chore(security): bump bandit to 1.12.5 (HIGH in the request path) #13

Merged
jlxq0 merged 1 commit from sec-bump-bandit into main 2026-09-02 09:38:57 +00:00
Owner
No description provided.
chore(security): bump bandit to 1.12.5
All checks were successful
CI / Quality gate (pull_request) Successful in 16s
CI / Build and push image (pull_request) Has been skipped
be32b3c02c
Fixes EEF-CVE-2026-74836 (HIGH, HTTP/2 connection-window starvation pins Plug
processes) and EEF-CVE-2026-75484 (MEDIUM, HTTP/2 header CR/LF/NUL passed
unvalidated) in the request path. Confirmed by mix deps.get: bandit no longer
lists as VULNERABLE after the bump. mix ci green, 17 passed.

Patch bump, lock only. Found by a lead reading mix deps.get output rather than
by any gate: mix deps.audit reports clean here (its own advisory DB, not OSV),
and no Renovate config watches this mix.lock. jlxq0/mantis#324.
jlxq0 merged commit e42a69784b into main 2026-09-02 09:38:57 +00:00
jlxq0 deleted branch sec-bump-bandit 2026-09-02 09:38:57 +00:00
Sign in to join this conversation.
No description provided.