Skip to content

Commit d6fbc47

Browse files
chore(deps): bump mkdocs-material 9.7.0 -> 9.7.7 (CVE-2026-73295)
Patch-level upgrade closing the sole remaining pip-audit finding attributable to a project dependency (docs/dev-only, not shipped in the runtime). Sole remaining cause of CI red after 7ce0f60/a64256a9. Verified: poetry run pip-audit now reports only the pip bootstrap vulnerability (PYSEC-2026-3721), which CI's own "Upgrade pip in Poetry venv" step already resolves in that environment; pip itself is untouched here per scope. poetry run mkdocs build --clean exits 0. Lockfile diff is limited to mkdocs-material's own version/hash/ dependency-bound metadata plus the content-hash -- no unrelated package churn. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
1 parent a64256a commit d6fbc47

2 files changed

Lines changed: 10 additions & 10 deletions

File tree

‎poetry.lock‎

Lines changed: 9 additions & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎pyproject.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -143,7 +143,7 @@ httpx = "^0.28.1"
143143
ipython = "^8.12"
144144
anyio = "^4.11.0"
145145
mkdocs = "^1.6.1"
146-
mkdocs-material = "^9.7.0"
146+
mkdocs-material = "^9.7.7"
147147
vulture = "^2.14"
148148
pip-audit = "^2.10.1"
149149
bandit = "^1.9.2"

0 commit comments

Comments
 (0)