Skip to content

fix: update aiohttp to resolve CVE-2026 vulnerabilities#25

Open
dannyneira wants to merge 1 commit into
mainfrom
independabot/aiohttp-cve-2026-22815
Open

fix: update aiohttp to resolve CVE-2026 vulnerabilities#25
dannyneira wants to merge 1 commit into
mainfrom
independabot/aiohttp-cve-2026-22815

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

  • Updated aiohttp in uv.lock from 3.13.3 to 3.13.5.
  • Resolves the selected direct runtime aiohttp Dependabot alert batch in uv.lock.
  • uv lock also refreshed the editable oz-agent-sdk package version metadata from 0.4.0 to the current pyproject.toml version, 0.13.0.

Dependabot alerts resolved

Verification

  • uv run python -m pip check
  • uv build
  • ./scripts/lint
  • ./scripts/test
  • pip-audit -r /tmp/aiohttp-requirement.txt -f json for aiohttp==3.13.5 reported No known vulnerabilities found and aiohttp_vulnerability_count=0.

Conversation: https://staging.warp.dev/conversation/9f7f7f26-e227-4754-8733-4d2049d946e2
Run: https://oz.staging.warp.dev/runs/019e7476-c7bc-7acb-96bd-ac2f33751fa5
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira requested a review from ianhodge May 29, 2026 16:08
@dannyneira dannyneira marked this pull request as ready for review May 29, 2026 17:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants