Skip to content

Conversation

@pre-commit-ci
Copy link
Contributor

@pre-commit-ci pre-commit-ci bot commented Dec 22, 2025

updates:
- [github.com/astral-sh/ruff-pre-commit: v0.14.9 → v0.14.10](astral-sh/ruff-pre-commit@v0.14.9...v0.14.10)
- [github.com/crate-ci/typos: v1 → typos-dict-v0.13.13](crate-ci/typos@v1...typos-dict-v0.13.13)
@amrit110 amrit110 force-pushed the pre-commit-ci-update-config branch from 38ab68b to a01be4a Compare December 27, 2025 16:22
Security updates:
- Update filelock from 3.19.1 to 3.20.1 (fixes GHSA-w853-jp5j-5j7f)

Severity: High

This update fixes a Time-of-Check-Time-of-Use (TOCTOU) race condition
that allows local attackers to corrupt or truncate arbitrary user files
through symlink attacks. The fix adds O_NOFOLLOW flag on Unix systems
and GetFileAttributesW API check on Windows to prevent symlink following.

Verified with pip-audit: No known vulnerabilities found.

Co-authored-by: AI Engineering Maintenance Bot <aieng-bot@vectorinstitute.ai>
Copy link
Member

@amrit110 amrit110 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ All checks passed. Auto-approving bot PR.

🤖 AI Engineering Maintenance Bot - Maintaining Vector Institute Repositories built by AI Engineering

@amrit110 amrit110 merged commit 42a8b64 into main Dec 27, 2025
7 checks passed
@amrit110 amrit110 deleted the pre-commit-ci-update-config branch December 27, 2025 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants