Commit f0728f6
Release 2026-07-17 (#906)
* added the metering code
* added logging
* added the sap metering sidecar
* updated the auth token usage
* updated the comments
* updated the env vars
* fix: update cryptography to 46.0.7 to address CVE-2026-39892
- Updated cryptography from 46.0.5 to 46.0.7
- Fixes buffer overflow vulnerability in non-contiguous buffer handling
- Regenerated requirements.txt with Python 3.10
- All unit tests passing (184 passed)
- All linting checks passing
* Bumped the cryptography module version to latest 47.0.0
* Fix CVE-2026-25645 and CVE-2026-34073 by upgrading requests and cryptography
Updated requests from 2.32.5 to 2.33.1 to address CVE-2026-25645.
Updated cryptography from 46.0.5 to 47.0.0 to address CVE-2026-34073.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Security/upgrade requests urllib3 CVE fix (#894)
* Security: Upgrade requests to 2.34.2 and urllib3 to 2.7.0
Fixes high-severity CVEs:
- CVE-2026-25645 (requests): Fixed in 2.33.0+
- GHSA-mf9v-mfxr-j63j (urllib3): Streaming API decompression issue
- GHSA-qccp-gfcp-xxvc (urllib3): Cross-origin redirect header leakage
Changes:
- requests: 2.32.5 → 2.34.2
- urllib3: 2.6.3 → 2.7.0
- charset-normalizer: 2.0.3 → 3.4.7 (transitive)
- idna: 3.10 → 3.15 (transitive)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
* Fixes high-severity CVEs:
- CVE-2026-25645 (requests): Fixed in 2.33.0+
- GHSA-mf9v-mfxr-j63j (urllib3): Streaming API decompression issue
- GHSA-qccp-gfcp-xxvc (urllib3): Cross-origin redirect header leakage
---------
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
* (fix) add typing extension lib (#898)
* Update requirements.txt
* Update requirements.in
* Expand static files caching (#901)
Support static files caching
* Security: Fix CVE-2026-45409 (idna) and GHSA-537c-gmf6-5ccf (cryptogr… (#902)
Security: Fix CVE-2026-45409 (idna) and GHSA-537c-gmf6-5ccf (cryptography)
Upgrades dependencies to address high-severity vulnerabilities:
- cryptography 47.0.0 → 48.0.1: Fixes vulnerable OpenSSL in wheels
- idna 3.10 → 3.15: Fixes DoS vulnerability in IDNA encoding
CVE-2026-45409: idna versions prior to 3.15 were vulnerable to DoS
attacks via specially crafted inputs to idna.encode() function.
GHSA-537c-gmf6-5ccf: cryptography wheels prior to 48.0.1 included
a statically linked copy of OpenSSL with security vulnerabilities.
---------
Co-authored-by: bhavin.shah <bhavin.shah@mendix.com>
Co-authored-by: priyal.chawda@mendix.com <priyal.chawda@mendix.com>
Co-authored-by: Piyush <piyush.tiwari@mendix.com>
Co-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>
Co-authored-by: Bhavin Shah <162097397+bhavinshah-mendix@users.noreply.github.com>
Co-authored-by: Sanny Ramirez <sai.ramirez.umak@gmail.com>
Co-authored-by: EnasAbdelrazek <96430281+EnasAbdelrazek@users.noreply.github.com>1 parent d5ac9d3 commit f0728f6
4 files changed
Lines changed: 9 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
97 | 97 | | |
98 | 98 | | |
99 | 99 | | |
100 | | - | |
| 100 | + | |
101 | 101 | | |
102 | 102 | | |
103 | 103 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
6 | 7 | | |
7 | 8 | | |
8 | 9 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
26 | | - | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
27 | 29 | | |
28 | 30 | | |
29 | 31 | | |
| |||
0 commit comments