chore(deps): bump PyJWT to 2.15.1, urllib3 to 2.8.0, virtualenv floor

This commit is contained in:
maziggy
2026-10-02 15:52:13 +02:00
parent c2619455ca
commit 30f3b3b5f2
3 changed files with 10 additions and 7 deletions
+1 -1
View File
@@ -83,5 +83,5 @@ markers = [
[dependency-groups]
dev = [
"cryptography>=46.0.7",
"pyjwt>=2.13.0",
"pyjwt>=2.15.1",
]
+3
View File
@@ -27,5 +27,8 @@ pip-audit>=2.7.0
# (Unpacker SEGV/DoS on reuse after caught error). Not a runtime dep of
# Bambuddy — pinned here so the audit stays clean.
msgpack>=1.2.1
# Transitive of pre-commit. 21.7.13 closes four advisories in 21.6.x.
# Not a runtime dep of Bambuddy — pinned here so the audit stays clean.
virtualenv>=21.7.13
# Secrets scan: gitleaks (Go binary, not a Python package).
# Install: go install github.com/zricethezav/gitleaks/v8@latest
+6 -6
View File
@@ -106,7 +106,7 @@ psutil>=6.0.0
tzdata>=2024.1; sys_platform == "win32"
# Authentication
PyJWT>=2.13.0
PyJWT>=2.15.1
passlib[bcrypt]>=1.7.4
ldap3>=2.9.0
pyotp>=2.9.0
@@ -137,11 +137,11 @@ certifi>=2024.2.2
# version detection and logs a warning at startup.
curl_cffi>=0.7.0
# Transitive pin: urllib3 2.6.3 has CVE-2026-44431 and CVE-2026-44432;
# 2.7.0+ is the fixed release. Direct pin here because none of our
# top-level deps require >=2.7.0 yet, so without this the resolver
# would silently keep installing the vulnerable 2.6.x line.
urllib3>=2.7.0
# Transitive pin: urllib3 2.7.0 has three advisories (streaming
# decompression limits, proxy TLS settings); 2.8.0 is the fixed release.
# Direct pin here because none of our top-level deps require >=2.8.0 yet,
# so without this the resolver would silently keep the vulnerable line.
urllib3>=2.8.0
# Transitive of fastapi. starlette 1.0.0 has PYSEC-2026-161; 1.1.x has
# CVE-2026-54282/54283; 1.3.1 is the fixed release. fastapi's range still