Skip to content

Comments

fix: nightly security dependency updates#302

Open
github-actions[bot] wants to merge 1 commit intomainfrom
security-nightly-updates-22084436181
Open

fix: nightly security dependency updates#302
github-actions[bot] wants to merge 1 commit intomainfrom
security-nightly-updates-22084436181

Conversation

@github-actions
Copy link
Contributor

Security Update

This is an automated PR triggered by the nightly Trivy security scan.

The following dependencies were updated to resolve vulnerabilities with a CVSS score of 7.0 or higher:

Package & Version Advisory Link
urllib3==2.6.3 https://avd.aquasec.com/nvd/cve-2026-21441

Verification: Attempted uv lock --upgrade-package. If blocked by parent constraints, the package was moved to override-dependencies in pyproject.toml to ensure the fix persists.

Copilot AI review requested due to automatic review settings February 17, 2026 03:03
@github-actions github-actions bot review requested due to automatic review settings February 17, 2026 03:03
@google-oss-prow
Copy link
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign andreyvelich for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@Fiona-Waters
Copy link
Contributor

This PR can be closed as this dependency was updated in #296

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant