Skip to content

Update and relax pins in requirements.txt#83

Merged
dexhunter merged 1 commit into
mainfrom
security/upgrade-requests-cve-2026-32274-33682
May 2, 2026
Merged

Update and relax pins in requirements.txt#83
dexhunter merged 1 commit into
mainfrom
security/upgrade-requests-cve-2026-32274-33682

Conversation

@jacenko
Copy link
Copy Markdown
Contributor

@jacenko jacenko commented Apr 21, 2026

Upgrade several developer/runtime dependencies and relax strict version pins to allow compatible updates. black updated from 24.3.0 to ~=26.3.1; pytest updated from 7.4.3 to ~=9.0.3; streamlit updated from 1.40.2 to ~=1.54.0. These changes address vulnerabilities CVE-2026-32274, CVE-2026-33682, and CVE-2025-71176.

Upgrade several developer/runtime dependencies and relax strict version pins to allow compatible updates. black updated from 24.3.0 to ~=26.3.1; pytest updated from 7.4.3 to ~=9.0.3; streamlit updated from 1.40.2 to ~=1.54.0. These changes smooth future patch/minor upgrades while keeping other packages unchanged.
@jacenko jacenko requested a review from dexhunter April 21, 2026 22:03
Copy link
Copy Markdown
Member

@dexhunter dexhunter left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@dexhunter dexhunter merged commit 40dcf28 into main May 2, 2026
2 checks passed
@dexhunter dexhunter deleted the security/upgrade-requests-cve-2026-32274-33682 branch May 2, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants