Skip to content

MAINT Update cryptography>=46.0.5 and werkzeug>=3.1.6 for dependabot alerts#1405

Merged
romanlutz merged 1 commit intoAzure:mainfrom
romanlutz:romanlutz/fix_dependabot_2
Feb 26, 2026
Merged

MAINT Update cryptography>=46.0.5 and werkzeug>=3.1.6 for dependabot alerts#1405
romanlutz merged 1 commit intoAzure:mainfrom
romanlutz:romanlutz/fix_dependabot_2

Conversation

@romanlutz
Copy link
Contributor

Add uv constraint-dependencies to enforce minimum versions for transitive dependencies with security advisories.

  • cryptography: 45.0.7/46.0.3 -> 46.0.5
  • werkzeug: 3.1.5 -> 3.1.6

…alerts

Add uv constraint-dependencies to enforce minimum versions for
transitive dependencies with security advisories.

- cryptography: 45.0.7/46.0.3 -> 46.0.5
- werkzeug: 3.1.5 -> 3.1.6
- diskcache: no fix available (5.6.3 is latest on PyPI)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@romanlutz romanlutz merged commit 69a85fa into Azure:main Feb 26, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants