- requests: bump minimum to >=2.33.0 (CVE temp file reuse) - streamlit: bump minimum to >=1.54.0 (SSRF/NTLM exposure) - picomatch: add npm override for >=2.3.2/<3 || >=4.0.4 (ReDoS + method injection) - flatted: tighten override to >=3.4.2 (prototype pollution) - yaml: add npm override for >=1.10.3 (stack overflow) - rustls-webpki: cargo update to 0.103.10 (CRL distribution point) - Also fix pre-existing ty lint error in metrics.py (type: ignore for Windows resource import) - Pygments: no patch available (<=2.19.2 vulnerable, no fix released) |
||
|---|---|---|
| .. | ||
| benchmarks | ||
| hindsight_dev | ||
| upgrade_tests | ||
| pyproject.toml | ||
| README.md | ||