Skip to content

fix(deps): resolve overdue critical/high Dependabot alerts#11

Merged
YushaArif99 merged 1 commit into
mainfrom
fix/dependabot-high-critical-overdue
Jun 15, 2026
Merged

fix(deps): resolve overdue critical/high Dependabot alerts#11
YushaArif99 merged 1 commit into
mainfrom
fix/dependabot-high-critical-overdue

Conversation

@YushaArif99

Copy link
Copy Markdown
Member

Summary

  • Bump h11 to 0.16.0 (critical CVE-2025-43859)
  • Refresh poetry.lock so pillow, urllib3, aiohttp, setuptools, and black meet current advisory floors

Test plan

  • Dependabot critical/high alerts close on merge
  • Vanta GitHub Repo critical/high tests re-scan green

Bump h11 to 0.16.0 and refresh poetry.lock so transitive Python deps
(pillow, urllib3, aiohttp, setuptools) meet current advisory floors.
@mintlify

mintlify Bot commented Jun 15, 2026

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
unify-d270b1a5 🟢 Ready View Preview Jun 15, 2026, 10:21 AM

💡 Tip: Enable Workflows to automatically generate PRs for you.

@juliagsy juliagsy left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm!

@YushaArif99 YushaArif99 merged commit 11e6e95 into main Jun 15, 2026
1 of 3 checks passed
@YushaArif99 YushaArif99 deleted the fix/dependabot-high-critical-overdue branch June 15, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants