Skip to content

fix(deps): pin 2 vulnerable dependencies (4 alerts) - #3

Open
cw-ananke[bot] wants to merge 1 commit into
mainfrom
ananke-dependabot-1786128733210
Open

fix(deps): pin 2 vulnerable dependencies (4 alerts)#3
cw-ananke[bot] wants to merge 1 commit into
mainfrom
ananke-dependabot-1786128733210

Conversation

@cw-ananke

@cw-ananke cw-ananke Bot commented Aug 7, 2026

Copy link
Copy Markdown

Dependabot Resolution

Resolves 4 open Dependabot alerts by pinning vulnerable dependencies to their patched versions.

Dependency From To Alerts
pyo3 0.23 0.29.0 2
diffusers ==0.37.0 0.38.0 2

Files changed

  • rust/sglang-grpc/Cargo.toml
  • sgl-model-gateway/bindings/python/Cargo.toml
  • 3rdparty/amd/wheel/sglang/pyproject.toml
  • python/pyproject.toml

Generated by ananke Dependabot resolver.


CI States

Latest PR Test (Base): ❌ Run #31208929438
Latest PR Test (Extra): 🚫 Run #31208930318

@cloudwalk-review-agent cloudwalk-review-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

Dependency bumps are consistent with the PR goal of remediating known vulnerabilities:

  • pyo3 updated to =0.29.0 in both Rust bindings crates
  • diffusers updated to 0.38.0 in both Python dependency manifests

I did not find concrete correctness, security, or deploy-safety issues in the provided diff. One notable non-functional side effect is that python/pyproject.toml file mode changed from 100755 to 100644, which is generally appropriate for a TOML manifest and should be safe.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants