Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Dec 28, 2025

Two security vulnerabilities in urllib3 2.0.7: improper handling of highly compressed data and unbounded decompression chain links.

Changes

  • urllib3: 2.0.7 → 2.6.2 (fixes CVEs)
  • boto3: 1.28.63 → 1.42.17
  • botocore: 1.31.63 → 1.42.17
  • s3transfer: 0.7.0 → 0.16.0
  • python-dateutil: 2.8.2 → 2.9.0.post0
  • six: 1.16.0 → 1.17.0

All updated versions verified against GitHub Advisory Database with no vulnerabilities found. Existing unit tests pass.

Original prompt

This section details on the original issue you should resolve

<issue_title>Update Python dependencies</issue_title>
<issue_description>Update the Pythen dependencies defined in the requirements.txt files. Focus on fixing security related issues.</issue_description>

Comments on the Issue (you are @copilot in this section)


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

Copilot AI changed the title [WIP] Update Python dependencies in requirements.txt Update Python dependencies to fix urllib3 security vulnerabilities Dec 28, 2025
Copilot AI requested a review from stefanfreitag December 28, 2025 09:15
@stefanfreitag stefanfreitag added the enhancement New feature or request label Dec 28, 2025
@stefanfreitag stefanfreitag marked this pull request as ready for review December 28, 2025 09:17
@stefanfreitag stefanfreitag merged commit f395e03 into main Dec 28, 2025
4 of 5 checks passed
@stefanfreitag stefanfreitag deleted the copilot/update-python-dependencies branch December 28, 2025 09:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update Python dependencies

2 participants