Skip to content

Bump FastAPI / starlette dependencies to fix CVE #2470

@plaflamme

Description

@plaflamme

The current versions have a CVE opened against them due to their python-multipart dependency https://nvd.nist.gov/vuln/detail/CVE-2024-24762

Obviously this isn't technically a problem for sqlmesh since it's not expected to sitting directly on the intertubes, but this is triggering static analysis tools and is good hygiene in general.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions