Skip to content

fix(deps): resolve Dependabot security alerts#235

Merged
mplatzer merged 3 commits into
mainfrom
fix/dependabot-security-upgrades
Apr 30, 2026
Merged

fix(deps): resolve Dependabot security alerts#235
mplatzer merged 3 commits into
mainfrom
fix/dependabot-security-upgrades

Conversation

@mplatzer
Copy link
Copy Markdown
Contributor

This PR refreshes uv.lock with uv lock --upgrade so vulnerable transitive dependencies are updated to patched releases (urllib3, Pillow, Tornado, cryptography, requests, filelock, fonttools, virtualenv, Black, pytest, Pygments, pymdown-extensions, PyTorch, transformers, and related packages).

Also updated

  • pyproject.toml minimum versions to match what we resolved (torch, transformers, dev/docs tooling).
  • .pre-commit-config.yaml Ruff hook to v0.15.12 to stay in sync with ruff in the lockfile.

Verification

  • uv run ruff check mostlyai tests
  • uv run pytest (46 passed)

Note: Includes major upgrades (e.g. transformers 5.x, pandas 3.x, torch 2.11). Downstream consumers on older stacks may need to align versions.

Made with Cursor

Refresh uv.lock with uv lock --upgrade so transitive packages pick up
patched releases (urllib3, pillow, tornado, cryptography, requests,
filelock, fonttools, virtualenv, black, pytest, pygments,
pymdown-extensions, torch, transformers, and related stack).

Align pyproject minimums and ruff-pre-commit rev with the resolved
versions. Tests and ruff pass.

Made-with: Cursor
Loosen the declared floor so environments pinning torch==2.6.0+cpu
remain compatible. The repo lockfile still resolves newer torch for
CI and security-patched installs.

Made-with: Cursor
@mplatzer mplatzer merged commit aefc601 into main Apr 30, 2026
4 checks passed
@mplatzer mplatzer deleted the fix/dependabot-security-upgrades branch April 30, 2026 08:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant