Skip to content

Conversation

@jsjiang
Copy link
Contributor

@jsjiang jsjiang commented Jan 6, 2026

@sfisher Hi Scott,
Here are the changes:

  • upgrade filelock to 3.20.1 or newer to resolve a security alert.
  • update urllib3 from "2.6.0" to "^2.6.0" to allow compatible updates, which is consistent with the versioning pattern used for all other dependencies in this file.

Please review and let me know if you have quesitons.

Thank you

Jing

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR upgrades two dependencies to address a security alert and improve version flexibility: filelock is upgraded from ^3.18.0 to ^3.20.1, and urllib3 is changed from an exact version "2.6.0" to a caret range "^2.6.0" to allow compatible minor version updates.

Key changes:

  • Upgrade filelock minimum version to 3.20.1 to resolve a security vulnerability
  • Change urllib3 from exact version pinning to caret versioning for flexible updates
  • Update poetry.lock with resulting dependency version changes

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
pyproject.toml Updated filelock to ^3.20.1 and urllib3 to ^2.6.0 with caret versioning
poetry.lock Reflects the dependency resolution with filelock 3.20.2, urllib3 2.6.2, and transitive dependency updates (boto3, botocore, certifi, sqlparse, tzdata)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link
Contributor

@sfisher sfisher left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me. Thanks, @jsjiang .

@jsjiang jsjiang merged commit c854ac1 into develop Jan 7, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants