Commit c2154ad
Merge Develop into Master (#896)
* added the metering code
* added logging
* added the sap metering sidecar
* updated the auth token usage
* updated the comments
* updated the env vars
* fix: update cryptography to 46.0.7 to address CVE-2026-39892
- Updated cryptography from 46.0.5 to 46.0.7
- Fixes buffer overflow vulnerability in non-contiguous buffer handling
- Regenerated requirements.txt with Python 3.10
- All unit tests passing (184 passed)
- All linting checks passing
* Bumped the cryptography module version to latest 47.0.0
* Fix CVE-2026-25645 and CVE-2026-34073 by upgrading requests and cryptography
Updated requests from 2.32.5 to 2.33.1 to address CVE-2026-25645.
Updated cryptography from 46.0.5 to 47.0.0 to address CVE-2026-34073.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Security/upgrade requests urllib3 CVE fix (#894)
* Security: Upgrade requests to 2.34.2 and urllib3 to 2.7.0
Fixes high-severity CVEs:
- CVE-2026-25645 (requests): Fixed in 2.33.0+
- GHSA-mf9v-mfxr-j63j (urllib3): Streaming API decompression issue
- GHSA-qccp-gfcp-xxvc (urllib3): Cross-origin redirect header leakage
Changes:
- requests: 2.32.5 → 2.34.2
- urllib3: 2.6.3 → 2.7.0
- charset-normalizer: 2.0.3 → 3.4.7 (transitive)
- idna: 3.10 → 3.15 (transitive)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fixes high-severity CVEs:
- CVE-2026-25645 (requests): Fixed in 2.33.0+
- GHSA-mf9v-mfxr-j63j (urllib3): Streaming API decompression issue
- GHSA-qccp-gfcp-xxvc (urllib3): Cross-origin redirect header leakage
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
---------
Co-authored-by: bhavin.shah <bhavin.shah@mendix.com>
Co-authored-by: priyal.chawda@mendix.com <priyal.chawda@mendix.com>
Co-authored-by: Piyush <piyush.tiwari@mendix.com>
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Bhavin Shah <162097397+bhavinshah-mendix@users.noreply.github.com>1 parent bb5aa2d commit c2154ad
0 file changed
0 commit comments