From ae367e8dab3e1683b2b98e043904667d121eb7f7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phane=20Wirtel?= Date: Thu, 24 Sep 2026 07:51:47 +0200 Subject: [PATCH] fix(deps): upgrade pip to 26.2.1 for security fix (dev only) Resolves a medium severity Dependabot alert: pip would incorrectly handle doubly-encoded package URLs from indexes. Transitive dev dependency via pip-api (pip-audit). GHSA-qwm4-qh6w-59xr Co-Authored-By: Claude Sonnet 5 --- requirements/dev.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements/dev.txt b/requirements/dev.txt index 2bc96ea..0ed89db 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -149,7 +149,7 @@ pillow-heif==1.3.0 # via # -c requirements/main.txt # willow -pip==26.1.2 +pip==26.2.1 # via pip-api pip-api==0.0.34 # via pip-audit