Skip to content

build(deps): bump the docker-compose-images group across 1 directory with 5 updates - #19949

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker_compose/docker-compose-images-99d63541f1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker_compose/docker-compose-images-99d63541f1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the docker-compose-images group with 5 updates in the / directory:

Package From To
elasticsearch 9.5.1 9.5.2
motoserver/moto 5.2.2 5.2.3
rabbitmq 4.3.4-alpine 4.3.5-alpine
azure-storage/azurite 3.36.0 3.37.0
google/cloud-sdk 580.0.0-emulators 582.0.0-emulators

Updates elasticsearch from 9.5.1 to 9.5.2

Updates motoserver/moto from 5.2.2 to 5.2.3

Updates rabbitmq from 4.3.4-alpine to 4.3.5-alpine

Updates azure-storage/azurite from 3.36.0 to 3.37.0

Updates google/cloud-sdk from 580.0.0-emulators to 582.0.0-emulators

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…with 5 updates

Bumps the docker-compose-images group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| elasticsearch | `9.5.1` | `9.5.2` |
| motoserver/moto | `5.2.2` | `5.2.3` |
| rabbitmq | `4.3.4-alpine` | `4.3.5-alpine` |
| azure-storage/azurite | `3.36.0` | `3.37.0` |
| google/cloud-sdk | `580.0.0-emulators` | `582.0.0-emulators` |



Updates `elasticsearch` from 9.5.1 to 9.5.2

Updates `motoserver/moto` from 5.2.2 to 5.2.3

Updates `rabbitmq` from 4.3.4-alpine to 4.3.5-alpine

Updates `azure-storage/azurite` from 3.36.0 to 3.37.0

Updates `google/cloud-sdk` from 580.0.0-emulators to 582.0.0-emulators

---
updated-dependencies:
- dependency-name: elasticsearch
  dependency-version: 9.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker-compose-images
- dependency-name: motoserver/moto
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker-compose-images
- dependency-name: rabbitmq
  dependency-version: 4.3.5-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker-compose-images
- dependency-name: azure-storage/azurite
  dependency-version: 3.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker-compose-images
- dependency-name: google/cloud-sdk
  dependency-version: 582.0.0-emulators
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: docker-compose-images
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker_compose Pull requests that update docker_compose code labels Aug 31, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 31, 2026 03:18
@dependabot dependabot Bot added the docker_compose Pull requests that update docker_compose code label Aug 31, 2026
@dependabot
dependabot Bot requested a review from Kyle-Verhoog August 31, 2026 03:18
@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Pipelines  Tests

⚠️ Warnings

❌ Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 7 Pipeline jobs failed

DataDog/apm-reliability/dd-trace-py | llmobs/openai 23/25 — 🔄 Retry may pass, looks flaky

View more details · View in GitLab

Changelog | Validate changelog

View more details · View in GitHub Actions

Release note not found during changelog validation. Use 'reno new <slug>' to add a new note or label 'changelog/no-changelog' to skip.

DataDog/apm-reliability/dd-trace-py | build linux serverless: [amd64, cp315-cp315, v113741238-d2b8243-manylinux2014_x86_64, 1]

View more details · View in GitLab

View all 7 failed jobs.

ℹ️ Info

No other issues found (see more)

🧪 All tests passed
❄️ No new flaky tests detected

🔄 Datadog retried 13 tests - 6 passed on retry View in Datadog

🚧 25 tests that failed were ignored due to quarantine View in Datadog

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: a16f68a | Docs | View more details | Give us feedback!

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

Codeowners resolved as

Resolved from the full PR diff against main using the target branch CODEOWNERS file.
CODEOWNERS team requests not listed below are not required by the current file set.

docker-compose.base.yml                                                 @DataDog/python-guild

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

Dependency direction analysis

⚠️ Existing dependency direction violations

There are 240 dependency direction violations that already exist on the base branch and have not been changed by this PR.

Show existing violations (showing 5 of 240 highest severity)
ddtrace.internal.tracemethods -×-> ddtrace.trace  (internal-core -> product:tracing, score=135)
ddtrace.llmobs._integrations.base -×-> ddtrace.trace  (product:llmobs -> product:tracing, score=133)
ddtrace.internal.opentelemetry.context -×-> ddtrace.trace  (product:opentelemetry -> product:tracing, score=133)
ddtrace.debugging._exception.replay -×-> ddtrace.trace  (product:debugging -> product:tracing, score=133)
ddtrace.llmobs._integrations.llama_index -×-> ddtrace.trace  (product:llmobs -> product:tracing, score=133)

To see all violations, download the layers-base.json and layers-pr.json artifacts from this CI job and run:

uv run --script scripts/import-analysis/layers.py compare layers-base.json layers-pr.json

@cit-pr-commenter-54b7da

Copy link
Copy Markdown

Circular import analysis

⚠️ Existing circular imports

There are 3 circular imports that already exist on the base branch and have not been changed by this PR.

ddtrace.errortracking._handled_exceptions.bytecode_injector -> ddtrace.errortracking._handled_exceptions.callbacks -> ddtrace.errortracking._handled_exceptions.collector -> ddtrace.errortracking._handled_exceptions.bytecode_reporting -> ddtrace.errortracking._handled_exceptions.bytecode_injector
ddtrace.llmobs -> ddtrace.llmobs._evaluators -> ddtrace.llmobs._evaluators.format -> ddtrace.llmobs._experiment -> ddtrace.llmobs
ddtrace.appsec._asm_request_context -> ddtrace.appsec._iast._iast_request_context_base -> ddtrace.appsec._iast._iast_env -> ddtrace.appsec._iast.reporter -> ddtrace.appsec._exploit_prevention.stack_traces -> ddtrace.appsec._asm_request_context

@pr-commenter

pr-commenter Bot commented Aug 31, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-08-31 03:47:05

Comparing candidate commit a16f68a in PR branch dependabot/docker_compose/docker-compose-images-99d63541f1 with baseline commit f08f042 in branch main.

📊 Benchmarking dashboard

Found 0 performance improvements and 7 performance regressions! Performance is the same for 576 metrics, 10 unstable metrics, 2 known flaky benchmarks, 16 flaky benchmarks without significant changes.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

scenario:httppropagationinject-ids_only

  • 🟥 execution_time [+2.424µs; +2.616µs] or [+14.355%; +15.494%]

scenario:iastaspects-modulo_noaspect

  • 🟥 execution_time [+45.616µs; +51.404µs] or [+13.758%; +15.504%]

scenario:iastaspects-strip_aspect

  • 🟥 execution_time [+69.457µs; +76.581µs] or [+24.227%; +26.711%]

scenario:iastaspectsospath-ospathbasename_aspect

  • 🟥 execution_time [+123.308µs; +129.976µs] or [+30.064%; +31.689%]

scenario:iastaspectssplit-rsplit_aspect

  • 🟥 execution_time [+22.828µs; +25.694µs] or [+16.238%; +18.276%]

scenario:telemetryaddmetric-1-count-metric-1-times

  • 🟥 execution_time [+648.804ns; +692.465ns] or [+23.971%; +25.584%]

scenario:tracer-small

  • 🟥 execution_time [+27.387µs; +29.912µs] or [+8.101%; +8.848%]

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:coreapiscenario-context_with_data_listeners

  • unstable execution_time [-757.760ns; +708.397ns] or [-6.924%; +6.473%]

scenario:coreapiscenario-core_dispatch_1_listener

  • unstable execution_time [-36.399ns; +29.211ns] or [-5.933%; +4.761%]

scenario:coreapiscenario-core_dispatch_50_listeners

  • unstable execution_time [-1430.719ns; +1842.956ns] or [-8.513%; +10.965%]

scenario:coreapiscenario-core_dispatch_exception_listeners

  • unstable execution_time [-957.554ns; +1554.863ns] or [-7.411%; +12.035%]

scenario:coreapiscenario-core_dispatch_listeners

  • unstable execution_time [-273.412ns; +375.018ns] or [-7.521%; +10.316%]

scenario:coreapiscenario-core_dispatch_no_args_listeners

  • unstable execution_time [-192.991ns; +313.363ns] or [-6.713%; +10.900%]

scenario:coreapiscenario-core_dispatch_with_results_1_listener

  • unstable execution_time [-50.006ns; +104.666ns] or [-4.275%; +8.947%]

scenario:coreapiscenario-core_dispatch_with_results_50_listeners

  • unstable execution_time [-4146.508ns; +3803.672ns] or [-10.106%; +9.270%]

scenario:coreapiscenario-core_dispatch_with_results_listeners

  • unstable execution_time [-776.806ns; +777.792ns] or [-9.554%; +9.566%]

scenario:packagesupdateimporteddependencies-import_many_stdlib_cached

  • unstable execution_time [-58860.813ns; +59563.314ns] or [-9.403%; +9.515%]

Known flaky benchmarks

These benchmarks are marked as flaky and will not trigger a failure. Modify FLAKY_BENCHMARKS_REGEX to control which benchmarks are marked as flaky.

scenario:iastaspects-casefold_noaspect

  • 🟥 execution_time [+71.723µs; +78.190µs] or [+29.711%; +32.390%]

scenario:iastaspects-translate_noaspect

  • 🟥 execution_time [+26.161µs; +31.525µs] or [+7.340%; +8.845%]

Known flaky benchmarks without significant changes:

  • scenario:errortrackingflasksqli-baseline
  • scenario:flasksimple-iast-get
  • scenario:iastaspects-casefold_aspect
  • scenario:iastaspects-index_aspect
  • scenario:iastaspects-ljust_noaspect
  • scenario:iastaspects-lower_aspect
  • scenario:iastaspects-replace_aspect
  • scenario:iastaspects-swapcase_aspect
  • scenario:iastaspects-title_noaspect
  • scenario:iastaspects-translate_aspect
  • scenario:iastaspects-upper_noaspect
  • scenario:packagespackageforrootmodulemapping-cache_off
  • scenario:packagespackageforrootmodulemapping-cache_on
  • scenario:sethttpmeta-all-enabled
  • scenario:span-start
  • scenario:telemetryaddmetric-record-100-metrics

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #20099.

@dependabot
dependabot Bot deleted the dependabot/docker_compose/docker-compose-images-99d63541f1 branch September 7, 2026 03:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker_compose Pull requests that update docker_compose code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant