Bump tornado from 6.5.5 to 6.5.7 - #101
Conversation
03a242c to
a8eb66a
Compare
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerabilities reported by pip-audit, but cannot fix them automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in What was fixed in this runaieng-bot applied fixes for the other pip-audit findings:
Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
646b902 to
a4b03d3
Compare
Bumps [tornado](https://github.com/tornadoweb/tornado) from 6.5.5 to 6.5.7. - [Changelog](https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst) - [Commits](tornadoweb/tornado@v6.5.5...v6.5.7) --- updated-dependencies: - dependency-name: tornado dependency-version: 6.5.7 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…ties - msgpack>=1.2.1 to fix GHSA-6v7p-g79w-8964 - transformers>=5.3.0 to fix CVE-2026-4372 - vcrpy>=8.2.1 to fix GHSA-rpj2-4hq8-938g Note: nltk PYSEC-2026-597 has no patched version yet; human review required. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
…lity openai>=2.34.0 introduced strict credential enforcement that rejects empty OPENAI_API_KEY values at client initialization time, breaking e2e tests that rely on VCR cassettes with an intentionally empty API key placeholder. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
- Remove duplicate msgpack entry (main already has msgpack>=1.2.1) - Revert openai<2.34.0 constraint (main fixed test_e2e to use non-empty API key placeholder, so openai 2.44.0 is compatible) Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
d2a7657 to
ee1a1ca
Compare
|
Automated fix applied and PR merged The agentic fix loop successfully fixed this PR and merged it. ✓ Successfully fixed merge_only failures - Modified 1 files - Executed 1990 agent actions - (1533 info, 191 tool_call, 44 error, 151 tool_result, 70 reasoning, 1 action) View detailed trace on dashboard | Raw trace AI Engineering Maintenance Bot |
Bumps tornado from 6.5.5 to 6.5.7.
Changelog
Sourced from tornado's changelog.
... (truncated)
Commits
48fc2d4Merge pull request #3633 from bdarnell/curl-reset-654ae1dddRelease notes and version bump for 6.5.73154caacurl_httpclient: Reset the curl object before putting it on the freelist7d869c0Merge pull request #3631 from bdarnell/cve-links288241fdocs: Use the correct link syntax8da981cdocs: Add CVE links to 6.5.6 release notesaba2569Merge pull request #3626 from bdarnell/fixes-656a24b260httpclient_test: Accept an additional error message varianta74240aRelease notes and version bump for 6.5.6.e8fc7edsimple_httpclient: Strip auth headers on cross-origin redirectsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.