From d62970ee1b8149515165db4f90c552cdf9d3f1f9 Mon Sep 17 00:00:00 2001 From: Thorsten Date: Sun, 6 Sep 2026 21:26:10 +0200 Subject: [PATCH] Fix backend dependency vulnerabilities (36 CVEs across 6 packages) Upgrades fastapi (0.115.6->0.141.1, pulling starlette to 1.6.0), fastapi-users (14.0.1->15.0.5), aiosmtplib (3.0.2->5.1.2), python-multipart (0.0.20->0.0.32), and sentence-transformers (3.3.1->6.0.1, pulling transformers and pyjwt to patched versions). Verified via pip-audit (zero remaining findings across all 97 resolved dependencies) and functional smoke tests: auth flow, RAG embedding/retrieval (dimension still 384, similarity still sane), DM-turn tool-calling (roll_dice still fires correctly), and a live WebSocket handshake/send/broadcast round trip against the upgraded Starlette. Co-Authored-By: Claude Sonnet 5 --- backend/requirements.txt | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/backend/requirements.txt b/backend/requirements.txt index 0caedc6..9b9f15d 100644 --- a/backend/requirements.txt +++ b/backend/requirements.txt @@ -1,13 +1,13 @@ -fastapi==0.115.6 +fastapi==0.141.1 uvicorn[standard]==0.34.0 sqlalchemy[asyncio]==2.0.36 asyncpg==0.30.0 alembic==1.14.0 pydantic-settings==2.7.0 -fastapi-users[sqlalchemy]==14.0.1 +fastapi-users[sqlalchemy]==15.0.5 openai>=1.50.0,<2.0.0 -aiosmtplib==3.0.2 -python-multipart==0.0.20 +aiosmtplib==5.1.2 +python-multipart==0.0.32 websockets==14.1 pgvector==0.3.6 -sentence-transformers==3.3.1 +sentence-transformers==6.0.1