Uh oh!
There was an error while loading. Please reload this page.
[compliance] Update devbox examples with vulnerabilities - #2753
Merged
Conversation
Bump Django from 4.2.22 to 4.2.27 in the Django stack requirements. Update filelock from 3.18.0 to 3.20.1 in the PyTorch basic example poetry.lock file.
Contributor
There was a problem hiding this comment.
Pull request overview
This PR updates dependency versions in devbox examples to address known security vulnerabilities. The updates include Django in the Django stack example and filelock in the PyTorch basic example, bringing both to their latest secure versions.
- Upgraded Django from 4.2.22 to 4.2.27 to address security vulnerabilities
- Updated filelock from 3.18.0 to 3.20.1 with corresponding poetry.lock changes including hashes and metadata
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| examples/stacks/django/requirements.txt | Bumped Django version from 4.2.22 to 4.2.27 to address security vulnerabilities |
| examples/data_science/pytorch/basic-example/poetry.lock | Updated filelock from 3.18.0 to 3.20.1, including updated file hashes, python version requirement, and removed extras metadata |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
mikeland73
approved these changes
Dec 17, 2025
Uh oh!
There was an error while loading. Please reload this page.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.Update devbox examples with vulnerabilities. Bump Django from 4.2.22 to 4.2.27 in the Django stack requirements. Update filelock from 3.18.0 to 3.20.1 in the PyTorch basic example poetry.lock file.
How was it tested?
devbox shell
Community Contribution License
All community contributions in this pull request are licensed to the project
maintainers under the terms of the
Apache 2 License.
By creating this pull request, I represent that I have the right to license the
contributions to the project maintainers under the Apache 2 License as stated in
the
Community Contribution License.