Skip to content

Security updates - #433

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
security-updates
Open

Security updates#433
github-actions[bot] wants to merge 1 commit into
masterfrom
security-updates

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

Security Vulnerability Report

Generated on: 2026-08-13 02:11:30

Summary

Found vulnerabilities in 9 packages requiring updates.

Package Upgrades Overview

Package Current Version Recommended Version Vulnerabilities
aiohttp 3.14.1 3.14.3 3
click 8.2.1 8.3.3 1
jupyterlab 4.5.9 4.6.2 5
mistune 3.2.1 3.3.0 19
pillow 12.2.0 12.3.0 20
pyasn1 0.6.3 0.6.4 4
pymdown-extensions 10.21.3 11.0.1 2
setuptools 80.10.2 83.0.0 2
soupsieve 2.7 2.8.4 2

Detailed Vulnerability Information

aiohttp (v3.14.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3545 3.14.3 CVE-2026-69244, GHSA-cq5v-8q36-5273
PYSEC-2026-3546 3.14.2 CVE-2026-69243, GHSA-mfx4-hv73-q22v
PYSEC-2026-3547 3.14.2 CVE-2026-59881, GHSA-mq44-7p77-q5h7

click (v8.2.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-2132 8.3.3 GHSA-47fr-3ffg-hgmw, CVE-2026-7246

jupyterlab (v4.5.9)

Vulnerability ID Fix Versions Aliases
GHSA-h5v5-8746-g7mm 4.5.10, 4.6.2
GHSA-whvh-wf3x-g77j 4.5.10, 4.6.2
GHSA-gx64-gj6p-pc4c 4.5.10, 4.6.2
GHSA-pppj-hq3g-57pj 4.5.10, 4.6.2
GHSA-89vp-jrxv-24w8 4.5.10, 4.6.2

mistune (v3.2.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-2652 3.3.0 CVE-2026-49851, GHSA-qcq2-496w-v96p
PYSEC-2026-2217 3.3.0 CVE-2026-59929, GHSA-qfrw-5rxm-mhh2
PYSEC-2026-2214 3.3.0 CVE-2026-59926, GHSA-g97x-gvcm-x72h
PYSEC-2026-2215 3.3.0 GHSA-8mpj-m6qm-5qr8, CVE-2026-59927
PYSEC-2026-2212 3.3.0 CVE-2026-59924, GHSA-r4rv-85jg-w4mf
PYSEC-2026-2216 3.3.0 CVE-2026-59928, GHSA-ffq3-xpv3-j92q
PYSEC-2026-2213 3.3.0 CVE-2026-59925, GHSA-4j32-57v6-6g45
PYSEC-2026-2218 3.3.0 CVE-2026-59930, GHSA-2hm2-hc3v-44h9
PYSEC-2026-2211 3.3.0 GHSA-8c25-4j27-2rv3, CVE-2026-59923
PYSEC-2026-2210 3.3.0 CVE-2026-59922, GHSA-c8j7-8cv4-2xmq
PYSEC-2026-2652 3.3.0 CVE-2026-49851, GHSA-qcq2-496w-v96p
PYSEC-2026-2216 3.3.0 CVE-2026-59928, GHSA-ffq3-xpv3-j92q
PYSEC-2026-2215 3.3.0 GHSA-8mpj-m6qm-5qr8, CVE-2026-59927
PYSEC-2026-2210 3.3.0 CVE-2026-59922, GHSA-c8j7-8cv4-2xmq
PYSEC-2026-2214 3.3.0 CVE-2026-59926, GHSA-g97x-gvcm-x72h
PYSEC-2026-2217 3.3.0 CVE-2026-59929, GHSA-qfrw-5rxm-mhh2
PYSEC-2026-2218 3.3.0 CVE-2026-59930, GHSA-2hm2-hc3v-44h9
PYSEC-2026-2213 3.3.0 CVE-2026-59925, GHSA-4j32-57v6-6g45
PYSEC-2026-2211 3.3.0 GHSA-8c25-4j27-2rv3, CVE-2026-59923

pillow (v12.2.0)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-2253 12.3.0 GHSA-8v84-f9pq-wr9x, BIT-pillow-2026-54059, CVE-2026-54059
PYSEC-2026-2255 12.3.0 CVE-2026-55379, GHSA-45hq-cxwh-f6vc, BIT-pillow-2026-55379
PYSEC-2026-2257 12.3.0 GHSA-4x4j-2g7c-83w6, CVE-2026-55798
PYSEC-2026-2256 12.3.0 BIT-pillow-2026-55380, GHSA-phj9-mv4w-65pm, CVE-2026-55380
PYSEC-2026-2254 12.3.0 GHSA-5x94-69rx-g8h2, CVE-2026-54060, BIT-pillow-2026-54060
PYSEC-2026-3453 12.3.0 CVE-2026-59205, BIT-pillow-2026-59205, GHSA-9hw9-ch79-4vh6
PYSEC-2026-3451 12.3.0 GHSA-6r8x-57c9-28j4, BIT-pillow-2026-59199, CVE-2026-59199
PYSEC-2026-3452 12.3.0 BIT-pillow-2026-59203, CVE-2026-59203, GHSA-pg7v-jwj7-p798
PYSEC-2026-2254 12.3.0 GHSA-5x94-69rx-g8h2, CVE-2026-54060, BIT-pillow-2026-54060
PYSEC-2026-2253 12.3.0 CVE-2026-54059, GHSA-8v84-f9pq-wr9x, BIT-pillow-2026-54059
PYSEC-2026-2256 12.3.0 CVE-2026-55380, BIT-pillow-2026-55380, GHSA-phj9-mv4w-65pm
PYSEC-2026-2255 12.3.0 CVE-2026-55379, GHSA-45hq-cxwh-f6vc, BIT-pillow-2026-55379
PYSEC-2026-3451 12.3.0 GHSA-6r8x-57c9-28j4, BIT-pillow-2026-59199, CVE-2026-59199
PYSEC-2026-3452 12.3.0 BIT-pillow-2026-59203, GHSA-pg7v-jwj7-p798, CVE-2026-59203
PYSEC-2026-3453 12.3.0 CVE-2026-59205, BIT-pillow-2026-59205, GHSA-9hw9-ch79-4vh6
PYSEC-2026-3454 12.3.0 BIT-pillow-2026-59197, CVE-2026-59197, GHSA-xj96-63gp-2gmr
PYSEC-2026-3495 12.3.0 CVE-2026-59200, GHSA-jjj6-mw9f-p565, BIT-pillow-2026-59200
PYSEC-2026-3496 12.3.0 CVE-2026-59204, BIT-pillow-2026-59204, GHSA-vjc4-5qp5-m44j
PYSEC-2026-3494 12.3.0 CVE-2026-59198, BIT-pillow-2026-59198, GHSA-fj7v-r99m-22gq
PYSEC-2026-3493 12.3.0 CVE-2026-54058, GHSA-62p4-gmf7-7g93, BIT-pillow-2026-54058

pyasn1 (v0.6.3)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3456 0.6.4 GHSA-8ppf-4f7h-5ppj, CVE-2026-59885
PYSEC-2026-3457 0.6.4 CVE-2026-59886, GHSA-hm4w-wwcw-mr6r
PYSEC-2026-3455 0.6.4 CVE-2026-59884, GHSA-m4p7-r5rc-7g4j
PYSEC-2026-3455 0.6.4 CVE-2026-59884, GHSA-m4p7-r5rc-7g4j

pymdown-extensions (v10.21.3)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3609 11.0.0 CVE-2026-61632, GHSA-9xwg-3r6f-jcx2
PYSEC-2026-3654 11.0.1 GHSA-gm37-52c6-37mw, CVE-2026-67422

setuptools (v80.10.2)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3447 83.0.0 CVE-2026-59890, GHSA-h35f-9h28-mq5c, BIT-setuptools-2026-59890
PYSEC-2026-3447 83.0.0 CVE-2026-59890, BIT-setuptools-2026-59890, GHSA-h35f-9h28-mq5c

soupsieve (v2.7)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3072 2.8.4 GHSA-836r-79rf-4m37, CVE-2026-49477
PYSEC-2026-3071 2.8.4 CVE-2026-49476, GHSA-2wc2-fm75-p42x

Recommended Actions

  1. Review the vulnerability details above.
  2. Close and reopen this PR to trigger CI/CD tests.
  3. Approve and merge the PR if everything looks good.

This report was generated automatically. Please verify all upgrades before applying.

@github-actions
github-actions Bot force-pushed the security-updates branch 2 times, most recently from 7847bfa to b83d223 Compare July 15, 2026 02:43
@github-actions
github-actions Bot force-pushed the security-updates branch 3 times, most recently from dc5ae59 to 7fb2bb9 Compare July 23, 2026 03:14
@github-actions
github-actions Bot force-pushed the security-updates branch 2 times, most recently from 92be369 to 0cd0474 Compare August 4, 2026 02:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants