Commit bf941a0
chore: refresh uv.lock and tolerate pytest CVE pending companion PR
Two coordinated changes:
1. uv.lock resolver regeneration — brings fastapi/rich/ruff/uvicorn into sync
with pyproject.toml lower bounds that had drifted after Dependabot merges.
No behavioural change; test suite green at 324 passed.
2. osv-scanner.toml — time-bounded IgnoredVulns entry for GHSA-6w46-j5rx-g56g
(ignoreUntil 2026-04-21). The pytest 9.0.2 → 9.0.3 bump lands in companion
PR (feature/pytest-cve-bump), which will atomically remove this entry.
Refs: Pre-Sprint 4 pytest CVE WI (18 Apr)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent c5cb637 commit bf941a0
2 files changed
Lines changed: 40 additions & 35 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments