Skip to content

Conversation

@ModeSevenIndustrialSolutions
Copy link
Contributor

No description provided.

Signed-off-by: Matthew Watkins <mwatkins@linuxfoundation.org>
Copilot AI review requested due to automatic review settings January 12, 2026 12:12
@github-actions github-actions bot added the chore Code chores (dependency updates, etc) label Jan 12, 2026
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates the urllib3 dependency to version 2.6.3 or higher to address a security vulnerability (CVE-2026-21441) related to decompression-bomb attacks.

Changes:

  • Added urllib3>=2.6.3 as an explicit dependency in pyproject.toml with security justification
  • Updated uv.lock to reflect urllib3 version 2.6.3 with updated package hashes

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
pyproject.toml Added urllib3>=2.6.3 dependency with CVE-2026-21441 security comment
uv.lock Updated urllib3 from 2.6.2 to 2.6.3 with new hashes and dependency references

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@ModeSevenIndustrialSolutions ModeSevenIndustrialSolutions merged commit b5f1bb2 into lfreleng-actions:main Jan 12, 2026
24 checks passed
@ModeSevenIndustrialSolutions ModeSevenIndustrialSolutions deleted the update-urllib3 branch January 12, 2026 12:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Code chores (dependency updates, etc)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants