Skip to content

Bump aiohttp from 3.14.0 to 3.14.1 - #105

Merged
amrit110 merged 1 commit into
mainfrom
dependabot/uv/aiohttp-3.14.1
Jun 20, 2026
Merged

Bump aiohttp from 3.14.0 to 3.14.1#105
amrit110 merged 1 commit into
mainfrom
dependabot/uv/aiohttp-3.14.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jun 17, 2026
@amrit110

Copy link
Copy Markdown
Member

Security Vulnerability — No Patch Available Yet

aieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:

Package Version Vulnerability Status
torch 2.11.0 CVE-2025-3000 No fix version available on PyPI

Why this cannot be auto-fixed

CVE-2025-3000 affects PyTorch's torch.jit.script function (memory corruption). pip-audit reports no fix version for the currently installed torch==2.11.0, and the vulnerability advisory does not list a patched release.

What was fixed in this PR

aieng-bot has bumped the following packages to resolve the other 7 vulnerabilities found:

Recommended next steps

  1. Monitor the CVE-2025-3000 advisory for a patch release
  2. Check if a pip-audit ignore/exception can be added temporarily with justification (requires human review)
  3. Consider whether the torch.jit.script usage can be replaced with torch.compile

This PR will not be auto-merged until the torch vulnerability is resolved.

@amrit110
amrit110 force-pushed the dependabot/uv/aiohttp-3.14.1 branch from 094cdf1 to eb6b7c2 Compare June 19, 2026 01:17
@amrit110

Copy link
Copy Markdown
Member

Security Vulnerability — No Patch Available Yet

aieng-bot found the following security vulnerability reported by pip-audit, but cannot fix it automatically because no patched version has been released to PyPI yet:

Package Version Vulnerability Fix Versions Status
torch 2.11.0 CVE-2025-3000 (none) No fix available on PyPI

Why this cannot be auto-fixed

The vulnerability CVE-2025-3000 exists in torch itself. A fix requires the upstream PyTorch maintainers to release a new version to PyPI. pip-audit confirms there is no patched version available at this time.

The CVE description: "A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption."

Recommended next steps

  1. Monitor the vulnerability advisory for a patch release from the PyTorch team
  2. Consider whether a pip-audit ignore/exception can be added temporarily with justification (requires human review)
  3. Once a patched release is published to PyPI, aieng-bot can re-run and apply the update automatically

This PR will not be auto-merged until the vulnerability is resolved.

@amrit110

Copy link
Copy Markdown
Member

Automated fix applied and PR merged

The agentic fix loop successfully fixed this PR and merged it.

✓ Successfully fixed security failures - Modified 0 files - Executed 177 agent actions - (107 info, 28 tool_call, 10 error, 19 tool_result, 13 reasoning)

View detailed trace on dashboard | Raw trace

AI Engineering Maintenance Bot

…nerabilities

- torch>=2.12.1 to address CVE-2025-3000 (memory corruption in torch.jit.script)
- pydantic-settings>=2.14.2 to address GHSA-4xgf-cpjx-pc3j
- msgpack>=1.2.1 to address GHSA-6v7p-g79w-8964

Co-authored-by: aieng-bot <aieng-bot@vectorinstitute.ai>
@amrit110
amrit110 force-pushed the dependabot/uv/aiohttp-3.14.1 branch from 9192937 to b7e33df Compare June 20, 2026 01:22
@amrit110
amrit110 merged commit 5e287a1 into main Jun 20, 2026
8 checks passed
@amrit110
amrit110 deleted the dependabot/uv/aiohttp-3.14.1 branch June 20, 2026 01:28
@amrit110

Copy link
Copy Markdown
Member

Automated fix applied and PR merged

The agentic fix loop successfully fixed this PR and merged it.

✓ Successfully fixed security failures - Modified 1 files - Executed 601 agent actions - (411 info, 80 tool_call, 18 error, 59 tool_result, 31 reasoning, 2 action)

View detailed trace on dashboard | Raw trace

AI Engineering Maintenance Bot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant