fix(deps): bump python-multipart to 0.0.32 (security)#616
Conversation
Resolves 4 advisories flagged by dependency-review on PR #613, including a high-severity ReDoS: - GHSA-5rvq-cxj2-64vf (high) quadratic querystring parsing DoS (patched 0.0.30) - GHSA-vffw-93wf-4j4q / GHSA-6jv3-5f52-599m (low) parameter smuggling (0.0.30) - GHSA-v9pg-7xvm-68hf (low) negative Content-Length buffering (patched 0.0.31) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Completed Working on "Code Review"✅ Code review complete. No issues found - all changes look good! ✅ ✅ Workflow completed successfully. |
Dependency ReviewThe following issues were found:
License Issuesuv.lock
OpenSSF Scorecard
Scanned Files
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
📝 WalkthroughWalkthrough
ChangesServer optional dependency update
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🚅 Deployed to the QueryWeaver-pr-616 environment in queryweaver
|
Summary
Bumps
python-multipart0.0.29 → 0.0.32to clear the dependency-review failure blocking thestaging → mainpromotion (PR #613).dependency-reviewflagged 4 advisories onpython-multipart@0.0.29:0.0.32(latest) covers all four.Changes
pyproject.toml:python-multipart~=0.0.29→~=0.0.32uv.lock: regenerated (Updated python-multipart v0.0.29 -> v0.0.32)Test plan
uv sync --all-extrasresolves cleanly;import multipart→ 0.0.32Once merged into
staging, PR #613's dependency-review will pass.🤖 Generated with Claude Code
Summary by CodeRabbit