• security: fix Dependabot vulnerabilities
    Some checks failed
    Cross-Node Transaction Testing / transaction-test (push) Successful in 8s
    Deploy to Testnet / deploy-testnet (push) Successful in 1m53s
    Multi-Node Stress Testing / stress-test (push) Successful in 3s
    Python Tests / test-python (push) Failing after 33s
    Build Debian Miner Binary / build-miner (push) Failing after 14m18s

    aitbc released this 2026-05-20 08:02:07 +02:00 | 160 commits to main since this release

    • Update idna from 3.13 to 3.15 (fixes CVE-2026-45409)
    • Update ujson from 5.12.0 to 5.12.1 (fixes CVE-2026-44660)
    • Update urllib3 from 2.6.3 to 2.7.0 (fixes CVE-2026-44431, CVE-2026-44432)
    • Remove vllm (transitive dependency causing diskcache vulnerability)
    • Remove diskcache (CVE-2025-69872 - no longer required)
    • Update requirements.txt with secure dependency versions

    All vulnerabilities now resolved: pip-audit shows no known vulnerabilities found

    Downloads