mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-08-09 23:33:12 +00:00
OSV weekly scan reported 50 known vulnerabilities in pinned deps. This bumps everything with a released, semver-compatible fix: Python (uv.lock): - aiohttp 3.14.1 -> 3.14.3 (GHSA-cq5v-8q36-5273, GHSA-mfx4-hv73-q22v, GHSA-mq44-7p77-q5h7) - h2 4.3.0 -> 4.4.1 (CVE-2026-71554 request smuggling; exclude-newer exception documented in pyproject, remove after 2026-08-17) npm (root workspace): - brace-expansion 5.0.8 -> 5.0.9, undici 6.27->6.28 / 7.28->7.29, js-yaml 4.3.1, nanoid 3.3.17/3.3.18, ip-address 10.4.0, mermaid 11.16.1 + dompurify 3.4.13 (root overrides so the streamdown transitive copy is pinned too) - electron 40.10.2 -> 40.10.6 (GHSA-r4w5-6pfg-jxp5; the 41.x major for GHSA-9f4c-93c8-jc8g is deferred to its own PR) npm (website): mermaid, dompurify, js-yaml, nanoid, fast-uri 3.1.5, postcss 8.5.23, undici 7.29.0 npm (photon sidecar): @opentelemetry/core 2.8.0 via override, undici npm (whatsapp-bridge): body-parser 1.20.6 min-release-age excludes added to .npmrc/website/.npmrc for the sub-2wk CVE-fix releases, each with a removal date. Remaining findings are blocked upstream: cryptography <49 cap (alibabacloud-tea-openapi), image-size (no fixed release), tar 6.x transitive majors, electron 41. Local rescan: 50 -> 19 known vulns, 0 introduced.