-
security: fix Dependabot vulnerabilities
Some checks failedCross-Node Transaction Testing / transaction-test (push) Successful in 8sDeploy to Testnet / deploy-testnet (push) Successful in 1m53sMulti-Node Stress Testing / stress-test (push) Successful in 3sPython Tests / test-python (push) Failing after 33sBuild Debian Miner Binary / build-miner (push) Failing after 14m18sreleased this
2026-05-20 08:02:07 +02:00 | 160 commits to main since this release- Update idna from 3.13 to 3.15 (fixes CVE-2026-45409)
- Update ujson from 5.12.0 to 5.12.1 (fixes CVE-2026-44660)
- Update urllib3 from 2.6.3 to 2.7.0 (fixes CVE-2026-44431, CVE-2026-44432)
- Remove vllm (transitive dependency causing diskcache vulnerability)
- Remove diskcache (CVE-2025-69872 - no longer required)
- Update requirements.txt with secure dependency versions
All vulnerabilities now resolved: pip-audit shows no known vulnerabilities found
Downloads