Skip to content

Conversation

@RinZ27
Copy link

@RinZ27 RinZ27 commented Jan 21, 2026

Bumped requests and aiohttp to their latest stable versions.

Previous constraints were pulling in urllib3 < 2.3.0 and aiohttp < 3.10, which have known quirks with SSL/TLS connection handling and header parsing. After reviewing the logic, I decided that ensuring the SDK remains robust when dealing with API calls and image downloads should be a priority.

Also regenerated uv.lock to reflect these dependency updates.

@RinZ27 RinZ27 requested a review from a team as a code owner January 21, 2026 13:55
@RinZ27 RinZ27 changed the title security: upgrade core dependencies to fix critical CVE-2026-21441 (MitM) & CVE-2025-69223 (DoS) Upgrade requests and aiohttp to fix SSL handling and header parsing issues Jan 21, 2026
@RinZ27 RinZ27 force-pushed the fix/upgrade-critical-deps branch 6 times, most recently from c7c6566 to 4f194a4 Compare January 22, 2026 10:29
@RinZ27 RinZ27 force-pushed the fix/upgrade-critical-deps branch from eb0c1a3 to 9c7dec9 Compare January 22, 2026 15:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant