Skip to content

Commit 4ef99cc

Browse files
committed
chore(deps): bump 9 main-app dependencies to Dependabot-validated versions
Bundles the nine open Dependabot PRs against the main app into a single uv.lock regeneration: - urllib3 2.6.3 -> 2.7.0 (closes #200) - gitpython 3.1.46 -> 3.1.50 (closes #198) - python-dotenv 1.2.1 -> 1.2.2 (closes #190) - pytest 9.0.2 -> 9.0.3 (closes #188) - uv 0.9.21 -> 0.11.6 (closes #184) - cryptography 46.0.5 -> 46.0.7 (closes #181) - pygments 2.19.2 -> 2.20.0 (closes #177) - requests 2.32.5 -> 2.33.0 (closes #175) - idna 3.11 -> 3.15 (closes #205, CVE-2026-45409) idna 3.14 fixed CVE-2026-45409 -- a quadratic-time DoS vector via oversized inputs that bypassed the earlier CVE-2024-3651 mitigation. The other bumps are version-currentness hygiene. All nine target versions verified through Socket Firewall (sfw) on the full transitive dependency tree; no malware / typosquat / supply-chain alerts surfaced. Signed-off-by: lelia <2418071+lelia@users.noreply.github.com>
1 parent eb9121f commit 4ef99cc

1 file changed

Lines changed: 83 additions & 83 deletions

File tree

0 commit comments

Comments
 (0)