mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-04 13:11:35 +02:00
requirements.txt
- cryptography 46.0.7 -> 48.0.1 floor (GHSA-537c-gmf6-5ccf,
non-contiguous Python buffer handling)
- python-multipart 0.0.27 -> 0.0.31 floor (CVE-2026-53538/53539/53540,
multipart parser hardening)
- starlette 1.1.0 -> 1.3.1 floor (CVE-2026-54282/54283, FormParser
limit enforcement + StaticFiles absolute-path rejection)
- pyopenssl 26.0.0 -> 26.3.0 floor (NOT a security fix; pyOpenSSL
<26.3.0 caps cryptography<47 and would otherwise downgrade out
of the GHSA-537c-gmf6-5ccf fix line)
backend/app/api/routes/mfa.py
- 3x HTTP_422_UNPROCESSABLE_ENTITY -> HTTP_422_UNPROCESSABLE_CONTENT
(the former is deprecated in starlette 1.3.x, same 422 wire status;
the 2 remaining warnings are inside FastAPI itself, upstream's)
Release-notes review done before bump: cryptography 47/48 dropped
binary EC, CFB/OFB/CFB8, Camellia, PUBLIC_KEY_TYPES/PRIVATE_KEY_TYPES,
OpenSSL 1.1.x, Python 3.8 -- grep clean against every removed surface;
starlette's newly-enforced max_part_size=1MB only applies to text form
fields (verified in MultiPartParser.on_part_data), file streams from
UploadFile = File(...) are unaffected; python-multipart 0.0.30 dropped
RFC 2231/5987 filename* parsing, minor cosmetic impact on non-ASCII
filename uploads, plain filename= fallback still works.