Skip to content

fix(security): update dependencies [SECURITY]#566

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/security
Mar 13, 2026
Merged

fix(security): update dependencies [SECURITY]#566
renovate[bot] merged 1 commit intomainfrom
renovate/security

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Mar 13, 2026

This PR contains the following updates:

Package Change Age Confidence
black (changelog) 26.3.026.3.1 age confidence

GitHub Vulnerability Alerts

CVE-2026-32274

Impact

Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value of this argument to write cache files to arbitrary file system locations.

Patches

Fixed in Black 26.3.1.

Workarounds

Do not allow untrusted user input into the value of the --python-cell-magics option.


Release Notes

psf/black (black)

v26.3.1

Compare Source

Stable style
  • Prevent Jupyter notebook magic masking collisions from corrupting cells by using
    exact-length placeholders for short magics and aborting if a placeholder can no longer
    be unmasked safely (#​5038)
Configuration
  • Always hash cache filename components derived from --python-cell-magics so custom
    magic names cannot affect cache paths (#​5038)
Blackd
  • Disable browser-originated requests by default, add configurable origin allowlisting
    and request body limits, and bound executor submissions to improve backpressure
    (#​5039)

Configuration

📅 Schedule: Branch creation - "before 4am" in timezone UTC, Automerge - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) in timezone UTC.

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner March 13, 2026 00:48
@renovate renovate bot added chore dependencies Pull requests that update a dependency file fix labels Mar 13, 2026
@renovate renovate bot enabled auto-merge (squash) March 13, 2026 00:48
@github-actions github-actions bot added fix and removed fix chore labels Mar 13, 2026
@renovate renovate bot merged commit 3cbb77d into main Mar 13, 2026
22 of 24 checks passed
@renovate renovate bot deleted the renovate/security branch March 13, 2026 01:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file fix

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

1 participant