Skip to content

fix(deps): upgrade lockfile for security advisories#284

Merged
YushaArif99 merged 3 commits into
stagingfrom
fix/high-dependabot-main
Jun 2, 2026
Merged

fix(deps): upgrade lockfile for security advisories#284
YushaArif99 merged 3 commits into
stagingfrom
fix/high-dependabot-main

Conversation

@YushaArif99
Copy link
Copy Markdown
Contributor

Summary

  • Raise python-multipart floor to >=0.0.27.
  • Refresh uv.lock for patched langchain-core, langsmith, lxml, urllib3, and python-multipart (6 Dependabot high alerts on main).

staging already had most of these versions; main lockfile lagged after merge.

Test plan

  • uv sync and a focused pytest slice on main after merge
  • Promote to staging via normal merge flow

Raise python-multipart floor and refresh uv.lock for langchain-core,
langsmith, lxml, urllib3, and python-multipart patches on main.
@YushaArif99 YushaArif99 changed the base branch from main to staging June 2, 2026 11:12
@YushaArif99 YushaArif99 requested a review from hmahmood24 as a code owner June 2, 2026 11:12
Resolve uv.lock conflict by re-locking on staging tip with python-multipart
>=0.0.27 and upgraded transitive security patches.
Regenerate lock after unify/unillm staging updates so uv lock --check
passes against CI merged state (includes litellm 1.83.7 from unillm).
@YushaArif99 YushaArif99 merged commit e363706 into staging Jun 2, 2026
14 of 20 checks passed
@YushaArif99 YushaArif99 deleted the fix/high-dependabot-main branch June 2, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant