Skip to content

Upgrade libraries to resolve Dependabot alerts#101

Merged
iamvukasin merged 1 commit intomainfrom
upgrade-libs
Apr 9, 2026
Merged

Upgrade libraries to resolve Dependabot alerts#101
iamvukasin merged 1 commit intomainfrom
upgrade-libs

Conversation

@iamvukasin
Copy link
Copy Markdown
Collaborator

No description provided.

@iamvukasin iamvukasin requested review from a team April 8, 2026 08:39
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​pillow@​12.1.1 ⏵ 12.2.086 +110010010070
Updatedpypi/​web3@​7.14.0 ⏵ 7.15.092 -1100 +2100100100
Updatedpypi/​aiohttp@​3.13.3 ⏵ 3.13.597 +1100 +10100100100
Updatedpypi/​requests@​2.32.5 ⏵ 2.33.199 +1100 +2100100100
Updatedpypi/​json5@​0.12.1 ⏵ 0.14.0100100100100100

View full report

Copy link
Copy Markdown
Contributor

@QEDK QEDK left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you also add:

[tool.uv]
exclude-newer = "1 week"

@iamvukasin
Copy link
Copy Markdown
Collaborator Author

I wanted to add it, but it will conflict with web3==7.15.0 since it was released 6 days ago. We can wait one more day before updating the config.

@QEDK
Copy link
Copy Markdown
Contributor

QEDK commented Apr 8, 2026

I wanted to add it, but it will conflict with web3==7.15.0 since it was released 6 days ago. We can wait one more day before updating the config.

We can address via another PR I think.

Copy link
Copy Markdown
Contributor

@QEDK QEDK left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@iamvukasin iamvukasin merged commit 77b996a into main Apr 9, 2026
6 checks passed
@iamvukasin iamvukasin deleted the upgrade-libs branch April 9, 2026 19:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants