Skip to content

Security/dependabot fixes#161

Merged
maubreville merged 3 commits into
masterfrom
security/dependabot-fixes
Jun 16, 2026
Merged

Security/dependabot fixes#161
maubreville merged 3 commits into
masterfrom
security/dependabot-fixes

Conversation

@maubreville

Copy link
Copy Markdown
Collaborator
  • new logo

maubreville and others added 3 commits June 9, 2026 13:15
- Django 4.2.18 → 4.2.30 (1 CRITICAL, 9 HIGH, 5 MEDIUM, 7 LOW CVEs)
- GitPython 3.1.41 → 3.1.50 (5 HIGH CVEs incl. RCE via hooksPath injection)
- Werkzeug 3.0.6 → 3.1.8 (3 MEDIUM CVEs — safe_join Windows device names)
- gdown 5.1.0 → 6.1.0 (CVE-2026-40491 arbitrary file write via path traversal)
- djangorestframework-simplejwt 5.3.1 → 5.5.1 (CVE-2024-22513 privilege management)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@maubreville maubreville merged commit ee32491 into master Jun 16, 2026
1 check passed
@maubreville maubreville deleted the security/dependabot-fixes branch June 16, 2026 11:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant