Skip to content

Conversation

mehtarac
Copy link
Member

Description

Updating the minimum version of pydantic dependencies to 2.4.0. Version 2.0 is known to be vulnerable to a REDoS (Regular Expression Denial of Service) attack, as documented by SNYK. The first non-vulnerable version is 2.4.0.

Related Issues

Documentation PR

Type of Change

Other (please describe): Updating minimum dependency

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@mehtarac mehtarac merged commit e4879e1 into strands-agents:main Aug 25, 2025
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants