Commit d02378e
Bump filelock from 3.20.1 to 3.20.3 (#135)
* Bump filelock from 3.20.1 to 3.20.3
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.20.1 to 3.20.3.
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.20.1...3.20.3)
---
updated-dependencies:
- dependency-name: filelock
dependency-version: 3.20.3
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Fix security vulnerabilities in dependencies
Security updates:
- Update aiohttp from 3.12.15 to 3.13.3 (fixes GHSA-6mq8-rvhq-8wgg, GHSA-69f9-5gxw-wvc2, GHSA-6jhg-hg63-jvvf, GHSA-g84x-mcqj-x9qq, GHSA-fh55-r93g-j68g, GHSA-54jq-c3m8-4m76, GHSA-jj3x-wxrx-4x23, GHSA-mqqc-3gqh-h2x8)
- Update urllib3 from 2.6.2 to 2.6.3 (fixes GHSA-38jv-5279-wg99)
- Update virtualenv from 20.34.0 to 20.36.1 (fixes GHSA-597g-3phw-6986)
All vulnerabilities have been addressed with patched versions.
Severity: High (8 aiohttp DoS/request smuggling vulnerabilities)
Co-authored-by: AI Engineering Maintenance Bot <aieng-bot@vectorinstitute.ai>
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Amrit Krishnan <amrit110@gmail.com>
Co-authored-by: AI Engineering Maintenance Bot <aieng-bot@vectorinstitute.ai>1 parent 42a8b64 commit d02378e
2 files changed
Lines changed: 2087 additions & 2047 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
22 | | - | |
| 21 | + | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| 35 | + | |
| 36 | + | |
35 | 37 | | |
36 | 38 | | |
37 | 39 | | |
| |||
0 commit comments