Skip to content

Dependabot/moderate severity version bumps#4915

Draft
ChrisChapman-gh wants to merge 3 commits into
mainfrom
dependabot/moderate-severity-version-bumps
Draft

Dependabot/moderate severity version bumps#4915
ChrisChapman-gh wants to merge 3 commits into
mainfrom
dependabot/moderate-severity-version-bumps

Conversation

@ChrisChapman-gh
Copy link
Copy Markdown
Collaborator

Resolves

https://github.com/microsoft/AzureTRE/security/dependabot/351
https://github.com/microsoft/AzureTRE/security/dependabot/352
https://github.com/microsoft/AzureTRE/security/dependabot/353

What is being addressed

Moderate severity dependabot alerts.
They are not exploitable code path but are being updated for good measure

How is this addressed

Update pytest from 8.3.3 to 9.0.3
Update aiohttp from 3.13.3 to 3.13.4

Update direct aiohttp pins in api_app, resource_processor/vmss_porter, and the CLI requirements/setup metadata from 3.13.3 to 3.13.4.

This addresses the open moderate Dependabot alerts for aiohttp: #333, #332, #331, #330, #313, #312, #311, #310, #309, #308, #307, #306, #296, #295, #294, and #293. These alerts are fixed by aiohttp 3.13.4.
@ChrisChapman-gh ChrisChapman-gh self-assigned this May 22, 2026
@ChrisChapman-gh ChrisChapman-gh added api Composition Service API dependencies Pull requests that update a dependency file deployment labels May 22, 2026
@github-actions
Copy link
Copy Markdown

Unit Test Results

0 tests   0 ✅  0s ⏱️
0 suites  0 💤
0 files    0 ❌

Results for commit 78e26d7.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api Composition Service API dependencies Pull requests that update a dependency file deployment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant