Skip to content

[Misc] Fix 5 Dependabot vulnerabilities - #1164

Merged
coderfeli merged 1 commit into
mainfrom
fix/gitpython-cve
Sep 20, 2026
Merged

coderfeli merged 1 commit into
mainfrom
fix/gitpython-cve

Conversation

@Phil-amd

@Phil-amd Phil-amd commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Bumps gitpython 3.1.58 → 3.1.59 in docs/sphinx/requirements.txt, clearing all
5 Dependabot alerts (1 critical, 2 high, 2 moderate). Transitive via
rocm-docs-core, installed by Read the Docs.

The file is pip-compile output, but recompiling churns unrelated pins — it was
generated under Python 3.12, and ipython==9.16.1 cannot resolve below 3.11, so
this edits the one line the advisory asks for. Nothing else moves:
rocm-docs-core wants GitPython>=3.1.30 and 3.1.59 keeps 3.1.58's runtime deps
(gitdb<5,>=4.0.1), so the existing pins hold. Verified by resolving against
them; docs-only, no code paths affected.

GitHub found 5 vulnerabilities (1 critical, 2 high, 2 moderate), all GitPython 3.1.58.
@Phil-amd
Phil-amd requested a review from coderfeli September 18, 2026 07:55
@coderfeli
coderfeli merged commit 12a9613 into main Sep 20, 2026
16 checks passed
@coderfeli
coderfeli deleted the fix/gitpython-cve branch September 20, 2026 11:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants