Maintenance¶
How to upgrade¶
Routine dependency updates arrive as Renovate pull requests (renovate.json): non-major Python and JavaScript updates and Docker digest updates are grouped, lock file maintenance runs weekly, and the rev pins in .pre-commit-config.yaml are bumped too (the local uv run hooks take their tool versions from uv.lock). Version ceilings (e.g. PostgreSQL 17, Python 3.13) are enforced via packageRules. These are the places that hold version pins, and what to do when Renovate does not cover a change:
- The Python package dependencies (normal dependencies and dev dependencies)
- Check outdated Python packages:
uv run cli show-outdated(check Python section in output) uv lock --upgradewill update packages according to their version range inpyproject.toml- Other upgrades (e.g. major versions) must be upgraded by modifying the version range in
pyproject.tomlbefore callinguv lock --upgrade - The
adit-radis-shareddependency is pinned to a Git tag in[tool.uv.sources]ofpyproject.toml; bump the tag manually and runuv lock - JavaScript dependencies
- Check outdated JavaScript packages:
uv run cli show-outdated(check NPM section in output) npm updatewill update packages according to their version range inpackage.json- Other upgrades (e.g. major versions) must be upgraded by modifying the version range in
package.jsonbefore callingnpm update - After an upgrade run
uv run cli copy-statics: it copies thedcmjs,dicomweb-client, anddicom-web-anonymizerbuilds fromnode_modulesintoadit/upload/static/vendor(package.jsondeclares onlydicom-web-anonymizer;dcmjsis pulled in as its dependency, and thedicomweb-clientglob only matches when that package is installed). Check that the vendored files still work in the upload app. The CodeMirror files inadit/mass_transfer/static/mass_transfer/vendorare vendored by hand and are not touched bycopy-statics - Python and uv in
Dockerfilethat builds the container where ADIT runs in - The
postgresql-client-<version>package installed there must match the major version of thepostgresimage indocker-compose.base.yml, otherwisedb-backup/db-restorebreak - Dependent services in
docker-compose.base.yml, like PostgreSQL or the Orthanc test servers - GitHub Codespaces development container dependencies in
.devcontainer/devcontainer.jsonand.devcontainer/Dockerfile - GitHub Actions
.github/workflows/ci.ymldependencies