Bump urllib3 from 2.6.3 to 2.7.0 - #91
dependabot[bot] wants to merge 2 commits into
Conversation
73871a8 to
b183300
Compare
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability exists in What was fixed automaticallyThe following vulnerabilities were successfully patched in this PR:
Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
b183300 to
6e25842
Compare
- pillow: >=12.1.1 -> >=12.2.0 (CVE-2026-40192, CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311) - pip: >=26.0 -> >=26.1 (CVE-2026-3219, CVE-2026-6357) - pytest: >=8.x -> >=9.0.3 (CVE-2025-71176) - python-dotenv: >=1.0.0 -> >=1.2.2 (CVE-2026-28684) - transformers: >=4.30.0 -> >=5.0.0 (CVE-2026-1839) - idna: add >=3.15 (CVE-2026-45409) - pymdown-extensions: add >=10.21.3 (CVE-2026-46338) - torch: >=2.0.0 -> >=2.10.0 (CVE-2025-3001) Note: torch CVE-2025-3000 remains in torch 2.12.0 (latest) with no fix version published upstream yet — requires human review. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
The openai library now rejects empty string API keys at client initialization. Since the test uses VCR cassettes to intercept all HTTP calls, a dummy key is sufficient. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
5e3b658 to
ddcfadf
Compare
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedPYSEC-2026-597 is a path traversal vulnerability in A fix requires the upstream NLTK maintainers to release a new version. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically. Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
|
Automated fix applied and PR merged The agentic fix loop successfully fixed this PR and merged it. ✓ Successfully fixed merge_conflict failures - Modified 2 files - Executed 640 agent actions - (400 info, 105 tool_call, 25 error, 82 tool_result, 28 reasoning) View detailed trace on dashboard | Raw trace AI Engineering Maintenance Bot |
|
A newer version of urllib3 exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Bumps urllib3 from 2.6.3 to 2.7.0.
Release notes
Sourced from urllib3's releases.
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
9a950b9Release 2.7.05ec0de4Merge commit from fork2bdcc44Merge commit from forkf45b0dfFix a misleading example forProxyManager(#4970)577193cSwitch to nightly PyPy3.11 in CI for now (#4984)e90af45Avoid infinite loop inHTTPResponse.read_chunkedwhenamt=0(#4974)67ed74fBump dev dependencies (#4972)3abd481Upgrade mypy to version 1.20.2 (#4978)2b8725dDrop support for EOL PyPy3.10 (#4979)2944b2aUpgradesetup-chromeandsetup-firefoxto fix warnings (#4973)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.