Skip to content

fix(security): Patch 57 vulnerabilities in backend - #160

Merged
git-steer[bot] merged 1 commit into
mainfrom
security/fix-backend
Jun 25, 2026
Merged

fix(security): Patch 57 vulnerabilities in backend#160
git-steer[bot] merged 1 commit into
mainfrom
security/fix-backend

Conversation

@git-steer

@git-steer git-steer Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Security Fix

This PR addresses 57 security vulnerabilities (non-destructive lockfile bumps).

CVE Package Severity Fix Version
N/A pydantic-settings MEDIUM 2.14.2
N/A pydantic-settings MEDIUM 2.14.2
N/A pypdf MEDIUM 6.13.3
CVE-2026-54531 pypdf MEDIUM 6.13.0
CVE-2026-54530 pypdf MEDIUM 6.13.0
CVE-2026-49461 pypdf MEDIUM 6.12.2
CVE-2026-49460 pypdf MEDIUM 6.12.2
CVE-2026-48735 pypdf MEDIUM 6.12.1
CVE-2026-54283 starlette HIGH 1.3.1
CVE-2026-54282 Starlette LOW 1.3.0
CVE-2026-48818 starlette HIGH 1.1.0
CVE-2026-48817 starlette MEDIUM 1.1.0
CVE-2026-54283 starlette HIGH 1.3.1
CVE-2026-54282 Starlette LOW 1.3.0
CVE-2026-48818 starlette HIGH 1.1.0
CVE-2026-48817 starlette MEDIUM 1.1.0
CVE-2026-53539 python-multipart HIGH 0.0.30
CVE-2026-53540 python-multipart LOW 0.0.31
CVE-2026-53538 python-multipart LOW 0.0.30
CVE-2026-53537 python-multipart LOW 0.0.30
CVE-2026-48526 pyjwt HIGH 2.13.0
CVE-2026-48522 PyJWT MEDIUM 2.13.0
CVE-2026-48525 pyjwt MEDIUM 2.13.0
CVE-2026-48523 pyjwt MEDIUM 2.13.0
CVE-2026-48524 pyjwt LOW 2.13.0
CVE-2026-48155 pypdf MEDIUM 6.12.0
CVE-2026-48156 pypdf MEDIUM 6.12.0
CVE-2026-48710 starlette MEDIUM 1.0.1
CVE-2026-48710 starlette MEDIUM 1.0.1
CVE-2026-45409 idna MEDIUM 3.15
CVE-2026-44431 urllib3 HIGH 2.7.0
CVE-2026-44432 urllib3 HIGH 2.7.0
CVE-2026-42561 python-multipart HIGH 0.0.27
CVE-2026-44307 Mako HIGH 1.3.12
CVE-2026-42311 pillow HIGH 12.2.0
CVE-2026-42310 pillow MEDIUM 12.2.0
CVE-2026-42308 pillow MEDIUM 12.2.0
CVE-2026-42309 pillow MEDIUM 12.2.0
CVE-2026-28684 python-dotenv MEDIUM 1.2.2
CVE-2026-0846 nltk HIGH 3.9.3
CVE-2026-41314 pypdf MEDIUM 6.10.2
CVE-2026-41312 pypdf MEDIUM 6.10.2
CVE-2026-41313 pypdf MEDIUM 6.10.2
CVE-2026-40347 python-multipart MEDIUM 0.0.26
CVE-2026-41168 pypdf MEDIUM 6.10.1
CVE-2025-71176 pytest MEDIUM 9.0.3
CVE-2026-40192 pillow HIGH 12.2.0
CVE-2026-40260 pypdf MEDIUM 6.10.0
CVE-2026-25645 requests MEDIUM 2.33.0
CVE-2026-33699 pypdf MEDIUM 6.9.2
CVE-2026-33231 nltk HIGH 3.9.4
CVE-2026-33230 nltk MEDIUM 3.9.4
CVE-2026-33123 pypdf MEDIUM 6.9.1
CVE-2026-32597 PyJWT HIGH 2.12.0
CVE-2026-32274 black HIGH 26.3.1
CVE-2026-31826 pypdf MEDIUM 6.8.0
CVE-2026-28804 pypdf MEDIUM 6.7.5
  • Critical: 0 High: 16 Medium: 35 Low: 6

Merge is gated by the ADR-005 functional-integrity gate. Generated by git-steer.

@git-steer git-steer Bot added dependencies Dependency updates security Security vulnerability automated Created by automation needs-human-merge Held by ADR-005 functional-integrity gate labels Jun 25, 2026
@git-steer

git-steer Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor Author

🚦 Functional-integrity gate: NO-GO (ADR-005) — auto-merge withheld, held for human review.

Dimensions: [{"dimension":"BUILD","result":"FAIL"},{"dimension":"TEST","result":"NOT_APPLICABLE"},{"dimension":"SMOKE","result":"NOT_APPLICABLE"},{"dimension":"SURFACE","result":"NOT_APPLICABLE"}]

Why this is held — gate verdict NO-GO:

docker-extension/ui (npm) — BUILD FAILED
npm error Conflicting peer dependency: vite@7.3.6
npm error node_modules/vite
npm error   peer vite@"^4.2.0 || ^5.0.0 || ^6.0.0 || ^7.0.0" from @vitejs/plugin-react@4.7.0
npm error   node_modules/@vitejs/plugin-react
npm error     dev @vitejs/plugin-react@"^4.2.0" from the root project
npm error
npm error Fix the upstream dependency conflict, or retry
npm error this command with --force or --legacy-peer-deps
npm error to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /home/runner/.npm/_logs/2026-06-25T11_29_18_098Z-eresolve-report.txt
npm error A complete log of this run can be found in: /home/runner/.npm/_logs/2026-06-25T11_29_18_098Z-debug-0.log

…ltk, pillow, pydantic-settings, pyjwt, pypdf, pytest, python-dotenv, python-multipart, requests, starlette, urllib3)
@git-steer
git-steer Bot force-pushed the security/fix-backend branch from c8ef4ca to 35139bd Compare June 25, 2026 11:39
@git-steer
git-steer Bot merged commit 30e0acd into main Jun 25, 2026
2 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Created by automation dependencies Dependency updates escalation:hard-stop needs-human-merge Held by ADR-005 functional-integrity gate security Security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants