From 940d0396f8e2707aac6439599913d28c138db464 Mon Sep 17 00:00:00 2001 From: rivassec Date: Mon, 28 Sep 2026 19:07:28 -0700 Subject: [PATCH] deps(deps): bump anyio from 4.13.0 to 4.14.2 Fixes Dependabot alerts #20 (GHSA-82r6-8w77-94w6, critical: TLSStream IDNA host name spoofing) and #19 (GHSA-5p39-cfhj-2xmp, medium: process-pool workers block on undrained stderr). anyio is transitive via watchfiles. Only the anyio entry is updated, with hashes from PyPI, so the rest of the hashed pins are left as they are. Deps are satisfied: idna 3.15 is already pinned, and typing_extensions is only needed below Python 3.13. Co-Authored-By: Claude Opus 5.5 --- requirements.txt | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/requirements.txt b/requirements.txt index 0145cb79..2b44b5c3 100644 --- a/requirements.txt +++ b/requirements.txt @@ -4,9 +4,9 @@ # # pip-compile --generate-hashes --no-emit-index-url --output-file=requirements.txt requirements.in # -anyio==4.13.0 \ - --hash=sha256:08b310f9e24a9594186fd75b4f73f4a4152069e3853f1ed8bfbf58369f4ad708 \ - --hash=sha256:334b70e641fd2221c1505b3890c69882fe4a2df910cba14d97019b90b24439dc +anyio==4.14.2 \ + --hash=sha256:9f505dda5ac9f0c8309b5e8bd445a8c2bf7246f3ce950121e45ea15bc41d1494 \ + --hash=sha256:cfa139f3ed1a23ee8f88a145ddb5ac7605b8bbfd8592baacd7ce3d8bb4313c7f # via watchfiles beautifulsoup4==4.15.0 \ --hash=sha256:288e3ca7d54b06f2ac191970bc275c1939cb46d450b255bf6718b04aa37ab4f7 \