chore(deps): bump aiohttp from 3.14.1 to 3.14.3 - #1082
Conversation
Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.14.1 to 3.14.3. - [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst) - [Commits](aio-libs/aiohttp@v3.14.1...v3.14.3) --- updated-dependencies: - dependency-name: aiohttp dependency-version: 3.14.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Dependabot Triage — PR #1082: aiohttp 3.14.1 → 3.14.3Classification
Key observations
RecommendationMerge now Patch-level bump inside the same minor line that clears one high and two medium advisories, including a memory-safety bug in the HTTP parser. Small, well-aged, no supply-chain signals. Follow-up actions
Supply-chain triage per the |
|
@dependabot rebase |
|
I can't perform the requested action because I don't have any knowledge about this pull request. |
|
Claude finished @frankbria's task in 2m 16s —— View job GLM Precision Review — PR #1082 (aiohttp 3.14.1 → 3.14.3)Scope: concrete code defects only (logic errors, security, data loss, races, breaking API/contract changes, resource leaks). Style/architecture/tests/supply-chain are covered by the general review.
Result: no defects found. The diff is Formal summary posted via |
ReviewConfirmed this is a pure Agreeing with the prior triage comment on this PR: patch-level bump within the same minor line (3.14.x) that resolves one high-severity (
No concerns. Safe to merge once CI is green. |
|
✅ GLM review: no defects found. Scope was concrete code defects only (logic/security/data-loss/races/breaking-contract/resource-leaks). This PR is a General review (style/architecture/tests/supply-chain) is covered separately. |
Bumps aiohttp from 3.14.1 to 3.14.3.
Changelog
Sourced from aiohttp's changelog.
... (truncated)
Commits
5e392ceRelease v3.14.3 (#13225)49f65d5[PR #13222/f4866933 backport][3.14] Build C parser error message from bounded...240099e[PR #13180/ee53d655 backport][3.14] drop every copy of credential headers on ...d93f30aBump version (#13202)c1b9212Release v3.14.2 (#13201)380d4b5[PR #13054/ed8b040c backport][3.14] escape backslashes in digest auth quoted-...e1e1beeMake llhttp method array size dynamic (#13174) (#13196)aa4cf29[PR #13170/2b906869 backport][3.14] Fix StreamResponse.last_modified rounding...71b57b4[PR #13172/a57747ed backport][3.14] Fix C parser folding fragment into query_...64a03fb[PR #13169/1adc0cd7 backport][3.14] Upgrade http:// to https:// in README.rst...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.