Skip to content

Upgrade GitPython to resolve GHSA-r9mr-m37c-5fr3 GHSA-fjr4-x663-mwxc GHSA-94p4-4cq8-9g67 GHSA-6p8h-3wgx-97gf - #607

Merged
cigamit merged 1 commit into
mainfrom
GHSA-r9mr-m37c-5fr3
Jul 28, 2026
Merged

Upgrade GitPython to resolve GHSA-r9mr-m37c-5fr3 GHSA-fjr4-x663-mwxc GHSA-94p4-4cq8-9g67 GHSA-6p8h-3wgx-97gf#607
cigamit merged 1 commit into
mainfrom
GHSA-r9mr-m37c-5fr3

Conversation

@cigamit

@cigamit cigamit commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@cigamit cigamit self-assigned this Jul 28, 2026
Copilot AI review requested due to automatic review settings July 28, 2026 20:01
@cigamit cigamit added dependencies Pull requests that update a dependency file SECURITY A security related issue like a CVE specifically python Pull requests that update python code labels Jul 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates GitPython dependency constraints to address multiple GitPython security advisories (GHSAs) referenced in the PR title, ensuring the Ascender dependency set remains secure.

Changes:

  • Bumps the compiled/pinned GitPython version in requirements.txt to 3.1.57.
  • Raises the minimum GitPython version constraint in requirements.in.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
requirements/requirements.txt Updates the pinned GitPython version to 3.1.57.
requirements/requirements.in Raises the minimum GitPython constraint to mitigate the referenced advisories (but currently not high enough for all listed GHSAs).

Comment thread requirements/requirements.in
@cigamit
cigamit merged commit 6b6c936 into main Jul 28, 2026
1 check passed
@cigamit
cigamit deleted the GHSA-r9mr-m37c-5fr3 branch July 28, 2026 20:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code SECURITY A security related issue like a CVE specifically

Development

Successfully merging this pull request may close these issues.

3 participants