Skip to content
This repository was archived by the owner on Nov 26, 2025. It is now read-only.

chore: bump aiohttp from 3.12.13 to 3.12.14 in the pip group#185

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/pip/pip-cdbe78a3a0
Open

chore: bump aiohttp from 3.12.13 to 3.12.14 in the pip group#185
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/pip/pip-cdbe78a3a0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 15, 2025

Bumps the pip group with 1 update: aiohttp.

Updates aiohttp from 3.12.13 to 3.12.14

Release notes

Sourced from aiohttp's releases.

3.12.14

Bug fixes

  • Fixed file uploads failing with HTTP 422 errors when encountering 307/308 redirects, and 301/302 redirects for non-POST methods, by preserving the request body when appropriate per :rfc:9110#section-15.4.3-3.1 -- by :user:bdraco.

    Related issues and pull requests on GitHub: #11270.

  • Fixed :py:meth:ClientSession.close() <aiohttp.ClientSession.close> hanging indefinitely when using HTTPS requests through HTTP proxies -- by :user:bdraco.

    Related issues and pull requests on GitHub: #11273.

  • Bumped minimum version of aiosignal to 1.4+ to resolve typing issues -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: #11280.

Features

  • Added initial trailer parsing logic to Python HTTP parser -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: #11269.

Improved documentation

  • Clarified exceptions raised by WebSocketResponse.send_frame et al. -- by :user:DoctorJohn.

    Related issues and pull requests on GitHub: #11234.

... (truncated)

Changelog

Sourced from aiohttp's changelog.

3.12.14 (2025-07-10)

Bug fixes

  • Fixed file uploads failing with HTTP 422 errors when encountering 307/308 redirects, and 301/302 redirects for non-POST methods, by preserving the request body when appropriate per :rfc:9110#section-15.4.3-3.1 -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:11270.

  • Fixed :py:meth:ClientSession.close() <aiohttp.ClientSession.close> hanging indefinitely when using HTTPS requests through HTTP proxies -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:11273.

  • Bumped minimum version of aiosignal to 1.4+ to resolve typing issues -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:11280.

Features

  • Added initial trailer parsing logic to Python HTTP parser -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub: :issue:11269.

Improved documentation

  • Clarified exceptions raised by WebSocketResponse.send_frame et al. -- by :user:DoctorJohn.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the pip group with 1 update: [aiohttp](https://github.com/aio-libs/aiohttp).


Updates `aiohttp` from 3.12.13 to 3.12.14
- [Release notes](https://github.com/aio-libs/aiohttp/releases)
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.12.13...v3.12.14)

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.12.14
  dependency-type: indirect
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Jul 15, 2025
@github-actions
Copy link

Preview Has Been Created or Updated!

The Preview Image URL is ghcr.io/garyellow/ntpu-linebot:dependabot-pip-pip-cdbe78a3a0.

@github-actions
Copy link

Your image moby/buildkit:buildx-stable-1 critical: 0 high: 7 medium: 7 low: 1
Current base image alpine:3 critical: 0 high: 0 medium: 0 low: 0
Refreshed base image alpine:3 critical: 0 high: 0 medium: 1 low: 0

@github-actions
Copy link

🔍 Vulnerabilities of moby/buildkit:buildx-stable-1

📦 Image Reference moby/buildkit:buildx-stable-1
digestsha256:72a94020693fa94cecaf87505088224ff3246270ea64b291a4aaf63fd4b41f3c
vulnerabilitiescritical: 0 high: 7 medium: 7 low: 1
platformlinux/amd64
size108 MB
packages250
📦 Base Image alpine:3
also known as
  • 3.21
  • 3.21.3
  • latest
digestsha256:1c4eef651f65e2f7daee7ee785882ac164b02b78fb74503052a26dc061c90474
vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
critical: 0 high: 5 medium: 1 low: 1 git 2.47.2-r0 (apk)

pkg:apk/alpine/git@2.47.2-r0?os_name=alpine&os_version=3.21

high : CVE--2025--48385

Affected range<2.47.3-r0
Fixed version2.47.3-r0
EPSS Score0.102%
EPSS Percentile29th percentile
Description

high : CVE--2025--46334

Affected range<2.47.3-r0
Fixed version2.47.3-r0
EPSS Score0.019%
EPSS Percentile3rd percentile
Description

high : CVE--2025--27614

Affected range<2.47.3-r0
Fixed version2.47.3-r0
EPSS Score0.020%
EPSS Percentile4th percentile
Description

high : CVE--2025--46835

Affected range<2.47.3-r0
Fixed version2.47.3-r0
EPSS Score0.021%
EPSS Percentile4th percentile
Description

high : CVE--2025--48384

Affected range<2.47.3-r0
Fixed version2.47.3-r0
EPSS Score0.014%
EPSS Percentile2nd percentile
Description

medium : CVE--2025--48386

Affected range<2.47.3-r0
Fixed version2.47.3-r0
EPSS Score0.014%
EPSS Percentile2nd percentile
Description

low : CVE--2025--27613

Affected range<2.47.3-r0
Fixed version2.47.3-r0
EPSS Score0.017%
EPSS Percentile3rd percentile
Description
critical: 0 high: 1 medium: 2 low: 0 stdlib 1.24.3 (golang)

pkg:golang/stdlib@1.24.3

high : CVE--2025--22874

Affected range>=1.24.0-0
<1.24.4
Fixed version1.24.4
EPSS Score0.024%
EPSS Percentile5th percentile
Description

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

medium : CVE--2025--4673

Affected range>=1.24.0-0
<1.24.4
Fixed version1.24.4
EPSS Score0.044%
EPSS Percentile13th percentile
Description

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

medium : CVE--2025--0913

Affected range>=1.24.0-0
<1.24.4
Fixed version1.24.4
EPSS Score0.015%
EPSS Percentile2nd percentile
Description

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

critical: 0 high: 1 medium: 2 low: 0 stdlib 1.24.2 (golang)

pkg:golang/stdlib@1.24.2

high : CVE--2025--22874

Affected range>=1.24.0-0
<1.24.4
Fixed version1.24.4
EPSS Score0.024%
EPSS Percentile5th percentile
Description

Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.

medium : CVE--2025--4673

Affected range>=1.24.0-0
<1.24.4
Fixed version1.24.4
EPSS Score0.044%
EPSS Percentile13th percentile
Description

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

medium : CVE--2025--0913

Affected range>=1.24.0-0
<1.24.4
Fixed version1.24.4
EPSS Score0.015%
EPSS Percentile2nd percentile
Description

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

critical: 0 high: 0 medium: 2 low: 0 golang.org/x/net 0.33.0 (golang)

pkg:golang/golang.org/x/net@0.33.0

medium 5.3: CVE--2025--22872 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected range<0.38.0
Fixed version0.38.0
CVSS Score5.3
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS Score0.033%
EPSS Percentile8th percentile
Description

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. , , etc contexts).

medium 4.4: CVE--2025--22870 Misinterpretation of Input

Affected range<0.36.0
Fixed version0.36.0
CVSS Score4.4
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
EPSS Score0.014%
EPSS Percentile1st percentile
Description

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied.

@github-actions
Copy link

Recommended fixes for image moby/buildkit:buildx-stable-1

Base image is alpine:3

Name3.21.3
Digestsha256:1c4eef651f65e2f7daee7ee785882ac164b02b78fb74503052a26dc061c90474
Vulnerabilitiescritical: 0 high: 0 medium: 0 low: 0
Pushed5 months ago
Size3.6 MB
Packages19
OS3.21.3
The base image is also available under the supported tag(s): 3.21, 3.21.3, latest

Refresh base image

Rebuild the image using a newer base image version. Updating this may result in breaking changes.
TagDetailsPushedVulnerabilities
3
Newer image for same tag
Also known as:
  • 3.22.0
  • 3.22
  • latest
Benefits:
  • Newer image for same tag
  • Minor OS version update
  • Tag was pushed more recently
  • Image has similar size
  • Tag is latest
  • Image contains similar number of packages
  • 3 was pulled 251K times last month
Image details:
  • Size: 3.8 MB
  • OS: 3.22.0
1 month ago



Change base image

✅ There are no tag recommendations at this time.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants