Commit 1a18618
Bump vulnerable deps flagged by Dependabot
* lxml 6.0.2 -> 6.1.0 (XXE in iterparse/ETCompatXMLParser defaults, GHSA high)
* authlib 1.6.9 -> 1.7.0 (CSRF when using cache)
* cryptography 46.0.6 -> 46.0.7 (buffer overflow on non-contiguous buffers)
* pytest 9.0.2 -> 9.0.3 (tmpdir handling)
* pygments 2.19.2 -> 2.20.0 (ReDoS in GUID regex) — relaxed docs-group pin from <2.20
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent 5015c08 commit 1a18618
2 files changed
Lines changed: 128 additions & 115 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
173 | 173 | | |
174 | 174 | | |
175 | 175 | | |
176 | | - | |
| 176 | + | |
177 | 177 | | |
178 | 178 | | |
179 | 179 | | |
| |||
0 commit comments