Skip to content

fix: resolve dependency security alerts - #7

Merged
gcharang merged 1 commit into
masterfrom
fix/dependency-security-alerts
Jul 31, 2026
Merged

fix: resolve dependency security alerts#7
gcharang merged 1 commit into
masterfrom
fix/dependency-security-alerts

Conversation

@gcharang

Copy link
Copy Markdown
Contributor

Summary

  • replace the unmaintained PyPDF2 dependency with pypdf across the API and pinned PageIndex runtime
  • preserve truthful artifact identity for the PyMuPDF single-page shortcut and pypdf multi-page path
  • override brace-expansion to the patched 5.0.8 release under the existing seven-day quarantine
  • fix relative PageIndex installer patch resolution and add provider-free regression coverage

Verification

  • make api-check docs-check
  • make playwright (20 passed, 1 authorized live test skipped)
  • make docker-build
  • TEST_POSTGRES_PORT=55433 make test-integration-stack (27 passed)
  • full repository CI gates completed locally; clean-code, architecture, and QA review lanes clean

@gcharang
gcharang merged commit e5b9d23 into master Jul 31, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant