From 1fe54c9659b0129e3a1ed423d00e90a74e435906 Mon Sep 17 00:00:00 2001 From: Alexsander Hamir Date: Mon, 5 Jan 2026 16:57:47 -0800 Subject: [PATCH] Fix security vulnerability: update fastapi-sso from 0.16.0 to 0.19.0 - Fixes GHSA-hp6r-r9vc-q8wx (CSRF vulnerability, CVSS 6.3) - Update in both pyproject.toml and requirements.txt --- pyproject.toml | 2 +- requirements.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index b8096d8ae9a..0df0ecf2d88 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -43,7 +43,7 @@ pyyaml = {version = "^6.0.1", optional = true} rq = {version = "*", optional = true} orjson = {version = "^3.9.7", optional = true} apscheduler = {version = "^3.10.4", optional = true} -fastapi-sso = { version = "^0.16.0", optional = true } +fastapi-sso = { version = "^0.19.0", optional = true } PyJWT = { version = "^2.10.1", optional = true, python = ">=3.9" } python-multipart = { version = "^0.0.18", optional = true} cryptography = {version = "*", optional = true} diff --git a/requirements.txt b/requirements.txt index 0db5e5fe735..df7bc8b3242 100644 --- a/requirements.txt +++ b/requirements.txt @@ -28,7 +28,7 @@ ddtrace==2.19.0 # for advanced DD tracing / profiling orjson==3.11.2 # fast /embedding responses polars==1.31.0 # for data processing apscheduler==3.10.4 # for resetting budget in background -fastapi-sso==0.16.0 # admin UI, SSO +fastapi-sso==0.19.0 # admin UI, SSO pyjwt[crypto]==2.10.1 ; python_version >= "3.9" python-multipart==0.0.18 # admin UI Pillow==11.0.0