Skip to content

deps(deps): bump anyio from 4.13.0 to 4.14.2 - #85

Merged
rivassec merged 1 commit into
mainfrom
deps/anyio-4.14.2
Sep 29, 2026
Merged

rivassec merged 1 commit into
mainfrom
deps/anyio-4.14.2

Conversation

@rivassec

Copy link
Copy Markdown
Owner

Fixes Dependabot alerts #20 (critical, GHSA-82r6-8w77-94w6: TLSStream IDNA 2003 host name spoofing) and #19 (medium, GHSA-5p39-cfhj-2xmp: process-pool workers can block on undrained stderr). Both are fixed in 4.14.2.

anyio is a transitive dependency via watchfiles (Pelican's autoreload). The site build never uses anyio's TLS streams or process pools, so real exposure was low, but the alert was open.

Change

Only the anyio entry in requirements.txt is updated, with sha256 hashes from PyPI. I didn't run a full pip-compile, so the other hashed pins are left as they are.
Deps are satisfied: idna 3.15 is already pinned, and typing_extensions is only required below Python 3.13.

Tested locally (Python 3.13, same install command as deploy.yml)

  • pip install --require-hashes --no-deps -r requirements.txt: OK
  • import anyio, watchfiles, pelican.utils: OK (anyio 4.14.2)
  • pelican content -s publishconf.py: 22 articles and 2 pages, no errors

🤖 Generated with Claude Code

Fixes Dependabot alerts #20 (GHSA-82r6-8w77-94w6, critical: TLSStream IDNA
host name spoofing) and #19 (GHSA-5p39-cfhj-2xmp, medium: process-pool
workers block on undrained stderr). anyio is transitive via watchfiles.

Only the anyio entry is updated, with hashes from PyPI, so the rest of the
hashed pins are left as they are. Deps are satisfied: idna 3.15 is already
pinned, and typing_extensions is only needed below Python 3.13.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@rivassec
rivassec merged commit e19417f into main Sep 29, 2026
18 of 19 checks passed
@rivassec
rivassec deleted the deps/anyio-4.14.2 branch September 29, 2026 03:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant