Skip to content

fix(deps): bump multidict to 6.9.1 for CVE-2026-104874 - #232

Merged
imran-siddique merged 1 commit into
mainfrom
fix/multidict-6.9.1
Oct 7, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
fix/multidict-6.9.1

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Fixes the red Security scan on main: pip-audit reports CVE-2026-104874 against multidict 6.7.1, fixed in 6.9.1.

Regenerated requirements/agt.txt and requirements/dev.txt with each file's own header command plus --upgrade-package multidict==6.9.1. The only changed lines are the multidict pin and its hashes; the cryptography override and the platform markers are unchanged. pip-audit is clean on both files, and the same command on main's agt.txt reports the CVE.

Supersedes #231, which dependabot generated without agt-overrides.txt: it downgrades cryptography from 50.0.1 to 48.0.1 and strips the --universal markers.

Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@imran-siddique
imran-siddique merged commit a092499 into main Oct 7, 2026
13 checks passed
@imran-siddique
imran-siddique deleted the fix/multidict-6.9.1 branch October 7, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants