Skip to content

Security updates#388

Open
github-actions[bot] wants to merge 1 commit intomasterfrom
security-updates
Open

Security updates#388
github-actions[bot] wants to merge 1 commit intomasterfrom
security-updates

Conversation

@github-actions
Copy link
Contributor

@github-actions github-actions bot commented Feb 4, 2026

Security Vulnerability Report

Generated on: 2026-02-28 00:33:10

Summary

Found vulnerabilities in 5 packages requiring updates.

Package Upgrades Overview

Package Current Version Recommended Version Vulnerabilities
biopython 1.85 Unknown 1
nbconvert 7.16.6 7.17.0 1
orjson 3.10.18 Unknown 1
pillow 11.3.0 12.1.1 1
protobuf 6.31.1 6.33.5 1

Detailed Vulnerability Information

biopython (v1.85)

Vulnerability ID Fix Versions Aliases
CVE-2025-68463 GHSA-x3vf-39hj-gxr4

nbconvert (v7.16.6)

Vulnerability ID Fix Versions Aliases
CVE-2025-53000 7.17.0 GHSA-xm59-rqc7-hhvf

orjson (v3.10.18)

Vulnerability ID Fix Versions Aliases
CVE-2025-67221 GHSA-hx9q-6w63-j58v

pillow (v11.3.0)

Vulnerability ID Fix Versions Aliases
CVE-2026-25990 12.1.1 BIT-pillow-2026-25990, GHSA-cfh3-3jmp-rvhc

protobuf (v6.31.1)

Vulnerability ID Fix Versions Aliases
CVE-2026-0994 5.29.6, 6.33.5 GHSA-7gcm-g887-7qv7

Recommended Actions

  1. Review the vulnerability details above.
  2. Close and reopen this PR to trigger CI/CD tests.
  3. Approve and merge the PR if everything looks good.

This report was generated automatically. Please verify all upgrades before applying.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants