Skip to content

Conversation

@vdusek
Copy link
Collaborator

@vdusek vdusek commented Feb 11, 2026

Summary

  • Added explicit black>=24.3.0 constraint to dev dependency group to override the vulnerable transitive dependency from pydoc-markdown -> docspec-python -> black
  • Same fix as applied in apify-client-python#582

Test plan

  • Pre-commit hooks pass (lint + type check)
  • CI pipeline passes

🤖 Generated with Claude Code

pydoc-markdown is unmaintained and pins old docspec-python with a
vulnerable version of black. We explicitly constrain black>=24.3.0
to override the transitive dependency and resolve the dependabot
security alert.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@vdusek vdusek added t-tooling Issues with this label are in the ownership of the tooling team. adhoc Ad-hoc unplanned task added during the sprint. labels Feb 11, 2026
@vdusek vdusek self-assigned this Feb 11, 2026
@vdusek vdusek added t-tooling Issues with this label are in the ownership of the tooling team. adhoc Ad-hoc unplanned task added during the sprint. labels Feb 11, 2026
@vdusek vdusek requested a review from B4nan February 11, 2026 08:30
@github-actions github-actions bot added this to the 134th sprint - Tooling team milestone Feb 11, 2026
@vdusek vdusek changed the title fix: override vulnerable black transitive dependency chore(deps): override vulnerable black transitive dependency Feb 11, 2026
@vdusek vdusek merged commit 910ab54 into master Feb 11, 2026
28 of 31 checks passed
@vdusek vdusek deleted the fix/override-vulnerable-black-dependency branch February 11, 2026 08:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

adhoc Ad-hoc unplanned task added during the sprint. t-tooling Issues with this label are in the ownership of the tooling team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants