chore(deps): upgrade PyYAML to address known security vulnerability #11167

Closed
HAL9000 wants to merge 1 commit from pr-fix-9244 into master
Owner

Upgrades PyYAML dependency to version >=6.0.3 to address known YAML parsing security vulnerabilities. Adds explicit constraint in pyproject.toml and documents in CHANGELOG. Verifies no unsafe yaml.load() calls exist.

Closes #9055.

Upgrades PyYAML dependency to version >=6.0.3 to address known YAML parsing security vulnerabilities. Adds explicit constraint in pyproject.toml and documents in CHANGELOG. Verifies no unsafe yaml.load() calls exist. Closes #9055.
HAL9000 added this to the v3.2.0 milestone 2026-05-12 19:11:27 +00:00
chore(deps): upgrade PyYAML to address known security vulnerability (#9244)
All checks were successful
CI / push-validation (pull_request) Successful in 30s
CI / helm (pull_request) Successful in 42s
CI / build (pull_request) Successful in 1m11s
CI / lint (pull_request) Successful in 1m24s
CI / quality (pull_request) Successful in 1m37s
CI / typecheck (pull_request) Successful in 1m53s
CI / security (pull_request) Successful in 1m56s
CI / integration_tests (pull_request) Successful in 4m59s
CI / unit_tests (pull_request) Successful in 5m5s
CI / docker (pull_request) Successful in 1m42s
CI / coverage (pull_request) Successful in 10m51s
CI / status-check (pull_request) Successful in 3s
5ad7701828
- Add explicit `pyyaml>=6.0.3` constraint to pyproject.toml dependencies with a security comment
- Add a `\#\#\# Security` section to CHANGELOG.md documenting this dependency constraint update
- Verify no unsafe yaml.load() calls exist in the codebase

Co-authored-by: HAL 9000 <hal9000@cleverthis.com>
ISSUES CLOSED: #9055
HAL9000 closed this pull request 2026-05-12 19:56:12 +00:00
All checks were successful
CI / push-validation (pull_request) Successful in 30s
CI / helm (pull_request) Successful in 42s
CI / build (pull_request) Successful in 1m11s
Required
Details
CI / lint (pull_request) Successful in 1m24s
Required
Details
CI / quality (pull_request) Successful in 1m37s
Required
Details
CI / typecheck (pull_request) Successful in 1m53s
Required
Details
CI / security (pull_request) Successful in 1m56s
Required
Details
CI / integration_tests (pull_request) Successful in 4m59s
Required
Details
CI / unit_tests (pull_request) Successful in 5m5s
Required
Details
CI / docker (pull_request) Successful in 1m42s
Required
Details
CI / coverage (pull_request) Successful in 10m51s
Required
Details
CI / status-check (pull_request) Successful in 3s

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
cleveragents/cleveragents-core!11167
No description provided.