Skip to content

fix(deps): bump black to 26.3.1 (Dependabot high)#112

Merged
martinkersner merged 1 commit into
mainfrom
worktree-bump-black
Jun 30, 2026
Merged

fix(deps): bump black to 26.3.1 (Dependabot high)#112
martinkersner merged 1 commit into
mainfrom
worktree-bump-black

Conversation

@martinkersner

Copy link
Copy Markdown
Member

Resolves 2 open Dependabot high-severity alerts (#2, #5): Black — arbitrary file writes from unsanitized input in cache file name (black < 26.3.1).

  • Bump black 26.1.026.3.1 in requirements/requirements-test.txt.

Dev-only tooling (formatter), not a runtime dependency.

Tests

No code changes; lint/test tooling only. CI flake8+black run will exercise the new pin.

Known failures

None.

@martinkersner martinkersner merged commit 962ebde into main Jun 30, 2026
7 checks passed
@martinkersner martinkersner deleted the worktree-bump-black branch June 30, 2026 06:49
@martinkersner martinkersner self-assigned this Jun 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant