Skip to content

v1

  • v1
  • 3f9f90f
  • Verified

    This commit was created on GitHub.com and signed with GitHub’s verified signature.
  • Choose a tag to compare

  • v1
  • 3f9f90f
  • Choose a tag to compare

  • Verified

    This commit was created on GitHub.com and signed with GitHub’s verified signature.
@lorenjphillips lorenjphillips tagged this 22 May 19:20
* fix(deps): bump urllib3 to 2.7.0

Patches GHSA-pq67-6m6q-mj2v: urllib3 < 2.7.0 forwards sensitive
headers across origins during proxied low-level redirects.

Resolves Dependabot alert #9.

* fix(deps): bump idna to 3.15

Patches the IDNA bypass of the CVE-2024-3651 fix: specially crafted
inputs to idna.encode() can still trigger pathological CPU usage on
idna < 3.15.

Resolves Dependabot alert #10.
Assets 2
Loading