Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 8 additions & 6 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -21,18 +21,18 @@ dependencies = [
"pydantic-settings>=2.14.2", # GHSA-4xgf-cpjx-pc3j: NestedSecretsSettingsSource symlink traversal and size bypass fixed in 2.14.2
"pydantic-ai-slim[logfire]>=1.26.0",
"scikit-learn>=1.7.0",
"urllib3>=2.7.0", # CVE-2026-44431/44432: sensitive header forwarding and decompression bomb fixed in 2.7.0
"urllib3>=2.8.0", # CVE-2026-44431/44432: sensitive header forwarding and decompression bomb fixed in 2.7.0; CVE-2026-97687/97688/97689: HTTPS proxy TLS confusion, Deflate infinite loop, chunked-response DoS fixed in 2.8.0
"openpyxl>=3.1.5",
"authlib>=1.7.1", # CVE-2026-28802: alg:none JWT bypass fixed in 1.6.7; GHSA-jj8c-mmj3-mmgv: CSRF protection bypass fixed in 1.6.11
"cryptography>=50.0.0", # CVE-2026-34073: DNS name constraint bypass fixed in 46.0.6; CVE-2026-39892: buffer overflow fixed in 46.0.7; GHSA-537c-gmf6-5ccf: fixed in 48.0.1; CVE-2026-69247: Bleichenbacher oracle via PKCS7 decryption fixed in 50.0.0
"filelock>=3.20.3",
"filelock>=3.24.2", # required by virtualenv>=21.7.13 (PYSEC-2026-4011/4013 fixes)
"pyasn1>=0.6.4", # CVE-2026-30922: DoS via uncontrolled recursion fixed in 0.6.3
"virtualenv>=20.36.1",
"virtualenv>=21.7.13", # PYSEC-2026-4011: unverified wheel downloads fixed in 21.7.12; PYSEC-2026-4013: shell injection in activate script fixed in 21.7.13
"tenacity>=9.1.2",
"certifi>=2026.1.4",
"pypdf>=6.7.5", # CVE-2026-28804: ASCIIHexDecode DoS fixed in 6.7.5
"PyYAML>=6.0.0",
"litellm>=1.82.4",
"litellm>=1.88.6", # CVE-2026-84377: fixed in 1.88.6
"google-generativeai>=0.8.6",
"openai-agents>=0.7.0",
"pillow>=12.3.0", # CVE-2026-40192: FITS decompression bomb fixed in 12.2.0; PYSEC-2026-2253/2254/2255/2256/2257: multiple vulnerabilities fixed in 12.3.0
Expand Down Expand Up @@ -91,9 +91,11 @@ override-dependencies = [
"mistune>=3.3.0", # CVE-2026-33079/CVE-2026-44897: ReDoS and heading ID XSS fixed in 3.2.1; CVE-2026-49851/PYSEC-2026-2215/PYSEC-2026-2652: CPU exhaustion DoS via recursive include and O(n²) parse_link_text fixed in 3.3.0
"notebook>=7.5.6", # CVE-2026-40171: stored XSS allowing auth token theft fixed in 7.5.6
"starlette>=1.3.1", # PYSEC-2026-161/GHSA-86qp-5c8j-p5mr: missing Host header validation bypasses path-based security checks fixed in 1.0.1; CVE-2026-54282/54283: fixed in 1.3.0/1.3.1
"urllib3>=2.7.0", # CVE-2026-44431/44432: sensitive header forwarding and decompression issues fixed in 2.7.0; aieng-platform-onboard pins 2.6.3
"urllib3>=2.8.0", # CVE-2026-44431/44432: sensitive header forwarding and decompression issues fixed in 2.7.0; CVE-2026-97687/97688/97689: HTTPS proxy TLS confusion, Deflate infinite loop, chunked-response DoS fixed in 2.8.0; aieng-platform-onboard pins 2.6.3
"virtualenv>=21.7.13", # PYSEC-2026-4011: unverified wheel downloads fixed in 21.7.12; PYSEC-2026-4013: shell injection in activate script fixed in 21.7.13; aieng-platform-onboard pins 20.36.1
"filelock>=3.24.2", # required by virtualenv>=21.7.13; aieng-platform-onboard pins 3.20.3
"bleach>=6.4.0", # GHSA-gj48-438w-jh9v/GHSA-8rfp-98v4-mmr6: fixed in 6.4.0
"tornado>=6.5.7", # GHSA-pw6j-qg29-8w7f: CurlAsyncHTTPClient credential leak fixed in 6.5.7
"tornado>=6.5.9", # GHSA-pw6j-qg29-8w7f: CurlAsyncHTTPClient credential leak fixed in 6.5.7; GHSA-chx6-46f5-w4vp/c2m8-h5v5-343r/3hv7-mjh2-fv65: fixed in 6.5.9
"msgpack>=1.2.1", # GHSA-6v7p-g79w-8964: DoS via SEGV when Unpacker is reused after error fixed in 1.2.1
"gradio>=6.16.0", # PYSEC-2026-2179: path traversal in FileExplorer component fixed in 6.16.0
"httplib2>=0.32.0", # PYSEC-2026-3444: decompression bomb / OOM via gzip/deflate response fixed in 0.32.0
Expand Down
Loading
Loading