Skip to content

fix(security): Pin tornado>=6.5.5 (GHSA-qjxf-f2mg-c6mc)#5425

Merged
cdoern merged 1 commit intollamastack:mainfrom
nathan-weinberg:tornado
Apr 2, 2026
Merged

fix(security): Pin tornado>=6.5.5 (GHSA-qjxf-f2mg-c6mc)#5425
cdoern merged 1 commit intollamastack:mainfrom
nathan-weinberg:tornado

Conversation

@nathan-weinberg
Copy link
Copy Markdown
Contributor

What does this PR do?

Addresses DoS due to too many multipart parts

Refs: GHSA-qjxf-f2mg-c6mc

Signed-off-by: Nathan Weinberg <nweinber@redhat.com>
@meta-cla meta-cla bot added the CLA Signed This label is managed by the Meta Open Source bot. label Apr 2, 2026
@cdoern cdoern added this pull request to the merge queue Apr 2, 2026
Merged via the queue into llamastack:main with commit 0614673 Apr 2, 2026
89 checks passed
@nathan-weinberg nathan-weinberg deleted the tornado branch April 2, 2026 15:26
@nathan-weinberg
Copy link
Copy Markdown
Contributor Author

@Mergifyio backport release-0.6.x

@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Apr 2, 2026

backport release-0.6.x

☑️ Command disallowed due to command restrictions in the Mergify configuration.

Details
  • sender-permission >= write

@nathan-weinberg
Copy link
Copy Markdown
Contributor Author

@cdoern can you do the honors?

@cdoern
Copy link
Copy Markdown
Collaborator

cdoern commented Apr 2, 2026

https://github.com/Mergifyio backport release-0.6.x

@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Apr 2, 2026

backport release-0.6.xhttps://github.com/Mergifyio backport release-0.6.x

❌ Sorry but I didn't understand the arguments of the command backport. Please consult the commands documentation 📚.

@cdoern
Copy link
Copy Markdown
Collaborator

cdoern commented Apr 2, 2026

ugh

@cdoern
Copy link
Copy Markdown
Collaborator

cdoern commented Apr 2, 2026

https://github.com/Mergifyio backport release-0.6.x

@mergify
Copy link
Copy Markdown
Contributor

mergify bot commented Apr 2, 2026

backport release-0.6.x

✅ Backports have been created

Details

mergify bot pushed a commit that referenced this pull request Apr 2, 2026
# What does this PR do?
Addresses  DoS due to too many multipart parts

Refs:
[GHSA-qjxf-f2mg-c6mc](GHSA-qjxf-f2mg-c6mc)

Signed-off-by: Nathan Weinberg <nweinber@redhat.com>
(cherry picked from commit 0614673)
leseb pushed a commit that referenced this pull request Apr 2, 2026
…) (#5426)

# What does this PR do?
Addresses  DoS due to too many multipart parts

Refs:
[GHSA-qjxf-f2mg-c6mc](https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc)<hr>This
is an automatic backport of pull request #5425 done by
[Mergify](https://mergify.com).

Signed-off-by: Nathan Weinberg <nweinber@redhat.com>
Co-authored-by: Nathan Weinberg <31703736+nathan-weinberg@users.noreply.github.com>
leseb pushed a commit to leseb/llama-stack that referenced this pull request Apr 2, 2026
)

# What does this PR do?
Addresses  DoS due to too many multipart parts

Refs:
[GHSA-qjxf-f2mg-c6mc](GHSA-qjxf-f2mg-c6mc)

Signed-off-by: Nathan Weinberg <nweinber@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Meta Open Source bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants