Skip to content

fix(source-code-analysis-worker-template): refresh uv.lock - #160

Open
monoxgas wants to merge 1 commit into
mainfrom
nick/worker-template-lock-refresh
Open

monoxgas wants to merge 1 commit into
mainfrom
nick/worker-template-lock-refresh

Conversation

@monoxgas

Copy link
Copy Markdown
Contributor

Summary

  • uv lock --upgrade for capabilities/source-code-analysis-worker-template. The lock hadn't been refreshed since it was added on May 7.
  • Version 0.1.0 → 0.1.1 in capability.yaml and pyproject.toml.

Why

The old lock pinned dreadnode 2.0.15, and osv-scanner reported 17 vulnerable packages in it, including litellm 1.83.0 (13 advisories, max 9.8), anyio 4.13.0 (max 9.3), urllib3 2.6.3 (max 8.9), and cryptography 47.0.0, joserfc 1.6.4 and pillow 11.3.0 (max 8.7). Black Duck asked for this template's installed dependencies for the Davos audit, so they would all appear in the report.

Verification

  • osv-scanner on the refreshed lock: no known vulnerabilities. It resolves dreadnode 2.0.49, litellm 1.84.0, anyio 4.15.1, cryptography 50.0.1, pillow 12.3.0 and urllib3 2.8.0.
  • pytest tests with --extra dev on Python 3.13, linux/amd64: 21 passed on this branch and 21 passed on main.

🤖 Generated with Claude Code

The template's uv.lock had not been refreshed since it was added on
2026-05-07. It pinned dreadnode 2.0.15, and osv-scanner reported 17
vulnerable packages in it (litellm 1.83.0 at 9.8, anyio 4.13.0 at 9.3,
urllib3, cryptography, pillow, joserfc and others). `uv lock --upgrade`
resolves dreadnode 2.0.49 and clears all of them. Bump to 0.1.1.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant