Skip to content

Bump anyio from 4.14.1 to 4.15.1 (security) - #1031

Merged
LeMyst merged 1 commit into
masterfrom
fix-anyio-dependabot
Sep 19, 2026
Merged

LeMyst merged 1 commit into
masterfrom
fix-anyio-dependabot

Conversation

@LeMyst

@LeMyst LeMyst commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Resolves the 3 open Dependabot alerts on anyio (all patched in 4.14.2):

anyio is a transitive dependency of the optional docs and notebooks groups only, not a runtime dependency of the library. Only poetry.lock changes (poetry update anyio). The resolver also refreshed the typing_extensions marker and removed a stale dev group tag from soupsieve.

Offline test suite: 281 passed, 2 skipped.

🤖 Generated with Claude Code

Fixes GHSA-82r6-8w77-94w6 (critical), GHSA-3w57-8xmc-8v26 (high)
and GHSA-5p39-cfhj-2xmp (moderate). anyio is a transitive dependency
of the docs and notebooks groups only.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@LeMyst
LeMyst merged commit ea43abb into master Sep 19, 2026
15 checks passed
@LeMyst
LeMyst deleted the fix-anyio-dependabot branch September 19, 2026 12:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant