fix(deps): bump python-dotenv to >=1.2.2 (CVE symlink overwrite)

Resolves last open Dependabot alert: python-dotenv symlink following
in set_key allows arbitrary file overwrite via cross-device rename.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
TPTBusiness
2026-04-21 22:38:18 +02:00
parent 6c8a1257c8
commit 9b87a1f5ae
+1 -1
View File
@@ -37,7 +37,7 @@ tables
tree-sitter-python
tree-sitter
python-dotenv
python-dotenv>=1.2.2 # CVE: symlink following allows arbitrary file overwrite
# infrastructure related.
docker