Skip to content

Release guidelines and PR template update#92

Merged
romanlutz merged 1 commit intomicrosoft:mainfrom
romanlutz:romanlutz/release_process_update
Mar 12, 2024
Merged

Release guidelines and PR template update#92
romanlutz merged 1 commit intomicrosoft:mainfrom
romanlutz:romanlutz/release_process_update

Conversation

@romanlutz
Copy link
Copy Markdown
Contributor

Description

Adding instructions to set the "release" info on GitHub.
Additionally, adding some more info for contributors to consider before opening PRs.

Tests

  • no new tests required
  • new tests added
  • existing tests adjusted

Documentation

  • no documentation changes needed
  • documentation added or edited
  • example notebook added or updated

@romanlutz romanlutz merged commit 526593e into microsoft:main Mar 12, 2024
@romanlutz romanlutz deleted the romanlutz/release_process_update branch March 12, 2024 06:32
romanlutz added a commit to romanlutz/PyRIT that referenced this pull request Apr 12, 2026
Direct dependencies:
- pypdf: >=6.8.0 -> >=6.10.0 (3 alerts: path injection, infinite loop, inefficient decoding)
- tinytag: >=2.1.1 -> >=2.2.1 (1 alert: DoS via SYLT frame parsing)

Optional dependencies (gcg/all):
- mlflow: >=2.22.0 -> >=3.11.1 (8 alerts: command injection, path traversal, auth bypass)

Transitive dependency constraints (tool.uv):
- aiohttp: >=3.13.4 (10 alerts: SSRF, header injection, DoS, memory issues)
- cryptography: >=46.0.5 -> >=46.0.7 (2 alerts: buffer overflow, DNS enforcement)
- requests: >=2.33.0 (1 alert: insecure temp file reuse)
- PyJWT: >=2.12.0 (1 alert: unknown crit header extensions)
- Pygments: >=2.20.0 (1 alert: ReDoS via GUID matching)

Frontend:
- axios: 1.14.0 -> 1.15.0 (1 alert: SSRF via NO_PROXY bypass)

Remaining alerts have no fix available (mlflow microsoft#92/microsoft#109/microsoft#111, lupa, diskcache).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants