chore(deps): bump starlette from 1.2.1 to 1.3.1#197
Conversation
Resolves: - CVE-2026-54283 (HIGH): request.form() limits silently ignored - CVE-2026-54282 (LOW): unvalidated request path hostname poisoning Signed-off-by: Sudip Sinha <Sudip.Sinha@RedHat.com>
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
PR image build and manifest generation completed successfully! 📦 PR image: 🗂️ CI manifests |
Summary
Bump starlette from 1.2.1 to 1.3.1 via lockfile update.
Security fixes
request.form()size limits silently ignored forapplication/x-www-form-urlencoded, enabling DoSrequest.url.hostnameNote
The remaining Dependabot alert (CVE-2026-54293, nltk path traversal) has no fix available — all versions including 3.9.4 (latest) are affected.
🤖 Generated with Claude Code