[Snyk] Security upgrade urllib3 from 2.0.7 to 2.8.0 - #91
HeyItsGilbert wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-20302846
|
This upgrade of Breaking Changes:
Other Notable Changes:
Recommendation:
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Version 2.8.0 exists and is compatible with the documentation workflow’s Python 3.11 runtime.
Review effort: Balanced
Findings: None
What changed in this PR
Upgrades the indirect urllib3 dependency to remediate the identified vulnerability.
Changes:
- Raises the minimum
urllib3version from 2.6.3 to 2.8.0.
| File | Description |
|---|---|
docs/requirements.txt |
Updates the documentation dependency constraint. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Test Results370 tests 359 ✅ 6s ⏱️ Results for commit 929e79b. |
Snyk has created this PR to fix 1 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
docs/requirements.txtBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling