Bump pytest from 9.0.2 to 9.0.3 - #87
Conversation
6736857 to
d228d7f
Compare
Security Vulnerability — No Patch Available Yetaieng-bot fixed all resolvable pip-audit findings, but one vulnerability cannot be fixed automatically because no patched version exists on PyPI:
What was fixed automaticallyThe following vulnerabilities were resolved in this PR:
Why CVE-2025-3000 cannot be auto-fixedCVE-2025-3000 affects Recommended next steps
CI will continue to fail on this CVE until it is resolved upstream or explicitly ignored. |
d228d7f to
0fd3666
Compare
Bump packages to address pip-audit findings: - pillow>=12.2.0 (CVE-2026-40192) - transformers>=5.0.0 (CVE-2026-1839) - torch>=2.12.0 (CVE-2025-3001, CVE-2026-4538/PYSEC-2026-139) - urllib3>=2.7.0 (PYSEC-2026-141, PYSEC-2026-142) - pip>=26.1 (CVE-2026-3219, CVE-2026-6357, PYSEC-2026-196) - python-dotenv>=1.2.2 (CVE-2026-28684) - idna>=3.15 (CVE-2026-45409) - pymdown-extensions>=10.21.3 (CVE-2026-46338) Note: torch CVE-2025-3000 (torch.jit.script memory corruption) has no fix available upstream and requires human review. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
openai 2.x rejects empty string API keys upfront; use a non-empty placeholder so VCR cassettes can still intercept the HTTP requests. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
76d221a to
2375328
Compare
|
Automated fix applied and PR merged The agentic fix loop successfully fixed this PR and merged it. ✓ Successfully fixed merge_conflict failures - Modified 2 files - Executed 806 agent actions - (571 info, 101 tool_call, 19 error, 82 tool_result, 33 reasoning) View detailed trace on dashboard | Raw trace AI Engineering Maintenance Bot |
Bumps pytest from 9.0.2 to 9.0.3.
Release notes
Sourced from pytest's releases.
Commits
a7d58d7Prepare release version 9.0.3089d981Merge pull request #14366 from bluetech/revert-14193-backport8127eafRevert "Fix: assertrepr_compare respects dict insertion order (#14050) (#14193)"99a7e60Merge pull request #14363 from pytest-dev/patchback/backports/9.0.x/95d8423bd...ddee02aMerge pull request #14343 from bluetech/cve-2025-71176-simple74eac69doc: Update training info (#14298) (#14301)f92dee7Merge pull request #14267 from pytest-dev/patchback/backports/9.0.x/d6fa26c62...7ee58acMerge pull request #12378 from Pierre-Sassoulas/fix-implicit-str-concat-and-d...37da870Merge pull request #14259 from mitre88/patch-4 (#14268)c34bfa3Add explanation for string context diffs (#14257) (#14266)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.