mirror of
https://github.com/NicolasBohn/NexQuant.git
synced 2026-07-27 23:47:46 +00:00
fix(deps): bump python-dotenv to >=1.2.2 (CVE symlink overwrite)
Resolves last open Dependabot alert: python-dotenv symlink following in set_key allows arbitrary file overwrite via cross-device rename. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
+1
-1
@@ -37,7 +37,7 @@ tables
|
||||
tree-sitter-python
|
||||
tree-sitter
|
||||
|
||||
python-dotenv
|
||||
python-dotenv>=1.2.2 # CVE: symlink following allows arbitrary file overwrite
|
||||
|
||||
# infrastructure related.
|
||||
docker
|
||||
|
||||
Reference in New Issue
Block a user