Skip to content

Bump filelock from 3.20.1 to 3.20.3#53

Merged
wasaga merged 1 commit intomainfrom
fix/filelock-toctou-vulnerability
Jan 20, 2026
Merged

Bump filelock from 3.20.1 to 3.20.3#53
wasaga merged 1 commit intomainfrom
fix/filelock-toctou-vulnerability

Conversation

@wasaga
Copy link
Copy Markdown
Contributor

@wasaga wasaga commented Jan 20, 2026

Summary

  • Updates filelock from 3.20.1 to 3.20.3

Security

Fixes Dependabot alert #18: filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock

Test plan

  • CI passes

Fixes Dependabot alert #18: filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
@wasaga wasaga merged commit bb07521 into main Jan 20, 2026
5 checks passed
@wasaga wasaga deleted the fix/filelock-toctou-vulnerability branch January 20, 2026 20:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants