Skip to content

chore(deps): bump worker_plan deps to patch security alerts#813

Merged
neoneye merged 1 commit into
mainfrom
deps/security-bumps-worker-plan
Jun 26, 2026
Merged

chore(deps): bump worker_plan deps to patch security alerts#813
neoneye merged 1 commit into
mainfrom
deps/security-bumps-worker-plan

Conversation

@neoneye

@neoneye neoneye commented Jun 26, 2026

Copy link
Copy Markdown
Member

Resolves 25 open Dependabot security alerts in worker_plan/pyproject.toml by bumping to the first stable patched release of each package.

Package From To Alerts
aiohttp 3.13.5 3.14.1 #152, #153, #156#164
tornado 6.5.4 6.5.7 #113, #114, #136, #155, #165, #166, #171
python-multipart 0.0.22 0.0.32 #142, #149, #167#170
urllib3 2.6.3 2.7.0 #150, #151
marshmallow 3.24.2 3.26.2 #81

Notes:

🤖 Generated with Claude Code

Resolves Dependabot security alerts in worker_plan/pyproject.toml by bumping to the first stable patched release of each package:

- aiohttp 3.13.5 -> 3.14.1 (alerts #152,#153,#156-#164)
- tornado 6.5.4 -> 6.5.7 (alerts #113,#114,#136,#155,#165,#166,#171)
- python-multipart 0.0.22 -> 0.0.32 (alerts #142,#149,#167-#170)
- urllib3 2.6.3 -> 2.7.0 (alerts #150,#151)
- marshmallow 3.24.2 -> 3.26.2 (alert #81), staying on 3.x to avoid the breaking 4.x major

transformers alert #137 is excluded: its only fix is the 5.x major line and the vulnerable Trainer class is never imported by PlanExe (handled separately).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@neoneye neoneye merged commit a35766e into main Jun 26, 2026
3 checks passed
@neoneye neoneye deleted the deps/security-bumps-worker-plan branch June 26, 2026 11:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant