Skip to content

VULN UPGRADE: minor upgrades — 47 packages (minor: 20 · patch: 27) [Documentation] - #647

Closed
campaigner-prod[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/pip/Documentation/0-1767801834
Closed

VULN UPGRADE: minor upgrades — 47 packages (minor: 20 · patch: 27) [Documentation]#647
campaigner-prod[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/pip/Documentation/0-1767801834

Conversation

@campaigner-prod

Copy link
Copy Markdown

Summary: High-severity security update — 47 packages upgraded (MINOR changes included)

Manifests changed:

  • Documentation (pip)

Updates

Package From To Type Vulnerabilities Fixed
urllib3 2.5.0 2.6.2 minor 2 HIGH
Babel 2.12.1 2.17.0 minor -
Pygments 2.16.1 2.19.2 minor -
Sphinx 7.1.2 7.4.7 minor -
annotated-types 0.5.0 0.7.0 minor -
attrs 23.1.0 23.2.0 minor -
certifi 2024.7.4 2024.12.14 minor -
charset-normalizer 3.2.0 3.4.4 minor -
docutils 0.18.1 0.22.4 minor -
idna 3.7 3.11 minor -
jsonschema-specifications 2023.7.1 2023.12.1 minor -
livereload 2.6.3 2.7.1 minor -
packaging 23.1 23.2 minor -
pathspec 0.11.2 0.12.1 minor -
referencing 0.30.2 0.37.0 minor -
rstcheck-core 1.1.1 1.2.2 minor -
six 1.16.0 1.17.0 minor -
sphinxcontrib-googleanalytics 0.4 0.5 minor -
typing_extensions 4.7.1 4.15.0 minor -
yamllint 1.32.0 1.37.1 minor -
MarkupSafe 2.1.3 2.1.5 patch -
PyYAML 6.0.1 6.0.3 patch -
alabaster 0.7.13 0.7.16 patch -
click 8.1.7 8.1.8 patch -
deepmerge 1.1.0 1.1.1 patch -
jsonschema 4.19.0 4.19.2 patch -
mdit-py-plugins 0.4.0 0.4.2 patch -
pydantic 2.7.1 2.7.4 patch -
pydantic_core 2.18.2 2.18.4 patch -
requests 2.32.4 2.32.5 patch -
rich 13.5.2 13.5.3 patch -
rpds-py 0.10.3 0.10.6 patch -
rstcheck 6.2.0 6.2.5 patch -
semver 3.0.1 3.0.4 patch -
shellingham 1.5.3 1.5.4 patch -
sphinx-tabs 3.4.1 3.4.7 patch -
sphinx_mdinclude 0.5.3 0.5.4 patch -
sphinxcontrib-applehelp 1.0.4 1.0.8 patch -
sphinxcontrib-devhelp 1.0.2 1.0.6 patch -
sphinxcontrib-htmlhelp 2.0.1 2.0.6 patch -
sphinxcontrib-openapi 0.8.1 0.8.4 patch -
sphinxcontrib-qthelp 1.0.3 1.0.8 patch -
sphinxcontrib-serializinghtml 1.1.5 1.1.10 patch -
sphinxcontrib-spelling 8.0.0 8.0.1 patch -
sphinxcontrib-websupport 1.2.4 1.2.7 patch -
tornado 6.5 6.5.4 patch -
typer 0.9.0 0.9.4 patch -

Packages marked with "-" are updated due to dependency constraints.


Security Details

🚨 Critical & High Severity (2 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
urllib3 GHSA-gm62-xv2j-4w53 HIGH urllib3 allows an unbounded number of links in the decompression chain 2.5.0 2.6.0
urllib3 GHSA-2xpw-w6gg-jr37 HIGH urllib3 streaming API improperly handles highly compressed data 2.5.0 2.6.0
⚠️ Dependencies that have Reached EOL (17)
Dependency Unsafe Version EOL Date New Version Path
MarkupSafe 2.1.3 - 2.1.5 Documentation/requirements.txt
attrs 23.1.0 - 23.2.0 Documentation/requirements.txt
click 8.1.7 - 8.1.8 Documentation/requirements.txt
idna 3.7 - 3.11 Documentation/requirements.txt
jsonschema 4.19.0 - 4.19.2 Documentation/requirements.txt
jsonschema-specifications 2023.7.1 - 2023.12.1 Documentation/requirements.txt
livereload 2.6.3 Aug 22, 2025 2.7.1 Documentation/requirements.txt
referencing 0.30.2 - 0.37.0 Documentation/requirements.txt
rpds-py 0.10.3 - 0.10.6 Documentation/requirements.txt
sphinxcontrib-applehelp 1.0.4 - 1.0.8 Documentation/requirements.txt
sphinxcontrib-devhelp 1.0.2 - 1.0.6 Documentation/requirements.txt
sphinxcontrib-htmlhelp 2.0.1 - 2.0.6 Documentation/requirements.txt
sphinxcontrib-qthelp 1.0.3 - 1.0.8 Documentation/requirements.txt
sphinxcontrib-serializinghtml 1.1.5 - 1.1.10 Documentation/requirements.txt
sphinxcontrib-websupport 1.2.4 Aug 9, 2025 1.2.7 Documentation/requirements.txt
tornado 6.5 - 6.5.4 Documentation/requirements.txt
typing_extensions 4.7.1 - 4.15.0 Documentation/requirements.txt

Review Checklist

Enhanced review recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment

Update Mode: Vulnerability Remediation (High)

🤖 Generated by DataDog Automated Dependency Management System

@campaigner-prod
campaigner-prod Bot marked this pull request as ready for review January 8, 2026 16:21
@campaigner-prod
campaigner-prod Bot marked this pull request as ready for review January 8, 2026 16:21
@seberm-6 seberm-6 closed this Jan 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant