Skip to content

chore(deps-dev): bump authlib from 1.6.9 to 1.6.11#10762

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/authlib-1.6.11
Open

chore(deps-dev): bump authlib from 1.6.9 to 1.6.11#10762
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/authlib-1.6.11

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 17, 2026

Bumps authlib from 1.6.9 to 1.6.11.

Release notes

Sourced from authlib's releases.

v1.6.11

Full Changelog: authlib/authlib@v1.6.10...v1.6.11

  • Fix CSRF issue with starlette client

v1.6.10

Full Changelog: authlib/authlib@v1.6.9...v1.6.10

  • Fix redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError.
Changelog

Sourced from authlib's changelog.

Version 1.6.11

Released on Apr 16, 2026

  • Fix CSRF vulnerability in the Starlette OAuth client when a cache is configured.

Version 1.6.10

Released on Apr 13, 2026

  • Fix redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError.
Commits
  • 0dc0e5b chore: bump to 1.6.11
  • aa7b8e4 Merge commit from fork
  • 401a770 fix: CSRF issue with starlette client
  • ef09aeb chore: release 1.6.10
  • 3be0846 fix: redirecting to unvalidated redirect_uri on UnsupportedResponseTypeError
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Dependabot Updates python Pull requests that update Python code labels Apr 17, 2026
@dependabot dependabot Bot requested a review from a team April 17, 2026 00:02
@dependabot dependabot Bot added dependencies Dependabot Updates python Pull requests that update Python code labels Apr 17, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 17, 2026

⚠️ Changes detected in the following folders without a corresponding update to the CHANGELOG.md:

  • prowler (root dependency files changed)

Please add an entry to the corresponding CHANGELOG.md file to maintain a clear history of changes.

@github-actions github-actions Bot added the community Opened by the Community label Apr 17, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 17, 2026

Conflict Markers Resolved

All conflict markers have been successfully resolved in this pull request.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 17, 2026

🔒 Container Security Scan

Image: prowler:b6f609f
Last scan: 2026-05-05 14:18:09 UTC

📊 Vulnerability Summary

Severity Count
🔴 Critical 4
Total 4

4 package(s) affected

⚠️ Action Required

Critical severity vulnerabilities detected. These should be addressed before merging:

  • Review the detailed scan results
  • Update affected packages to patched versions
  • Consider using a different base image if updates are unavailable

📋 Resources:

@dependabot dependabot Bot force-pushed the dependabot/pip/authlib-1.6.11 branch from 588781e to 57f77d5 Compare April 20, 2026 14:45
@dependabot dependabot Bot requested a review from a team as a code owner April 20, 2026 14:45
@dependabot dependabot Bot force-pushed the dependabot/pip/authlib-1.6.11 branch from 57f77d5 to e7f4cb9 Compare April 23, 2026 10:33
Bumps [authlib](https://github.com/authlib/authlib) from 1.6.9 to 1.6.11.
- [Release notes](https://github.com/authlib/authlib/releases)
- [Changelog](https://github.com/authlib/authlib/blob/v1.6.11/docs/changelog.rst)
- [Commits](authlib/authlib@v1.6.9...v1.6.11)

---
updated-dependencies:
- dependency-name: authlib
  dependency-version: 1.6.11
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/pip/authlib-1.6.11 branch from e7f4cb9 to cbccfc8 Compare May 5, 2026 14:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community Opened by the Community dependencies Dependabot Updates python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants