Skip to content

LCORE-1490: fixes CVE in pyasn1#1340

Merged
tisnik merged 1 commit into
lightspeed-core:mainfrom
tisnik:lcore-1490-pyasn-cve
Mar 17, 2026
Merged

LCORE-1490: fixes CVE in pyasn1#1340
tisnik merged 1 commit into
lightspeed-core:mainfrom
tisnik:lcore-1490-pyasn-cve

Conversation

@tisnik

@tisnik tisnik commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

Description

LCORE-1490: fixes CVE in pyasn1

Type of change

  • Refactor
  • New feature
  • Bug fix
  • CVE fix
  • Optimization
  • Documentation Update
  • Configuration Update
  • Bump-up service version
  • Bump-up dependent library
  • Bump-up library or tool used for development (does not change the final image)
  • CI configuration change
  • Konflux configuration change
  • Unit tests improvement
  • Integration tests improvement
  • End to end tests improvement
  • Benchmarks improvement

Tools used to create PR

  • Assisted-by: N/A
  • Generated by: N/A

Related Tickets & Documents

  • Related Issue #LCORE-1490

Summary by CodeRabbit

  • Chores
    • Updated a dependency to a newer version for compatibility and stability.

@coderabbitai

coderabbitai Bot commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: b3711265-0b39-4042-aaaa-9cfdafd74576

📥 Commits

Reviewing files that changed from the base of the PR and between b4928e1 and c42f3e3.

⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • pyproject.toml

Walkthrough

Updates the pyasn1 dependency requirement in pyproject.toml from version 0.6.2 to 0.6.3, with an associated ticket reference comment added. No logic or control flow modifications.

Changes

Cohort / File(s) Summary
Dependency Update
pyproject.toml
Updated pyasn1 requirement from >=0.6.2 to >=0.6.3 with associated comment reference.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and directly references the CVE fix objective (LCORE-1490) and the pyasn1 library upgrade, which aligns with the main change in the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@tisnik tisnik merged commit 80d5b9e into lightspeed-core:main Mar 17, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant