Skip to content

Conversation

@jeff-schnitter
Copy link
Collaborator

Summary

  • Update urllib3 dependency from >= 2.2.2 to >= 2.6.0 in pyproject.toml to address CVE-2025-66418 and CVE-2025-66471
  • Sync local homebrew formula with tap and update urllib3 resource to 2.6.3
  • Document homebrew dependency update limitations in CLAUDE.md
  • Document branch naming convention in CLAUDE.md

Test plan

  • Verify PR CI passes
  • After merge, update cortexapps/homebrew-tap formula with urllib3 2.6.3 resource

Closes #186

🤖 Generated with Claude Code

jeff-schnitter and others added 3 commits January 9, 2026 15:42
Addresses security vulnerabilities in urllib3 versions < 2.6.0.

Closes #186

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Updated homebrew/cortexapps-cli.rb to match current tap formula
- Updated urllib3 resource from 2.4.0 to 2.6.3 (addresses CVEs)
- Added documentation about homebrew dependency update limitations

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@jeff-schnitter jeff-schnitter merged commit 4fba98b into main Jan 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: Update urllib3 to address CVE-2025-66418 and CVE-2025-66471

2 participants