk area: per CLAUDE.md, config/graphql/schema.graphql is a golden SDL contract, and opencontractserver/tests/test_schema_parity.py fails on any shape drift. A minor-version bump of the underlying GraphQL library (4 minor versions: 0.324–0.327) could in principle change SDL rendering (e.g. directive ordering, default-value formatting, deprecation reason formatting) even without any application code changes. I couldn't run the Docker-based backend test suite in this environment to confirm, so:

  • Please confirm CI is green, specifically test_schema_parity.py and the broader GraphQL test suite, before merging.
  • If test_schema_parity.py fails, that's expected/actionable — regenerate schema.graphql per that test's docstring rather than pinning back the version, unless the schema diff reveals an actual behavioral change worth scrutinizing.

No code quality, security, or test coverage concerns beyond the above — there's no first-party code here to review, just a version pin.

@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #2312.

@dependabot dependabot Bot closed this Sep 8, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/strawberry-graphql-0.327.2 branch September 8, 2026 16:33
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 8, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants