Skip to content

Bump aiohttp and requests to fix 21 Dependabot alerts#192

Merged
bh2smith merged 1 commit intomainfrom
chore/bump-aiohttp-requests
May 5, 2026
Merged

Bump aiohttp and requests to fix 21 Dependabot alerts#192
bh2smith merged 1 commit intomainfrom
chore/bump-aiohttp-requests

Conversation

@bh2smith
Copy link
Copy Markdown
Member

@bh2smith bh2smith commented May 5, 2026

Summary

  • Bumps aiohttp from ~=3.12.15 to ~=3.13.4 (locked at 3.13.5) — resolves 20 security alerts including 1 high severity
  • Bumps requests from ~=2.32.5 to ~=2.33.0 (locked at 2.33.1) — resolves 1 medium severity alert
  • Both are pyproject.toml pin changes (minor version bumps)

Alerts resolved

aiohttp (20 alerts):

requests (1 alert):

Remaining after this PR

Only 2 low/medium alerts for the uv build tool itself — requires upgrading the uv binary, no code changes.

Test plan

  • make check (format + lint + mypy --strict)
  • make test-unit (72 tests pass)
  • CI passes (unit + E2E)

- aiohttp ~=3.12.15 → ~=3.13.4 (resolves 20 alerts, locked at 3.13.5)
- requests ~=2.32.5 → ~=2.33.0 (resolves 1 alert, locked at 2.33.1)
@bh2smith bh2smith merged commit a9db052 into main May 5, 2026
2 checks passed
@bh2smith bh2smith deleted the chore/bump-aiohttp-requests branch May 5, 2026 16:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants