Skip to content

Update metrics lockfile for security dependency patches#5962

Open
arpitjain099 wants to merge 1 commit into
GSA:mainfrom
arpitjain099:security/metrics-deps-2026-05
Open

Update metrics lockfile for security dependency patches#5962
arpitjain099 wants to merge 1 commit into
GSA:mainfrom
arpitjain099:security/metrics-deps-2026-05

Conversation

@arpitjain099
Copy link
Copy Markdown

Summary

  • Refresh metrics/poetry.lock to update vulnerable packages: urllib3, python-dotenv, requests, pyasn1, and protobuf.
  • Keep changes scoped to the metrics dependency graph only.
  • Bring lockfile-resolved versions to patched ranges from current Dependabot advisories.

Why

This removes known vulnerable resolved versions in the metrics package set while avoiding functional code changes.

Validation

  • poetry check (run in metrics/)

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
@arpitjain099 arpitjain099 force-pushed the security/metrics-deps-2026-05 branch from 5b5fd11 to 8bf4477 Compare May 13, 2026 17:14
@arpitjain099
Copy link
Copy Markdown
Author

Hi @kgarcia181, gentle ping on this. PR has been open for 4 days without review. I noticed you've been on the recent-approver side of recent merges in this repo. When you have a moment, would you mind giving it a quick look? No urgency. Happy to address any feedback.

@arpitjain099
Copy link
Copy Markdown
Author

Pinging gently. Let me know if there's a path forward or if I should close it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant