Skip to content

fix(deps): clear backend transitive security advisories (urllib3, Mako, idna, pytest) - #28

Merged
timothybrown merged 1 commit into
mainfrom
fix/backend-transitive-cves
Jun 5, 2026
Merged

timothybrown merged 1 commit into
mainfrom
fix/backend-transitive-cves

Conversation

@timothybrown

Copy link
Copy Markdown
Owner

Clears open Dependabot security alerts that Dependabot itself could not auto-fix, because the affected packages are transitive deps (no direct entry in pyproject.toml) and require a manual uv upgrade.

Package From To Lockfile(s) Advisory
urllib3 2.6.3 2.7.0 backend GHSA (medium)
Mako 1.3.10 1.3.12 backend GHSA (high)
idna 3.11 3.18 backend, tools/simulator, tests/e2e GHSA-65pc-fj4g-8rjx (medium)
pytest 9.0.2 9.0.3 backend (dev) GHSA (medium)

All patch/minor bumps, lockfile-only (uv lock --upgrade-package). No pyproject.toml changes needed — existing constraints already allow these. Verified the diff touches only these four packages.

Companion to the starlette 1.0.1 (#27) and idna//tools/fixtures (#26) PRs Dependabot was able to open.

🤖 Generated with Claude Code

Dependabot flagged these but could not auto-open PRs (transitive deps
need manual uv upgrades). Lockfile-only via `uv lock --upgrade-package`:

- urllib3 2.6.3 -> 2.7.0   (backend)
- Mako    1.3.10 -> 1.3.12 (backend; alembic templating)
- idna    3.11 -> 3.18     (backend, tools/simulator, tests/e2e)
- pytest  9.0.2 -> 9.0.3   (backend, dev)

All patch/minor. No pyproject changes; constraints already satisfied.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@timothybrown
timothybrown merged commit cf5f232 into main Jun 5, 2026
3 checks passed
@timothybrown
timothybrown deleted the fix/backend-transitive-cves branch June 5, 2026 17:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant