Skip to content

fix(security): update transitive deps (17 vulns)#16

Merged
git-steer[bot] merged 1 commit into
mainfrom
security/update-locks-20260531
May 31, 2026
Merged

fix(security): update transitive deps (17 vulns)#16
git-steer[bot] merged 1 commit into
mainfrom
security/update-locks-20260531

Conversation

@git-steer

@git-steer git-steer Bot commented May 31, 2026

Copy link
Copy Markdown
Contributor

Security: Force Dependency Resolution

This PR removes lock files to force fresh dependency resolution, picking up patched versions of transitive dependencies.

Affected Packages

  • idna (medium) → fix: 3.15
  • authlib (medium) → fix: 1.6.12
  • urllib3 (high) → fix: 2.7.0
  • mem0ai (low) → fix: 2.0.0b2
  • python-multipart (high) → fix: 0.0.27
  • python-dotenv (medium) → fix: 1.2.2
  • authlib (medium) → fix: 1.6.11
  • python-multipart (medium) → fix: 0.0.26
  • pytest (medium) → fix: 9.0.3
  • cryptography (medium) → fix: 46.0.7
  • Pygments (low) → fix: 2.20.0
  • cryptography (low) → fix: 46.0.6
  • requests (medium) → fix: 2.33.0
  • nltk (high) → fix: 3.9.4
  • nltk (medium) → fix: 3.9.4
  • PyJWT (high) → fix: 2.12.0

Lock Files Removed

  • uv.lock

Summary

  • Vulnerabilities addressed: 17
  • Critical: 0 High: 5 Medium: 9 Low: 3

After Merge

Run npm install / uv sync / pip install -r requirements.txt to regenerate lock files.


Generated by git-steer automated remediation

@git-steer git-steer Bot added automated Created by automation dependencies Dependency updates security Security vulnerability labels May 31, 2026
@git-steer git-steer Bot merged commit ef022bd into main May 31, 2026
3 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Created by automation dependencies Dependency updates security Security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants