Patch 0.31.5: pin transitive security floors (tqdm, idna)

backend/requirements.txt carries only loose `>=` direct constraints and
no compiled lockfile, so osv-scanner v2 resolves the transitive graph and
pins each unpinned transitive package to its MINIMUM published version —
surfacing CVEs in ancient releases pip would never install. That fired a
phantom HIGH (tqdm 4.9.0, GHSA-r7q7-xcjw-qx8q) plus an idna finding on the
OHM Patchwatch radar, even though the live deployment runs patched versions.

Add `tqdm>=4.66.3` and `idna>=3.15` to anchor the resolver to the patched
range. osv-scanner now reports zero findings. No direct-import / schema /
API / config change; deployed installs already satisfy the floors.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Ben Stull
2026-06-03 07:56:14 -07:00
parent 551d240967
commit cdbc8078b6
4 changed files with 35 additions and 2 deletions
+1 -1
View File
@@ -1,7 +1,7 @@
{
"name": "rfc-app-frontend",
"private": true,
"version": "0.31.4",
"version": "0.31.5",
"type": "module",
"scripts": {
"dev": "vite",