Skip to content

deps: update requests version to fix CVE - #553

Merged
sng-asyncfunc merged 1 commit into
AsyncFuncAI:mainfrom
GdoongMathew:fix/requests_cve
Jul 25, 2026
Merged

deps: update requests version to fix CVE#553
sng-asyncfunc merged 1 commit into
AsyncFuncAI:mainfrom
GdoongMathew:fix/requests_cve

Conversation

@GdoongMathew

@GdoongMathew GdoongMathew commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

Summary

Update package requests to version 2.34.2 or later. (fix #537, #539)

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the requests dependency constraint in api/pyproject.toml to ^2.34.2 and regenerates the api/poetry.lock file using Poetry 2.4.1, which updates various package markers and sub-dependencies. There are no review comments, so I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@sng-asyncfunc
sng-asyncfunc merged commit 6b4cdea into AsyncFuncAI:main Jul 25, 2026
3 checks passed
@GdoongMathew
GdoongMathew deleted the fix/requests_cve branch July 26, 2026 06:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: multiple requests advisories appear reachable in deepwiki-open

2 participants