Commit d7445a4
committed
Pin security floors for lxml, urllib3, requests, pygments
Resolved five open Dependabot advisories by adding minimum-version
constraints to pyproject.toml so Poetry resolves transitive deps to
patched releases:
- lxml >=6.1.0 (XXE in iterparse default configuration)
- urllib3 >=2.7.0 (sensitive-header forwarding on proxied redirects;
decompression-bomb safeguard bypass)
- requests >=2.33.0 (insecure temp file reuse in extract_zipped_paths)
- pygments >=2.20.0 (ReDoS in GUID regex matching)
Regenerated poetry.lock; only the four flagged packages changed.1 parent 4547d88 commit d7445a4
3 files changed
Lines changed: 159 additions & 163 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
0 commit comments