Skip to content

build(deps): update requests to 2.33.0 - #502

Merged
james-d-mitchell merged 1 commit into
mainfrom
codex/fix-dependabot-33
Sep 10, 2026
Merged

james-d-mitchell merged 1 commit into
mainfrom
codex/fix-dependabot-33

Conversation

@james-d-mitchell

Copy link
Copy Markdown
Member

Update Requests from 2.32.5 to 2.33.0 in uv.lock to address Dependabot alert #33 (CVE-2026-25645: insecure temporary file reuse in extract_zipped_paths()). requirements.txt already pins 2.33.0. Only the Requests version and distribution metadata change.

Validation:

  • uv lock --check --offline and git diff --check passed.
  • Installed the locked documentation dependencies in an isolated temporary environment; uv pip check passed.
  • Temporary smoke checks passed for distinct extracted paths, preservation of preexisting files, existing/missing path handling, and Sphinx request preparation.
  • Both pre-commit hook stages completed: codespell passed; other hooks had no applicable files.
  • No C++ rebuild or full pytest/doctest run for this lockfile-only change.

AI assistance: OpenAI Codex investigated the alert, prepared the dependency update, and ran the validation checks.

Update the uv lockfile to the patched version for CVE-2026-25645,
addressing Dependabot alert 33. requirements.txt already pins 2.33.0.

AI assistance: OpenAI Codex investigated the alert, prepared the lockfile
update, and ran dependency validation, smoke checks, and repository hooks.

Co-authored-by: Codex <codex@openai.com>
@james-d-mitchell james-d-mitchell added the codex A label for PRs or Issues touched by Codex label Sep 10, 2026
@james-d-mitchell
james-d-mitchell merged commit a0f85cf into main Sep 10, 2026
24 checks passed
@james-d-mitchell
james-d-mitchell deleted the codex/fix-dependabot-33 branch September 10, 2026 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

codex A label for PRs or Issues touched by Codex

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants