|
|
@@ -106,7 +106,7 @@ psutil>=6.0.0
|
|
|
tzdata>=2024.1; sys_platform == "win32"
|
|
|
|
|
|
# Authentication
|
|
|
-PyJWT>=2.13.0
|
|
|
+PyJWT>=2.15.1
|
|
|
passlib[bcrypt]>=1.7.4
|
|
|
ldap3>=2.9.0
|
|
|
pyotp>=2.9.0
|
|
|
@@ -137,11 +137,11 @@ certifi>=2024.2.2
|
|
|
# version detection and logs a warning at startup.
|
|
|
curl_cffi>=0.7.0
|
|
|
|
|
|
-# Transitive pin: urllib3 2.6.3 has CVE-2026-44431 and CVE-2026-44432;
|
|
|
-# 2.7.0+ is the fixed release. Direct pin here because none of our
|
|
|
-# top-level deps require >=2.7.0 yet, so without this the resolver
|
|
|
-# would silently keep installing the vulnerable 2.6.x line.
|
|
|
-urllib3>=2.7.0
|
|
|
+# Transitive pin: urllib3 2.7.0 has three advisories (streaming
|
|
|
+# decompression limits, proxy TLS settings); 2.8.0 is the fixed release.
|
|
|
+# Direct pin here because none of our top-level deps require >=2.8.0 yet,
|
|
|
+# so without this the resolver would silently keep the vulnerable line.
|
|
|
+urllib3>=2.8.0
|
|
|
|
|
|
# Transitive of fastapi. starlette 1.0.0 has PYSEC-2026-161; 1.1.x has
|
|
|
# CVE-2026-54282/54283; 1.3.1 is the fixed release. fastapi's range still
|