v2026.6.6
Security
- Resolved all 30 open dependency vulnerability alerts (15 Trivy code-scanning + 15 Dependabot) by bumping four packages together in
uv.lock. Each package was flagged independently, but no single Dependabot PR could pass thepip-auditCI gate because the gate fails while any vulnerable package remains; bumping all four in one change is what clears it.- Bumped
cryptographyto 49.0.0 (GHSA-537c-gmf6-5ccf). Thevaultandvault-keyringextras now requirecryptography>=48. - Bumped
starletteto 1.3.1 (CVE-2026-54282, CVE-2026-54283). - Bumped
aiohttpto 3.14.1 (CVE-2026-54273 through CVE-2026-54280). - Bumped
python-multipartto 0.0.32 (CVE-2026-53537, CVE-2026-53538, CVE-2026-53539, CVE-2026-53540).
- Bumped