Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 8 additions & 8 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -18,22 +18,22 @@ dependencies = [
"structlog",
"fastapi>=0.141.1",
"httpx>=0.28.1",
"uvicorn[standard]>=0.52.4",
"sqlalchemy[asyncio]>=2.0.52",
"uvicorn[standard]>=0.53.0",
"sqlalchemy[asyncio]>=2.0.53",
"asyncpg",
"pypdf>=6.18.0",
"pypdf>=6.18.1",
"python-docx>=1.2.0",
"python-multipart>=0.0.32",
"PyJWT>=2.10.1",
"PyJWT>=2.14.0",
"passlib[bcrypt]==1.7.4",
"cryptography>=50.0.0",
# Security: minimum versions to avoid known CVEs in transitive deps (pip-audit)
"filelock>=3.32.5",
"filelock>=3.32.6",
"future>=1.0.0",
"idna>=3.19", # GHSA-jjg7-2v4v-x38h — DoS via crafted domain in idna.encode
"marshmallow>=4.3.1",
"slowapi>=0.1.10",
"anthropic>=1.4.0",
"anthropic>=1.6.0",
]

[project.optional-dependencies]
Expand All @@ -42,8 +42,8 @@ dev = [
"pytest-asyncio>=1.4.0",
"pytest-cov>=7.1.0",
"httpx>=0.28.1",
"psycopg2-binary>=2.9.12",
"ruff>=0.16.6",
"psycopg2-binary>=2.9.13",
"ruff>=0.16.7",
"mypy>=2.3.1",
"bandit[toml]>=1.9.4",
"moto>=5.0",
Expand Down
36 changes: 18 additions & 18 deletions requirements.lock.txt
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ annotated-doc==0.0.5
# via fastapi
annotated-types==0.8.0
# via pydantic
anthropic==1.4.0
anthropic==1.6.0
# via cortex (pyproject.toml)
anyio==4.15.1
# via
Expand All @@ -17,17 +17,17 @@ anyio==4.15.1
# httpx2
# starlette
# watchfiles
ast-serialize==0.11.0
ast-serialize==0.11.2
# via mypy
asyncpg==0.31.0
# via cortex (pyproject.toml)
bandit==1.9.4
# via cortex (pyproject.toml)
bcrypt==5.0.0
# via passlib
boto3==1.43.89
boto3==1.43.94
# via moto
botocore==1.43.89
botocore==1.43.94
# via
# boto3
# moto
Expand All @@ -43,7 +43,7 @@ charset-normalizer==3.5.1
# via requests
click==8.5.0
# via uvicorn
coverage==7.16.0
coverage==7.16.1
# via pytest-cov
cryptography==50.0.1
# via
Expand All @@ -55,11 +55,11 @@ docstring-parser==0.18.0
# via anthropic
fastapi==0.141.1
# via cortex (pyproject.toml)
filelock==3.32.5
filelock==3.32.6
# via cortex (pyproject.toml)
future==1.0.0
# via cortex (pyproject.toml)
greenlet==3.5.5
greenlet==3.5.6
# via sqlalchemy
h11==0.16.0
# via
Expand All @@ -68,13 +68,13 @@ h11==0.16.0
# uvicorn
httpcore==1.0.9
# via httpx
httpcore2==2.12.0
httpcore2==2.13.0
# via httpx2
httptools==0.8.0
# via uvicorn
httpx==0.28.1
# via cortex (pyproject.toml)
httpx2==2.12.0
httpx2==2.13.0
# via anthropic
idna==3.19
# via
Expand All @@ -85,7 +85,7 @@ idna==3.19
# requests
iniconfig==2.3.0
# via pytest
jiter==0.16.0
jiter==0.17.0
# via anthropic
jmespath==1.1.0
# via
Expand Down Expand Up @@ -123,7 +123,7 @@ pluggy==1.6.0
# via
# pytest
# pytest-cov
psycopg2-binary==2.9.12
psycopg2-binary==2.9.13
# via cortex (pyproject.toml)
pycparser==3.0
# via cffi
Expand All @@ -132,15 +132,15 @@ pydantic==2.13.5
# anthropic
# cortex (pyproject.toml)
# fastapi
pydantic-core==2.46.5
pydantic-core==2.49.0
# via pydantic
pygments==2.21.0
# via
# pytest
# rich
pyjwt==2.13.0
pyjwt==2.14.0
# via cortex (pyproject.toml)
pypdf==6.18.0
pypdf==6.18.1
# via cortex (pyproject.toml)
pytest==9.1.1
# via
Expand Down Expand Up @@ -172,7 +172,7 @@ responses==0.26.3
# via moto
rich==15.0.0
# via bandit
ruff==0.16.6
ruff==0.16.7
# via cortex (pyproject.toml)
s3transfer==0.19.2
# via boto3
Expand All @@ -182,7 +182,7 @@ slowapi==0.1.10
# via cortex (pyproject.toml)
sniffio==1.3.1
# via anthropic
sqlalchemy==2.0.52
sqlalchemy==2.0.53
# via cortex (pyproject.toml)
starlette==1.6.0
# via fastapi
Expand Down Expand Up @@ -218,7 +218,7 @@ urllib3==2.7.0
# botocore
# requests
# responses
uvicorn==0.52.4
uvicorn==0.53.0
# via cortex (pyproject.toml)
uvloop==0.22.1
# via uvicorn
Expand All @@ -228,7 +228,7 @@ websockets==17.1
# via uvicorn
werkzeug==3.1.8
# via moto
wrapt==2.4.0
wrapt==2.4.1
# via deprecated
xmltodict==1.0.4
# via moto
2 changes: 1 addition & 1 deletion requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
#
# This file is kept only for tools that still expect requirements.txt.
# Pins below mirror a subset of [project] dependencies (auth + idna CVE floor).
PyJWT>=2.10.1
PyJWT>=2.14.0
passlib[bcrypt]==1.7.4
python-multipart==0.0.32
# Security: pin idna >= 3.19 (GHSA-jjg7-2v4v-x38h — DoS in idna.encode)
Expand Down
Loading