Skip to content

update h11 via httpx#856

Merged
paul-butcher merged 1 commit into
mainfrom
h11-0.16
Jun 9, 2025
Merged

update h11 via httpx#856
paul-butcher merged 1 commit into
mainfrom
h11-0.16

Conversation

@paul-butcher
Copy link
Copy Markdown
Contributor

@paul-butcher paul-butcher commented Jun 3, 2025

What does this change?

This updates h11 to a version that does not suffer from CVE-2025-43859
Resolving

See also: wellcomecollection/catalogue-pipeline#2920

Part of wellcomecollection/platform#5796

How to test

Everything should just work exactly the same as before

How can we measure success?

Three fewer vulnerability warnings reported by Dependabot

Have we considered potential risks?

We do not directly use h11, so it is unlikely that this will cause any issues - if the developers of httpcore and httpx are happy with it, then so are we.

If things stop working, then we can roll this back.

@paul-butcher paul-butcher merged commit 98ba35f into main Jun 9, 2025
6 checks passed
@github-project-automation github-project-automation Bot moved this from Ready for review to Done in Digital platform Jun 9, 2025
@paul-butcher paul-butcher deleted the h11-0.16 branch June 9, 2025 16:40
@pollecuttn pollecuttn moved this from Done to Archive in Digital platform Jun 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

3 participants