Commit ba4db7d
fix: upgrade vulnerable dependencies across agentex services
agentex backend:
- python-multipart 0.0.12 → 0.0.22 (CVE-2024-53981, CVE-2026-24486)
- temporalio 1.18.0 → 1.23.0 (CVE-2026-31812 quinn-proto, pending re-scan)
agentex-ui:
- next 15.5.9 → 15.5.10 (GHSA-h25m-26qc-wcjf)
- minimatch, tar, rollup, flatted transitive deps (13 CVEs via npm audit fix)
Remaining:
- starlette CVE-2025-62727: blocked on agentex-sdk widening fastapi
constraint (scaleapi/scale-agentex-python#285)
- libvips x3 + python-3.12: auto-fix on next rebuild against latest
Chainguard golden base
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>1 parent 88218f6 commit ba4db7d
File tree
4 files changed
+206
-135
lines changed- agentex-ui
- agentex
4 files changed
+206
-135
lines changed
0 commit comments