Skip to content

Bump urllib3 lockfile to 2.7.0#11

Open
arpitjain099 wants to merge 1 commit into
huggingface:mainfrom
arpitjain099:security/upgrade-urllib3-2.7.0
Open

Bump urllib3 lockfile to 2.7.0#11
arpitjain099 wants to merge 1 commit into
huggingface:mainfrom
arpitjain099:security/upgrade-urllib3-2.7.0

Conversation

@arpitjain099
Copy link
Copy Markdown

Summary

  • upgrade urllib3 in uv.lock from 2.6.3 to 2.7.0
  • resolves two open high-severity Dependabot alerts (redirect header forwarding and decompression-bomb bypass)
  • keeps the change scoped to lockfile-only dependency remediation

Test plan

  • python3 -m uv run pytest -q

Upgrade urllib3 in uv.lock to pick up fixes for two high-severity advisories flagged by Dependabot. Keeps runtime behavior unchanged while removing known HTTP redirect and decompression-bomb risks.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant