Skip to content

chore: bump aiohttp to 3.14.3 to patch security vulnerabilities - #3995

Merged
dnechay merged 2 commits into
developfrom
dzeranov/bump-aiohttp
Aug 5, 2026
Merged

chore: bump aiohttp to 3.14.3 to patch security vulnerabilities#3995
dnechay merged 2 commits into
developfrom
dzeranov/bump-aiohttp

Conversation

@Dzeranov

@Dzeranov Dzeranov commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Issue tracking

N/A

Context behind the change

Bumped aiohttp package to 3.14.3 as per https://github.com/humanprotocol/human-protocol/actions/runs/30901488755/job/91966585685

@Dzeranov
Dzeranov requested a review from zhiltsov-max August 4, 2026 12:11
@vercel

vercel Bot commented Aug 4, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
human-app Ready Ready Preview Aug 4, 2026 1:57pm
human-dashboard-frontend Ready Ready Preview Aug 4, 2026 1:57pm
staking-dashboard Ready Ready Preview Aug 4, 2026 1:57pm
2 Skipped Deployments
Project Deployment Actions Updated (UTC)
faucet-frontend Ignored Ignored Preview Aug 4, 2026 1:57pm
faucet-server Ignored Ignored Preview Aug 4, 2026 1:57pm

Request Review

@zhiltsov-max

zhiltsov-max commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

The dependency has to be declared in pyproject.toml like "aiohttp>=xxx". Updating just the lockfile introduces the risk that the change will be just overwritten by the next automatic lockfile update.

@dnechay
dnechay merged commit 68a20e4 into develop Aug 5, 2026
15 checks passed
@dnechay
dnechay deleted the dzeranov/bump-aiohttp branch August 5, 2026 10:25
@dnechay dnechay mentioned this pull request Aug 5, 2026
25 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants