Skip to content

fix(api): upgrade vulnerable Python dependencies - #1794

Open
Jacky-Pham wants to merge 1 commit into
mainfrom
Jacky/regbacklog-364-python-dependencies
Open

fix(api): upgrade vulnerable Python dependencies#1794
Jacky-Pham wants to merge 1 commit into
mainfrom
Jacky/regbacklog-364-python-dependencies

Conversation

@Jacky-Pham

@Jacky-Pham Jacky-Pham commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

Issue:

  • GitHub: Repository security alerts; no corresponding GitHub issue
  • JIRA: REGBACKLOG-364

Description of changes:

  • Upgrade Flask, Flask-CORS, Gunicorn, WeasyPrint, pytest, and Black to patched versions
  • Refresh the STRR API Poetry lockfile so affected transitive packages use patched versions
  • Update the Flask version check for Flask 3.1
  • Apply the formatting required by Black 26

The old versions have known security problems. These changes move the API to patched versions without changing its responses or business rules.


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of the BC Registry and Digital Services BSD 3-Clause License

@sonarqubecloud

sonarqubecloud Bot commented Sep 3, 2026

Copy link
Copy Markdown

@Jacky-Pham
Jacky-Pham marked this pull request as ready for review September 3, 2026 18:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant