Skip to content

Commit 28e3618

Browse files
committed
v1.34.6 — dependency security refresh (pip-audit clean)
Pin transitive deps flagged by pip-audit that dependabot cannot see (not in requirements.txt): pyjwt 2.13.0 (6 PYSEC), pydantic-settings 2.14.2 (GHSA-4xgf-cpjx-pc3j), idna 3.15 (PYSEC-2026-215), msgpack 1.2.1 (GHSA-6v7p-g79w-8964). Rides on top of dependabot bumps #55-#58 (fastapi 0.138.1, mcp 1.28.1, click 8.4.2, phonenumbers 9.0.33). 2602 pytest passed, ruff clean, pip-audit: no known vulnerabilities.
1 parent 7c51cb1 commit 28e3618

2 files changed

Lines changed: 5 additions & 1 deletion

File tree

‎app/config.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
from pydantic import Field
1313
from pydantic_settings import BaseSettings, SettingsConfigDict
1414

15-
VERSION = "1.34.5"
15+
VERSION = "1.34.6"
1616
MCP_TOOL_COUNT = 54 # Faz-2: +contrast_scan (website-scanner composite)
1717
MCP_RESOURCE_COUNT = 7 # v1.23.0: atlas+d3fend+cwe (4 templates + 3 catalogs)
1818
MCP_PROMPT_COUNT = 3 # v1.23.0: security_audit, vulnerability_check, contrast_triage

‎requirements.txt‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,15 @@ jinja2==3.1.6
66
python-multipart==0.0.32
77
dnspython==2.8.0
88
httpx==0.28.1
9+
idna==3.15
10+
msgpack==1.2.1
911
pytest==9.1.1
1012
phonenumbers==9.0.33
1113
cryptography==49.0.0
1214
cvss==3.6
1315
mcp==1.28.1
16+
pyjwt==2.13.0
17+
pydantic-settings==2.14.2
1418
PyYAML>=6.0.3
1519
tldextract>=5.3.1
1620
beautifulsoup4>=4.15.0

0 commit comments

Comments
 (0)