Commit 28e3618
committed
v1.34.6 — dependency security refresh (pip-audit clean)
Pin transitive deps flagged by pip-audit that dependabot cannot see
(not in requirements.txt): pyjwt 2.13.0 (6 PYSEC), pydantic-settings
2.14.2 (GHSA-4xgf-cpjx-pc3j), idna 3.15 (PYSEC-2026-215), msgpack
1.2.1 (GHSA-6v7p-g79w-8964). Rides on top of dependabot bumps #55-#58
(fastapi 0.138.1, mcp 1.28.1, click 8.4.2, phonenumbers 9.0.33).
2602 pytest passed, ruff clean, pip-audit: no known vulnerabilities.1 parent 7c51cb1 commit 28e3618
2 files changed
Lines changed: 5 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
9 | 11 | | |
10 | 12 | | |
11 | 13 | | |
12 | 14 | | |
13 | 15 | | |
| 16 | + | |
| 17 | + | |
14 | 18 | | |
15 | 19 | | |
16 | 20 | | |
| |||
0 commit comments