Skip to content

deps: bump jupyter-server to 2.21.0 in py3.10 CI lock (GHSA-c3mw-737p-c7g2) - #6851

Open
katsugtgz wants to merge 1 commit into
feast-dev:masterfrom
katsugtgz:deps/jupyter-server-2.21.0
Open

katsugtgz wants to merge 1 commit into
feast-dev:masterfrom
katsugtgz:deps/jupyter-server-2.21.0

Conversation

@katsugtgz

Copy link
Copy Markdown

Updates jupyter-server to address GHSA-c3mw-737p-c7g2 (CVE-2026-86049, Referer header leak in 5xx request logging).

Evidence:

  • sdk/python/requirements/py3.10-ci-requirements.txt pinned jupyter-server==2.20.0
  • pip-audit reported GHSA-c3mw-737p-c7g2 against that pin
  • updated version: 2.21.0

Validation:

  • pip-audit no longer reports the advisory for jupyter-server==2.21.0
  • both PyPI hashes updated from the jupyter-server 2.21.0 release; pip download --require-hashes verifies them
  • surgical edit of the single lock entry; no other pins touched

Scope: CI requirements lock entry only.

@katsugtgz
katsugtgz requested a review from a team as a code owner September 19, 2026 03:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant