Fix 3 HIGH transitive vulnerabilities: click and soupsieve #98
No reviewers
Labels
No labels
bug
contribution welcome
duplicate
enhancement
good first issue
help wanted
invalid
question
upstream
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Reference
marvin8/feed2fedi!98
Loading…
Reference in a new issue
No description provided.
Delete branch "refs/pull/98/head"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Addresses three HIGH-severity vulnerabilities in transitive dependencies identified by PYSENTRY.
Changes
click>=8.3.3andsoupsieve>=2.8.4to[tool.uv] constraint-dependenciesso uv never resolves below the fixed floorsCLAUDE.mda symlink toAGENTS.mdCloses #97
.forgejo/workflows/checks.ymlline 0🔴 Not actioned. This project uses bare semver tags without a
vprefix —pyproject.tomlconfigurestag_name = "{new_version}"in[tool.bumpversion]. The regex is intentionally strict; av-prefixed tag would indicate a misconfigured release and should fail fast.AGENTS.mdline 0✅ Fixed in commit
1bc3cc4— heading updated to# AGENTS.md..forgejo/workflows/ci.ymlline 0🔴 Not actioned.
forge.tokenis a Forgejo Actions built-in context variable — it provides the workflow's token automatically without requiring a secret. It is used consistently across all projects in this organisation..forgejo/workflows/ci.ymlline 0🔴 Not actioned. WuMing is maintained by the repo owner;
@mainis used deliberately across all projects so improvements are picked up without manual pin bumps. The risk accepted here is the same as self-hosting the action.pyproject.tomlline 0✅ Fixed in commit
1cc1d8e—ty~=0.0.60updated toty~=0.0.61to match the pre-commit rev.AGENTS.mdline 0✅ Fixed in commit
6138848— Stack section updated to remove git-cliff and describe the current approach:bump-my-versionviajustwith entries extracted fromRelease-Notes.mdbullet points..forgejo/workflows/ci.ymlline 0🔴 Not actioned. These model names are correct — they are used identically across all projects in this organisation that use WuMing, and are the established identifiers for WuMing's DeepSeek backend.