Skip to content

fix: upgrade uv to resolve Dependabot security alerts#194

Merged
bh2smith merged 1 commit intomainfrom
fix/upgrade-uv-security
May 6, 2026
Merged

fix: upgrade uv to resolve Dependabot security alerts#194
bh2smith merged 1 commit intomainfrom
fix/upgrade-uv-security

Conversation

@bh2smith
Copy link
Copy Markdown
Member

@bh2smith bh2smith commented May 5, 2026

Summary

uv is a transitive dev dependency via tox-uv, so this only affects CI — no runtime impact on SDK users.

Test plan

  • CI passes (lock file change only)

Fixes Dependabot alerts #2 (ZIP payload obfuscation, medium) and
#30 (arbitrary file deletion via RECORD entries, low).
@bh2smith bh2smith requested a review from belen-pruvost May 5, 2026 16:56
@bh2smith bh2smith merged commit ac6b5fe into main May 6, 2026
2 checks passed
@bh2smith bh2smith deleted the fix/upgrade-uv-security branch May 6, 2026 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants