Skip to content

chore(deps): resolve high-severity Dependabot alerts (pyasn1, brace-expansion) - #1222

Open
lfnovo wants to merge 1 commit into
mainfrom
chore/dependabot-highs
Open

chore(deps): resolve high-severity Dependabot alerts (pyasn1, brace-expansion)#1222
lfnovo wants to merge 1 commit into
mainfrom
chore/dependabot-highs

Conversation

@lfnovo

@lfnovo lfnovo commented Jul 25, 2026

Copy link
Copy Markdown
Owner

Resolves the three open high-severity Dependabot alerts:

  • pyasn1 ≤ 0.6.3 → 0.6.4 in uv.lock (two alerts, same package)
  • brace-expansion 1.1.15 → 1.1.16 in the frontend — the version was pinned via the overrides block in package.json (from a previous advisory), so the pin itself is bumped and the lockfile regenerated

Validation: npm run build green, backend pytest 637 passed. No application code changes.

Review in cubic

Resolves the three open high-severity Dependabot alerts (two pyasn1
entries in uv.lock, one brace-expansion in the frontend lockfile pinned
via overrides).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant