Skip to content

Commit b12fd8e

Browse files
Merge pull request #830 from microsoft/bugfix/vulnerabilities
fix: dependabot security alerts
2 parents cc95562 + bb9b76c commit b12fd8e

7 files changed

Lines changed: 269 additions & 256 deletions

File tree

src/backend/pyproject.toml

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,13 +26,19 @@ dependencies = [
2626
"pytest-asyncio==0.24.0",
2727
"pytest-cov==5.0.0",
2828
"python-dotenv==1.1.1",
29-
"python-multipart==0.0.20",
30-
"semantic-kernel==1.39.3",
29+
"python-multipart==0.0.22",
30+
"semantic-kernel==1.39.4",
3131
"uvicorn==0.35.0",
3232
"pylint-pydantic==0.3.5",
3333
"pexpect==4.9.0",
34-
"mcp==1.23.0",
34+
"mcp==1.26.0",
3535
"werkzeug==3.1.5",
3636
"azure-core==1.38.0",
3737
"agent-framework>=1.0.0b251105",
38+
"urllib3==2.6.3",
39+
"protobuf==5.29.6",
40+
"cryptography==46.0.5",
41+
"aiohttp==3.13.3",
42+
"pyasn1==0.6.2",
43+
"nltk==3.9.3",
3844
]

src/backend/requirements.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,9 +14,9 @@ opentelemetry-instrumentation-fastapi
1414
opentelemetry-instrumentation-openai
1515
opentelemetry-exporter-otlp-proto-http
1616

17-
semantic-kernel[azure]==1.32.2
18-
azure-ai-projects==1.0.0b11
19-
openai==1.84.0
17+
semantic-kernel[azure]==1.39.4
18+
azure-ai-projects==1.0.0
19+
openai==1.105.0
2020
azure-ai-inference==1.0.0b9
2121
azure-search-documents
2222
azure-ai-evaluation

src/backend/uv.lock

Lines changed: 181 additions & 175 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

src/frontend/package-lock.json

Lines changed: 9 additions & 9 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

src/frontend/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
"@types/node": "^16.18.126",
1616
"@types/react": "^18.3.23",
1717
"@types/react-dom": "^18.3.7",
18-
"axios": "^1.11.0",
18+
"axios": "^1.13.5",
1919
"react": "^18.3.1",
2020
"react-dom": "^18.3.1",
2121
"react-markdown": "^10.1.0",
@@ -68,4 +68,4 @@
6868
"vite": "^7.1.2",
6969
"vitest": "^3.2.4"
7070
}
71-
}
71+
}

src/mcp_server/pyproject.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,10 +21,12 @@ dependencies = [
2121
"azure-identity==1.19.0",
2222
"pydantic==2.11.7",
2323
"pydantic-settings==2.6.1",
24-
"python-multipart==0.0.18",
24+
"python-multipart==0.0.22",
2525
"httpx==0.28.1",
2626
"werkzeug==3.1.5",
2727
"urllib3==2.6.3",
28+
"azure-core==1.38.0",
29+
"cryptography==46.0.5",
2830
]
2931

3032
[project.optional-dependencies]

src/mcp_server/uv.lock

Lines changed: 62 additions & 63 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)