Commit 823de4f
chore(deps): bump fastmcp, authlib, urllib3, python-multipart, PyJWT, cryptography (#8)
- fastmcp >=3.2.0 closes CVE-2026-32871 (critical), CVE-2026-27124 (high)
- authlib >=1.6.9 closes CVE-2026-27962 (critical), CVE-2026-28490, CVE-2026-28498, CVE-2026-28802 (high)
- urllib3 >=2.7.0 closes CVE-2026-44432, CVE-2026-44431 (high)
- python-multipart >=0.0.27 closes CVE-2026-24486, CVE-2026-42561 (high)
- PyJWT >=2.12.0 closes CVE-2026-32597 (high)
- cryptography >=46.0.5 (transitive requirement for authlib 1.6.9)
pip-lupa CVE-2026-34444 is being handled separately via Vanta risk register acceptance — no upstream fix exists.
Mirror PR will follow in sondera-ai/internal-cedar-python.
Co-authored-by: Tyler Predale <tpredale@sondera.ai>1 parent 15adef4 commit 823de4f
2 files changed
Lines changed: 241 additions & 376 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
43 | 50 | | |
44 | 51 | | |
45 | 52 | | |
| |||
0 commit comments