Skip to content

ci: bump msgpack from 1.1.2 to 1.2.1 #154

ci: bump msgpack from 1.1.2 to 1.2.1

ci: bump msgpack from 1.1.2 to 1.2.1 #154

Triggered via pull request June 23, 2026 22:00
Status Failure
Total duration 1m 0s
Artifacts 1

ci.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

2 errors, 9 warnings, and 10 notices
Security audit
Process completed with exit code 1.
Security audit
Process completed with exit code 1.
Security audit
pip-audit: urllib3@2.6.3 — PYSEC-2026-141 (fix: 2.7.0)
Security audit
pip-audit: urllib3@2.6.3 — PYSEC-2026-142 (fix: 2.7.0)
Security audit
pip-audit: urllib3@2.6.3 — PYSEC-2026-142 (fix: 2.7.0)
Security audit
pip-audit: pydantic-settings@2.13.1 — GHSA-4xgf-cpjx-pc3j (fix: 2.14.2)
Security audit
pip-audit: pip@26.0.1 — CVE-2026-6357 (fix: 26.1)
Security audit
pip-audit: pip@26.0.1 — CVE-2026-3219 (fix: 26.1)
Security audit
pip-audit: pip@26.0.1 — PYSEC-2026-196 (fix: 26.1.2)
Security audit
pip-audit: idna@3.11 — PYSEC-2026-215 (fix: 3.15)
Pre-commit
Failed to save: Unable to reserve cache with key setup-uv-2-x86_64-unknown-linux-gnu-ubuntu-24.04-3.13.14-pruned-3abcbf1bc56e7309cd0f771a3fd3dfdf65dcc60e1720ae26b5393af3b4f21116, another job may be creating this cache.
Security audit: src/python_security_auditing/runners.py#L86
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/runners.py#L79
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/runners.py#L71
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/runners.py#L53
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/runners.py#L7
[B404] Consider possible security implications associated with the subprocess module.
Security audit: src/python_security_auditing/pr_comment.py#L101
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/pr_comment.py#L88
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/pr_comment.py#L76
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/pr_comment.py#L35
[B603] subprocess call - check for execution of untrusted input.
Security audit: src/python_security_auditing/pr_comment.py#L7
[B404] Consider possible security implications associated with the subprocess module.

Artifacts

Produced during runtime
Name Size Digest
security-audit-reports Expired
7.21 KB
sha256:7ab5aacfd87066f641fcbf82bd4664683ade5e80bae26477679f1eda81c9520f