Skip to content

fix(deps): upgrade soupsieve to 2.10 for security fixes - #242

Merged
matrixise merged 1 commit into
masterfrom
security/upgrade-soupsieve
Sep 24, 2026
Merged

matrixise merged 1 commit into
masterfrom
security/upgrade-soupsieve

Conversation

@matrixise

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades soupsieve from 2.8.3 to 2.10
  • Resolves 4 open Dependabot alerts (high/medium): polynomial ReDoS in the IDENTIFIER/VALUE selector sub-patterns and in the whitespace/comment trimming regex, memory exhaustion via large comma-separated selector lists, and a general ReDoS in the selector parser
  • Advisories: GHSA-gjv8-xp57-g29c, GHSA-j934-xhv5-fg8f, GHSA-2wc2-fm75-p42x, GHSA-836r-79rf-4m37

Test plan

  • python manage.py test pythonie --settings=pythonie.settings.tests (SQLite, 7/7 passed)
  • ruff check pythonie clean

@matrixise
matrixise force-pushed the security/upgrade-soupsieve branch 2 times, most recently from 2f671c7 to 9ffd369 Compare September 24, 2026 06:36
Resolves multiple high/medium severity Dependabot alerts: polynomial
ReDoS in the IDENTIFIER/VALUE selector sub-patterns and in the
whitespace/comment trimming regex, memory exhaustion via large
comma-separated selector lists, and a general ReDoS in the selector
parser.

GHSA-gjv8-xp57-g29c, GHSA-j934-xhv5-fg8f, GHSA-2wc2-fm75-p42x,
GHSA-836r-79rf-4m37

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@matrixise
matrixise force-pushed the security/upgrade-soupsieve branch from 9ffd369 to ab7b028 Compare September 24, 2026 06:37
@matrixise
matrixise merged commit c6a1f49 into master Sep 24, 2026
0 of 2 checks passed
@matrixise
matrixise deleted the security/upgrade-soupsieve branch September 24, 2026 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant