Skip to content

fix(deps): patch Dependabot CVEs across frontend and evaluation - #317

Merged
luarss merged 1 commit into
The-OpenROAD-Project:fix/dependabot-cvesfrom
luarss:fix/dependabot-cves
Jul 25, 2026
Merged

fix(deps): patch Dependabot CVEs across frontend and evaluation#317
luarss merged 1 commit into
The-OpenROAD-Project:fix/dependabot-cvesfrom
luarss:fix/dependabot-cves

Conversation

@luarss

@luarss luarss commented Jul 25, 2026

Copy link
Copy Markdown
Collaborator

Bump vulnerable dependencies to their first patched versions:

npm (frontend/nextjs-frontend):

pip (frontend/uv.lock):

  • pillow 12.2.0 -> 12.3.0
  • gitpython 3.1.50 -> 3.1.55
  • pyasn1 0.6.3 -> 0.6.4

pip (evaluation/uv.lock):

  • pillow 12.2.0 -> 12.3.0

Bump vulnerable dependencies to their first patched versions:

npm (frontend/nextjs-frontend):
- next 16.2.6 -> 16.2.11 (GHSA-89xv-2m56-2m9x et al.)
- sharp -> 0.35.3 via resolution (GHSA-f88m-g3jw-g9cj)
- brace-expansion -> 5.0.8 via resolution (GHSA-3jxr-9vmj-r5cp)

pip (frontend/uv.lock):
- pillow 12.2.0 -> 12.3.0
- gitpython 3.1.50 -> 3.1.55
- pyasn1 0.6.3 -> 0.6.4

pip (evaluation/uv.lock):
- pillow 12.2.0 -> 12.3.0

Signed-off-by: Jack Luar <jluar@precisioninno.com>
@luarss
luarss merged commit 14e406b into The-OpenROAD-Project:fix/dependabot-cves Jul 25, 2026
6 checks passed
@luarss
luarss deleted the fix/dependabot-cves branch July 25, 2026 11:17
@luarss
luarss restored the fix/dependabot-cves branch July 27, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant