Skip to content

[MAINT]: Bump transitive dependencies with known vulnerabilities - #199

Merged
Spencer Schoenberg (spencrr) merged 1 commit into
microsoft:mainfrom
spencrr:agents/openssf-scanner-vulnerability-fix
Oct 1, 2026
Merged

Spencer Schoenberg (spencrr) merged 1 commit into
microsoft:mainfrom
spencrr:agents/openssf-scanner-vulnerability-fix

Conversation

@spencrr

Copy link
Copy Markdown
Contributor

Description

Resolves the 23 OSV advisories OpenSSF Scorecard reports against uv.lock by bumping the affected transitive dependencies:

  • pyjwt 2.13.0 → 2.15.1
  • urllib3 2.7.0 → 2.8.0
  • virtualenv 21.5.1 → 21.14.1 (+ python-discovery 1.4.2 → 1.6.1)
  • gitpython 3.1.59 → 3.2.0
  • datasets 5.0.0 → 5.0.1

Breaking changes

None.

Checklist

  • pre-commit run --all-files passes
  • Tests added or updated for changes (not applicable; uv run pytest tests/unit tests/scripts passes)
  • Documentation updated (not applicable; lockfile-only change; uv run mkdocs build --strict passes)

Resolves the 23 OSV advisories flagged by OpenSSF Scorecard against uv.lock.
@spencrr
Spencer Schoenberg (spencrr) requested a review from a team October 1, 2026 00:15
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@spencrr
Spencer Schoenberg (spencrr) merged commit c54b13f into microsoft:main Oct 1, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants