gary-boon commited on
Commit
52916a2
·
1 Parent(s): a4a41eb

Security Phase 1: Update FastAPI from 0.104.1 to 0.109.1

Browse files

- Fixes SNYK-PYTHON-FASTAPI-6228055 (ReDoS vulnerability)
- Also updates starlette to 0.35.1 (fixes resource allocation issue)
- anyio already at safe version 4.10.0 (fixes race condition)
- Tested locally: All endpoints working correctly
- This fixes 3 HIGH severity vulnerabilities

Files changed (1) hide show
  1. requirements.txt +1 -1
requirements.txt CHANGED
@@ -1,5 +1,5 @@
1
  # Core dependencies for HuggingFace Spaces deployment
2
- fastapi==0.104.1
3
  uvicorn[standard]==0.24.0
4
  websockets==12.0
5
  python-multipart==0.0.6
 
1
  # Core dependencies for HuggingFace Spaces deployment
2
+ fastapi==0.109.1
3
  uvicorn[standard]==0.24.0
4
  websockets==12.0
5
  python-multipart==0.0.6