Commit 4ef99cc
committed
chore(deps): bump 9 main-app dependencies to Dependabot-validated versions
Bundles the nine open Dependabot PRs against the main app into a single
uv.lock regeneration:
- urllib3 2.6.3 -> 2.7.0 (closes #200)
- gitpython 3.1.46 -> 3.1.50 (closes #198)
- python-dotenv 1.2.1 -> 1.2.2 (closes #190)
- pytest 9.0.2 -> 9.0.3 (closes #188)
- uv 0.9.21 -> 0.11.6 (closes #184)
- cryptography 46.0.5 -> 46.0.7 (closes #181)
- pygments 2.19.2 -> 2.20.0 (closes #177)
- requests 2.32.5 -> 2.33.0 (closes #175)
- idna 3.11 -> 3.15 (closes #205, CVE-2026-45409)
idna 3.14 fixed CVE-2026-45409 -- a quadratic-time DoS vector via
oversized inputs that bypassed the earlier CVE-2024-3651 mitigation.
The other bumps are version-currentness hygiene.
All nine target versions verified through Socket Firewall (sfw) on the
full transitive dependency tree; no malware / typosquat / supply-chain
alerts surfaced.
Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>1 parent eb9121f commit 4ef99cc
1 file changed
Lines changed: 83 additions & 83 deletions
0 commit comments