Skip to content

Bump min versions for security fixes#18

Merged
aserper merged 2 commits intomainfrom
security-bump-versions
Apr 29, 2026
Merged

Bump min versions for security fixes#18
aserper merged 2 commits intomainfrom
security-bump-versions

Conversation

@aserper
Copy link
Copy Markdown
Owner

@aserper aserper commented Apr 29, 2026

Bumps minimum version constraints to fix dependabot security alerts:

  • GitPython>=3.1.42 (command injection via git options bypass)
  • python-multipart>=0.0.20 (DoS via large multipart data)
  • pytest>=9.0.3 (tmpdir handling)
  • cryptography>=44.0.0 (buffer overflow)

@aserper aserper merged commit 599b819 into main Apr 29, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant