Conversation
…HSA-jp82-jpqv-5vv3 starlette 1.0.1 is vulnerable to: - GHSA-82w8-qh3p-5jfq: request.form() limits silently ignored, enabling DoS (CVSS 7.5) - GHSA-jp82-jpqv-5vv3: unvalidated request path poisons url.hostname (CVSS 5.3) - GHSA-x746-7m8f-x49c: StaticFiles SSRF via UNC paths on Windows (CVSS 7.5) - GHSA-wqp7-x3pw-xc5r: Arbitrary HTTP method dispatch via getattr (CVSS 5.3) All fixed in starlette 1.3.1. Bumped in dev, mcp, computer-use, and web extras. fastapi 0.133.1 remains compatible.
ed8fce5 to
70ba65c
Compare
Related to the June/July-2026 dependency-CVE cluster — this is part of an overlapping set of consolidated pin bumps. Other open PRs bumping starlette 1.0.1 -> 1.3.1 (and adjacent CVE pins) for the same OSV/Dependabot findings: #56830, #59993, #47998 (tracking #47997). These are competing/overlapping, not duplicates — a maintainer should pick a single canonical consolidated dependency bump. Defense-in-depth dependency hygiene (out-of-scope per SECURITY.md §3.2, no §3.1 boundary crossing / PoC), so priced P2 on ordinary merits, not escalated by the security label. |
|
suggesting changes CI is currently failing on this PR head in Please fix or rerun the failing check, then push a new head or ask for re-review. Signed: GPT-5.5-low in Codex |
04b86bf to
10063d4
Compare
…o match pyproject.toml CI caught pin mismatch between pyproject.toml (1.3.1) and lazy_deps.py (still 1.0.1). The CVE bump in NousResearch#60676 updated pyproject.toml but missed the lazy_deps counterpart. Both dashboard and computer_use entries now match at 1.3.1.
10063d4 to
bdbb5f5
Compare
|
Superseded by dependabot PR #46870 which covers the same starlette bump. |
Summary
Bump pinned starlette from 1.0.1 to 1.3.1 across all extras (dev, mcp, computer-use, web).
CVEs Fixed
All fixed in starlette 1.3.1. fastapi 0.133.1 remains compatible.
Files Changed
pyproject.toml— 4 pin sites updated (dev, mcp, computer-use, web)uv.lock— resolved starlette 1.3.1No code changes — pin-only bump.