fix: constrain starlette to >=1.0.1 (CVE-2026-48710) - #174
Conversation
GHSA-86qp-5c8j-p5mr <!-- devin-review-badge-begin --> --- <a href="https://app.devin.ai/review/ogx-ai/ogx/pull/5977" target="_blank"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://static.devin.ai/assets/gh-open-in-devin-review-dark.svg?v=1"> <img src="https://static.devin.ai/assets/gh-open-in-devin-review-light.svg?v=1" alt="Open in Devin Review"> </picture> </a> <!-- devin-review-badge-end --> --------- Signed-off-by: Eoin Fennessy <efenness@redhat.com> Co-authored-by: Matthew Farrellee <matt@cs.wisc.edu> (cherry picked from commit 41c94c4) Signed-off-by: Charlie Doern <cdoern@redhat.com> Signed-off-by: Derek Higgins <derekh@redhat.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Derek Higgins <derekh@redhat.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. 🗂️ Base branches to auto review (4)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited) Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Merging build failures are unrelated |
42fc324
into
opendatahub-io:release-v3.3
Summary
starlette>=1.0.1constraint to address CVE-2026-48710Test plan