Skip to content

chore(security): pin down dependencies and workflow actions#2236

Merged
keshav-space merged 7 commits intomainfrom
pin-dependencies
Mar 27, 2026
Merged

chore(security): pin down dependencies and workflow actions#2236
keshav-space merged 7 commits intomainfrom
pin-dependencies

Conversation

@keshav-space
Copy link
Copy Markdown
Member

@keshav-space keshav-space commented Mar 26, 2026

  • Pin all direct dependencies
  • Pin workflow actions to full commit SHA
  • Set explicit workflow permissions
  • Following vulnerable dependency were bumped:
    • pkg:pypi/black@22.3.0 -> 24.3.0
    • pkg:pypi/cryptography@44.0.1 -> 46.0.5
    • pkg:pypi/idna@3.3 -> 3.7
    • pkg:pypi/redis@5.0.1 -> 6.2.0
    • pkg:pypi/requests@2.32.0 -> 2.32.4
    • pkg:pypi/sqlparse@0.5.0 -> 0.5.4
    • pkg:pypi/starlette@0.47.0 -> 0.49.1
    • pkg:pypi/urllib3@1.26.19 -> 2.6.3

Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
…permissions

Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
Signed-off-by: Keshav Priyadarshi <git@keshav.space>
@keshav-space keshav-space changed the title Pin down dependencies and workflow actions chore(security): pin down dependencies and workflow actions Mar 27, 2026
@keshav-space keshav-space merged commit 0e7adc6 into main Mar 27, 2026
8 checks passed
@keshav-space keshav-space deleted the pin-dependencies branch March 27, 2026 12:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant