Skip to content

build(deps): bump openhands-aci from 0.3.2 to 0.3.3#154

Merged
TuringND merged 1 commit intomainfrom
bump-openhands-aci-0.3.3
Apr 22, 2026
Merged

build(deps): bump openhands-aci from 0.3.2 to 0.3.3#154
TuringND merged 1 commit intomainfrom
bump-openhands-aci-0.3.3

Conversation

@TuringND
Copy link
Copy Markdown
Collaborator

Summary

  • Bumps openhands-aci from 0.3.2 to 0.3.3
  • Resolves CVE-2023-36464 (PyPDF2, CVSS 6.2 MEDIUM) — openhands-aci 0.3.3 dropped the deprecated PyPDF2 dependency in favour of pypdf
  • Addresses CRO-11828 (the last remaining failing vulnerability from the Vanta/Dependabot findings)

Test plan

  • Verify poetry.lock no longer contains pypdf2
  • Confirm existing PDF-related functionality works with pypdf only

Made with Cursor

Resolves CVE-2023-36464 by removing the transitive PyPDF2 dependency —
openhands-aci 0.3.3 dropped PyPDF2 in favour of pypdf.

Made-with: Cursor
@TuringND TuringND merged commit f6a6b8f into main Apr 22, 2026
4 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants