Skip to content

fix: bump nltk, pytest, Flask to resolve Dependabot security alerts#34

Merged
racmac57 merged 1 commit into
mainfrom
fix/dependabot-security-updates
Apr 14, 2026
Merged

fix: bump nltk, pytest, Flask to resolve Dependabot security alerts#34
racmac57 merged 1 commit into
mainfrom
fix/dependabot-security-updates

Conversation

@racmac57
Copy link
Copy Markdown
Owner

Resolves 7 of 9 Dependabot alerts by updating pinned versions in grok_review_package/Dependencies/requirements.txt:

Package Before After Alerts Resolved
nltk 3.8.1 3.9.1 #18 (critical), #23, #22, #21, #20
pytest 7.4.2 8.1.0 #25
Flask 2.3.3 3.1.0 #19

Remaining: Werkzeug #17 (already at 3.1.4, likely pre-dates alert) and vite #24 (npm, legacy folder — separate follow-up).

@racmac57 racmac57 requested a review from hy5guy as a code owner April 14, 2026 00:39
@racmac57 racmac57 merged commit 8b209c6 into main Apr 14, 2026
0 of 6 checks passed
@racmac57 racmac57 deleted the fix/dependabot-security-updates branch April 14, 2026 00:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant