Skip to content

build: refresh vulnerable dependencies while retaining Python 3.9 - #317

Open
krowvin wants to merge 1 commit into
mainfrom
fix/refresh-vulnerable-dependencies
Open

build: refresh vulnerable dependencies while retaining Python 3.9#317
krowvin wants to merge 1 commit into
mainfrom
fix/refresh-vulnerable-dependencies

Conversation

@krowvin

@krowvin krowvin commented Sep 11, 2026

Copy link
Copy Markdown
Collaborator

Refresh locked idna, urllib3, setuptools, filelock, and virtualenv versions while retaining Python 3.9 support and the existing dependency constraints.

Comparing the updated lockfile with GitHub's current advisory ranges removes eight of the fifteen open dependency alerts: #7, #9, #11, #12, #13, #15, #16, and #22. Seven remain (#14, #17, #19, #20, #21, #23, #24); their fixed releases require Python 3.10 or newer, and the lockfile still includes affected versions needed for Python 3.9 compatibility. This is a partial dependency cleanup, not a claim that all vulnerabilities are resolved.

Validation: Poetry lock consistency and a fresh local install pass, as do 98 mock/doctest tests and strict mypy locally. All eight PR checks pass, including Python 3.9/latest unit tests, code checks, CodeQL, and SonarCloud. The eight-alert reduction is based on comparing the lockfile with GitHub advisory ranges; GitHub will reassess default-branch alerts after merge.

@sonarqubecloud

Copy link
Copy Markdown

@krowvin
krowvin requested a review from msweier September 11, 2026 00:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant