Bump idna from 3.11 to 3.15 - #799
Conversation
PR SummaryLow Risk Overview This pulls in upstream security and robustness fixes, including mitigations for CVE-2026-45409 (oversized-input handling that could bypass earlier CVE-2024-3651 protections), earlier DNS label length enforcement, and Unicode/classification updates. No application code changes—only the pinned version and lockfile metadata (including Reviewed by Cursor Bugbot for commit 609934a. Bugbot is set up for automated code reviews on this repo. Configure here. |
fe98107 to
bb40dae
Compare
bb40dae to
55853f9
Compare
55853f9 to
0499b17
Compare
|
@dependabot rebase |
0499b17 to
273a86f
Compare
|
@dependabot rebase |
Bumps [idna](https://github.com/kjd/idna) from 3.11 to 3.15. - [Release notes](https://github.com/kjd/idna/releases) - [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md) - [Commits](kjd/idna@v3.11...v3.15) --- updated-dependencies: - dependency-name: idna dependency-version: '3.15' dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
273a86f to
609934a
Compare
Bumps idna from 3.11 to 3.15.
Changelog
Sourced from idna's changelog.
Commits
af30a09Release 3.1530314d4Pre-release 3.15rc005d4b21Merge pull request #237 from kjd/convert-docs-to-markdown2987fdbConvert README and HISTORY from reStructuredText to Markdown59fa800Merge pull request #236 from kjd/dependabot/github_actions/actions-f3e34333eadef6983Merge branch 'master' into dependabot/github_actions/actions-f3e34333eabbd8004Merge pull request #234 from StanFromIreland/patch-1edd07c0Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group5557db0Merge branch 'master' into patch-1f11746cMerge pull request #235 from StanFromIreland/patch-2