Skip to content

fix(deps): bump requests to 2.32.4 - #438

Open
katsugtgz wants to merge 1 commit into
JefferyHcool:masterfrom
katsugtgz:fix/requests-cve-2024-47081
Open

fix(deps): bump requests to 2.32.4#438
katsugtgz wants to merge 1 commit into
JefferyHcool:masterfrom
katsugtgz:fix/requests-cve-2024-47081

Conversation

@katsugtgz

Copy link
Copy Markdown

Summary

Bumps requests from 2.32.3 to 2.32.4 in backend/requirements.txt.

Vulnerability addressed

Relates to #395.

Scanner evidence

  • Before patch (2.32.3): osv-scanner reported PYSEC-2026-1872 / GHSA-9hjg-9r4m-mvj7 for requests==2.32.3.
  • After patch (2.32.4): PYSEC-2026-1872 / GHSA-9hjg-9r4m-mvj7 is no longer reported.

Remaining advisory: PYSEC-2026-2275 (CVE-2026-25645, GHSA-gc5v-m9x4-r6x2) still affects requests==2.32.4 — fixed in 2.33.0. A separate bump may be needed.

Changed files

  • backend/requirements.txt (1 line: requests==2.32.3requests==2.32.4)

No application logic or source behavior changed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants