Skip to content

Commit 597ad0b

Browse files
authored
fix: bump vulnerable transitive deps (#762)
Signed-off-by: Johnny Greco <jogreco@nvidia.com>
1 parent 7c2c15e commit 597ad0b

3 files changed

Lines changed: 22 additions & 16 deletions

File tree

packages/data-designer-engine/pyproject.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,7 @@ dependencies = [
5656
"ruff>=0.14.10,<1",
5757
"scipy>=1.11.0,<2",
5858
"sqlfluff>=4.1.0,<5",
59+
"starlette>=1.2.0,<2", # 1.2.0 fixes security advisory pulled in by mcp
5960
"tiktoken>=0.8.0,<1",
6061
]
6162

pyproject.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,7 @@ notebooks = [
5656
"mistune>=3.2.1,<4", # 3.2.1 fixes security advisory pulled in by nbconvert
5757
"nbconvert>=7.17.1,<8", # 7.17.1 fixes security advisory pulled in by jupyter
5858
"notebook>=7.6.0a5,<8", # 7.6.0a5 fixes security advisory pulled in by jupyter
59+
"tornado>=6.5.7,<7", # 6.5.7 fixes security advisory pulled in by jupyterlab
5960
]
6061
recipes = [
6162
"bm25s>=0.2.0,<1",

uv.lock

Lines changed: 20 additions & 16 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)