Skip to content

⚠️ SECURITY-#6: Update vulnerable dependencies#7

Merged
FernandoCelmer merged 1 commit intomasterfrom
feature/6
Apr 11, 2026
Merged

⚠️ SECURITY-#6: Update vulnerable dependencies#7
FernandoCelmer merged 1 commit intomasterfrom
feature/6

Conversation

@FernandoCelmer
Copy link
Copy Markdown
Member

Description

Update 4 packages with known security vulnerabilities across all requirements.txt files:

Package From To Severity CVE
h11 0.14.0 0.16.0 Critical Malformed Chunked-Encoding body acceptance
urllib3 2.3.0–2.4.0 2.6.3 High Decompression bombs, unbounded chain, redirect issues
requests 2.32.3 2.33.1 Medium Insecure temp file reuse, .netrc credential leak
Pygments 2.19.1 2.20.0 Low ReDoS via GUID matching regex

Files Changed

  • requirements.txt
  • etl_flow/requirements.txt
  • health_check_flow/requirements.txt
  • server_flow/requirements.txt

Motivation and Context

Resolves 27 open Dependabot security alerts.

Closes #6

Types of changes

  • Bug fix (change that fixes an issue)

Checklist

  • I have performed a self-review of my own code
  • All version bumps are to the latest patched releases

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fix Dependabot security alerts — update vulnerable dependencies

1 participant