security: pin lxml >=6.1.0 to fix CVE-2026-41066#2218
Conversation
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
👋 @MikaKerman |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe pull request adds Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
lxml >= 6.1.0to resolve the last remaining high-severity Dependabot alert (CVE-2026-41066 — XXE via defaultiterparse()/ETCompatXMLParser()config)Test plan
🤖 Generated with Claude Code
Summary by CodeRabbit
lxmlas a project dependency.