Skip to content

fix(deps): bump urllib3 to 2.8.0 in requirements-qt - #152

Merged
rldyourmnd merged 2 commits into
mainfrom
fix/urllib3-qt-cve
Oct 4, 2026
Merged

rldyourmnd merged 2 commits into
mainfrom
fix/urllib3-qt-cve

Conversation

@rldyourmnd

Copy link
Copy Markdown
Contributor

Summary

  • Recompile requirements-qt.txt with uv pip compile --upgrade-package urllib3: the osv-scan runtime fixture flagged PYSEC-2026-4176 (6.9) and PYSEC-2026-4177 (8.9) on the pinned urllib3 2.7.0 — both fixed in 2.8.0
  • CI feedback: ci-workflows#151

Test plan

  • Fixture osv-scan lane expected green (urllib3 2.8.0 has no open advisories)

@github-actions github-actions Bot added ci and removed ci labels Oct 4, 2026
@rldyourmnd
rldyourmnd force-pushed the fix/urllib3-qt-cve branch 2 times, most recently from fd9550a to 03ce3ab Compare October 4, 2026 11:27
uv pip compile --upgrade-package urllib3; fixes PYSEC-2026-4176/-4177 on 2.7.0.

Signed-off-by: Danil Silantyev <danil@nddev.it.com>
qt-ci.yml LOCK_SHA256 and tools.yml lock_sha256 must match requirements-qt.txt.

Signed-off-by: Danil Silantyev <danil@nddev.it.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant