Skip to content

Update pyproject.toml to avoid h11 dependency security issue - #1008

Merged
lovelydinosaur merged 3 commits into
encode:masterfrom
ljdelavega:patch-1
Apr 24, 2025
Merged

Update pyproject.toml to avoid h11 dependency security issue#1008
lovelydinosaur merged 3 commits into
encode:masterfrom
ljdelavega:patch-1

Conversation

@ljdelavega

Copy link
Copy Markdown
Contributor

To address the Critical-level CVE:

GHSA-vqfr-h8mv-ghfj

Summary

Checklist

  • I understand that this PR may be closed in case there was no previous discussion. (This doesn't apply to typos!)

Comment threadpyproject.toml Outdated

@lukehsiaolukehsiao left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My approval means nothing, but thanks for making this PR!

@alexpdp7alexpdp7 mentioned this pull request Apr 24, 2025
Comment threadpyproject.toml Outdated

@techgauntechgaun left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

came exactly for this, could we get this out asap? would appreciate it :)

@kingbuzzmankingbuzzman left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Kinda blocked by this..

@joanise

Copy link
Copy Markdown

Waiting on this to resolve the issue for our project too. I recommend accepting @lkasser1 's suggestion before merging, but we don't depend on that.

Co-authored-by: Lucas Kasser <lkasser8@gmail.com>
@lovelydinosaur

Copy link
Copy Markdown
Contributor

Thanks.

Aside; request contributors to not unnecessarily pile on in issues please. The initial prompt is sufficient.

@lovelydinosaur
lovelydinosaur merged commit d1e17c5 into encode:masterApr 24, 2025
@lovelydinosaurlovelydinosaur mentioned this pull request Apr 24, 2025
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@ljdelavega@joanise@lovelydinosaur@kingbuzzman@techgaun@lukehsiao@lkasser1