Commit f0e260b
committed
deps: pin idna>=3.15 (CVE-2024-3651) — incorporates Snyk PR #530
Transitive via requests; idna<3.7 has a ReDoS/DoS. Added in the same
transitive-pins block as setuptools/zipp with the CVE named (Snyk's auto-PR
left a generic comment). Verified: 3.15-3.18 exist on PyPI, requests allows
idna<4, dry-run resolves.1 parent aac22ef commit f0e260b
1 file changed
Lines changed: 1 addition & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
101 | 101 | | |
102 | 102 | | |
103 | 103 | | |
| 104 | + | |
0 commit comments