Skip to content

Conversation

@ivan09069
Copy link

Review pull request. If satisfactory proceed to merge.

snyk-bot and others added 25 commits April 8, 2025 05:21
Snyk has created this PR to upgrade axios from 1.8.2 to 1.8.3.

See this package in yarn:
axios

See this project in Snyk:
https://app.snyk.io/org/ivan09069/project/954b9c89-57b7-489c-84ba-69d41f6e9275?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade dompurify from 3.1.6 to 3.2.4.

See this package in yarn:
dompurify

See this project in Snyk:
https://app.snyk.io/org/ivan09069/project/af686e4e-3e5c-4e0c-bab9-59e78a4bb0f7?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade eslint-config-next from 14.2.3 to 14.2.25.

See this package in yarn:
eslint-config-next

See this project in Snyk:
https://app.snyk.io/org/ivan09069/project/c1d548b0-73a6-4e71-b158-e54e31cbcf66?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade lucide-react from 0.468.0 to 0.483.0.

See this package in yarn:
lucide-react

See this project in Snyk:
https://app.snyk.io/org/ivan09069/project/c1d548b0-73a6-4e71-b158-e54e31cbcf66?utm_source=github&utm_medium=referral&page=upgrade-pr
Snyk has created this PR to upgrade cmdk from 1.0.4 to 1.1.1.

See this package in yarn:
cmdk

See this project in Snyk:
https://app.snyk.io/org/ivan09069/project/c1d548b0-73a6-4e71-b158-e54e31cbcf66?utm_source=github&utm_medium=referral&page=upgrade-pr
…c8f4fa92cd008

[Snyk] Upgrade cmdk from 1.0.4 to 1.1.1
…20ec82702ab46

[Snyk] Upgrade lucide-react from 0.468.0 to 0.483.0
…2928b8d285722

[Snyk] Upgrade eslint-config-next from 14.2.3 to 14.2.25
…72ff32f7c564e

[Snyk] Upgrade dompurify from 3.1.6 to 3.2.4
…e7e6efc9ed7be

[Snyk] Upgrade axios from 1.8.2 to 1.8.3
…3d51fa9131

[Snyk] Security upgrade urllib3 from 2.0.7 to 2.5.0
The following vulnerabilities are fixed by pinning transitive dependencies:
- https://snyk.io/vuln/SNYK-PYTHON-STARLETTE-10874054
…de80d3547a

[Snyk] Security upgrade mermaid from 11.4.1 to 11.10.0
…55e8f37b13

[Snyk] Security upgrade starlette from 0.27.0 to 0.47.2
…lock to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-AXIOS-12613773
…3f4f9df2a1

[Snyk] Security upgrade axios from 1.8.4 to 1.12.0
…dc19605267

[Snyk] Security upgrade electron from 28.2.1 to 37.2.4
Bumps the pip group with 3 updates in the / directory: [torch](https://github.com/pytorch/pytorch), [langchain-community](https://github.com/langchain-ai/langchain) and [authlib](https://github.com/authlib/authlib).


Updates `torch` from 2.6.0 to 2.8.0
- [Release notes](https://github.com/pytorch/pytorch/releases)
- [Changelog](https://github.com/pytorch/pytorch/blob/main/RELEASE.md)
- [Commits](pytorch/pytorch@v2.6.0...v2.8.0)

Updates `langchain-community` from 0.2.5 to 0.3.27
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-community==0.2.5...langchain==0.3.27)

Updates `authlib` from 1.2.1 to 1.6.4
- [Release notes](https://github.com/authlib/authlib/releases)
- [Changelog](https://github.com/authlib/authlib/blob/main/docs/changelog.rst)
- [Commits](authlib/authlib@v1.2.1...v1.6.4)

---
updated-dependencies:
- dependency-name: torch
  dependency-version: 2.8.0
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: langchain-community
  dependency-version: 0.3.27
  dependency-type: direct:production
  dependency-group: pip
- dependency-name: authlib
  dependency-version: 1.6.4
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <[email protected]>
Add a security policy document outlining supported versions and vulnerability reporting.
Bump the pip group across 1 directory with 3 updates
Bumps the pip group with 1 update in the / directory: [authlib](https://github.com/authlib/authlib).


Updates `authlib` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/authlib/authlib/releases)
- [Changelog](https://github.com/authlib/authlib/blob/main/docs/changelog.rst)
- [Commits](authlib/authlib@v1.6.4...v1.6.5)

---
updated-dependencies:
- dependency-name: authlib
  dependency-version: 1.6.5
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <[email protected]>
Copy link
Author

@ivan09069 ivan09069 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

reviewed

Bump authlib from 1.6.4 to 1.6.5 in the pip group across 1 directory
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants