Skip to content

Fix Dependabot security alerts - #163

Merged
wasimxyz merged 1 commit into
stagingfrom
fix/dependabot-security-alerts
Jul 21, 2026
Merged

Fix Dependabot security alerts#163
wasimxyz merged 1 commit into
stagingfrom
fix/dependabot-security-alerts

Conversation

@wasimxyz

Copy link
Copy Markdown
Member

Summary

  • Bump transitive pillow 12.2.0 → 12.3.0 in uv.lock (closes 13 Pillow Dependabot alerts).
  • Override npm transitive js-yaml (≥4.3.0), body-parser (≥2.3.0), and brace-expansion (≥5.0.7) to clear the remaining open alerts.

Test plan

  • make check-all
  • Confirm Dependabot alerts auto-close after merge
  • Spot-check gel-doc / plate-reader image paths that use Pillow via scikit-image / matplotlib

Made with Cursor

… alerts.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vercel

vercel Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
data-hub Ready Ready Preview, Comment Jul 21, 2026 6:42pm

Request Review

@wasimxyz wasimxyz self-assigned this Jul 21, 2026
@wasimxyz
wasimxyz merged commit 974e44b into staging Jul 21, 2026
6 checks passed
@wasimxyz
wasimxyz deleted the fix/dependabot-security-alerts branch July 21, 2026 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant