Bump tornado from 6.5.5 to 6.5.7 - #106
Conversation
Security Vulnerability — No Patch Available Yetaieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:
Why this cannot be auto-fixedThe vulnerability (CVE-2025-3000) exists in What was fixed automaticallyThe following vulnerabilities were resolved in this update:
Recommended next steps
This PR will not be auto-merged until the vulnerability is resolved. |
ea68af8 to
62d58e1
Compare
|
Automated fix applied and PR merged The agentic fix loop successfully fixed this PR and merged it. ✓ Successfully fixed security failures - Modified 1 files - Executed 280 agent actions - (166 info, 47 tool_call, 6 error, 38 tool_result, 21 reasoning, 2 action) View detailed trace on dashboard | Raw trace AI Engineering Maintenance Bot |
62d58e1 to
fe962f8
Compare
…ilities - aiohttp>=3.14.1 (CVE-2026-54273, CVE-2026-54274, CVE-2026-54275, CVE-2026-54276, CVE-2026-54277, CVE-2026-54278, CVE-2026-54279, CVE-2026-54280) - cryptography>=48.0.1 (GHSA-537c-gmf6-5ccf) - starlette>=1.3.1 (CVE-2026-54282, CVE-2026-54283) Note: torch CVE-2025-3000 has no fix available upstream yet. Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
4ca3f41 to
0d96549
Compare
|
Automated fix applied and PR merged The agentic fix loop successfully fixed this PR and merged it. ✓ Successfully fixed merge_only failures - Modified 2 files - Executed 583 agent actions - (352 info, 109 tool_call, 19 error, 78 tool_result, 23 reasoning, 2 action) View detailed trace on dashboard | Raw trace AI Engineering Maintenance Bot |
Bumps tornado from 6.5.5 to 6.5.7.
Changelog
Sourced from tornado's changelog.
... (truncated)
Commits
48fc2d4Merge pull request #3633 from bdarnell/curl-reset-654ae1dddRelease notes and version bump for 6.5.73154caacurl_httpclient: Reset the curl object before putting it on the freelist7d869c0Merge pull request #3631 from bdarnell/cve-links288241fdocs: Use the correct link syntax8da981cdocs: Add CVE links to 6.5.6 release notesaba2569Merge pull request #3626 from bdarnell/fixes-656a24b260httpclient_test: Accept an additional error message varianta74240aRelease notes and version bump for 6.5.6.e8fc7edsimple_httpclient: Strip auth headers on cross-origin redirectsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.