Bump vcrpy from 8.1.0 to 8.2.1 - #103
Conversation
aacecd5 to
3f301c0
Compare
Security Vulnerability Triage — aieng-botFixed the following pip-audit vulnerabilities by bumping dependencies:
nltk PYSEC-2026-597 — No Upstream FixNLTK 3.9.4 (the latest release) is vulnerable to a path traversal attack (PYSEC-2026-597). No patched version has been released to PyPI. The Once a patched nltk version is released, the ignore entry should be removed and Generated by aieng-bot |
Bumps [vcrpy](https://github.com/kevin1024/vcrpy) from 8.1.0 to 8.2.1. - [Release notes](https://github.com/kevin1024/vcrpy/releases) - [Changelog](https://github.com/kevin1024/vcrpy/blob/master/docs/changelog.rst) - [Commits](kevin1024/vcrpy@v8.1.0...v8.2.1) --- updated-dependencies: - dependency-name: vcrpy dependency-version: 8.2.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
- Bump tornado>=6.5.7 to fix CVE-2026-49854, CVE-2026-49853, CVE-2026-49855, GHSA-pw6j-qg29-8w7f - Bump transformers>=5.3.0 to fix CVE-2026-4372 - Add msgpack>=1.2.1 to fix GHSA-6v7p-g79w-8964 (was transitive dep) - Add PYSEC-2026-597 (nltk 3.9.4, no upstream fix) to CI ignore list Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
3b4042d to
dc4173e
Compare
|
Automated fix applied and PR merged The agentic fix loop successfully fixed this PR and merged it. ✓ Successfully fixed security failures - Modified 2 files - Executed 651 agent actions - (444 info, 88 tool_call, 16 error, 67 tool_result, 35 reasoning, 1 action) View detailed trace on dashboard | Raw trace AI Engineering Maintenance Bot |
Bumps vcrpy from 8.1.0 to 8.2.1.
Release notes
Sourced from vcrpy's releases.
Changelog
Sourced from vcrpy's changelog.
... (truncated)
Commits
8531203Release v8.2.1045acb1Use a safe YAML loader for cassettes to prevent code executionde43f46Fix lint failures from merged PRs (codespell + ruff UP032)514c374Validate record_mode and raise a clear error on invalid valuesb736caddocs: recommend pytest-recording over unmaintained pytest-vcr06758c9Release v8.2.06554837Add env proxy cassette regression test (#994)62cf5e1Accounting for modified requests when storing played cassettes, with a test (...13f201amake url available in VCRHTTPResponse (#976)d57b553improve error message on repeated requestt (#985)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.