Skip to content

Commit 78af32f

Browse files
DeFiTONclaude
andcommitted
chore(deps): bump aiohttp 3.10.10 → 3.13.4 (closes 21 advisories)
Closes Dependabot alerts: CVE-2024-52303 through CVE-2026-34525 (1 high, 9 moderate, 11 low). All upstream aiohttp CVEs. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 4e920c4 commit 78af32f

1 file changed

Lines changed: 7 additions & 0 deletions

File tree

CHANGELOG.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
77

88
## [Unreleased]
99

10+
## [1.3.1] — 2026-05-26
11+
12+
### Security
13+
- Bumped `aiohttp` from 3.10.10 to 3.13.4 to close 21 advisories
14+
(1 high, 9 moderate, 11 low — CVE-2024-52303 through CVE-2026-34525).
15+
All upstream library CVEs; the bot itself was not the attack surface.
16+
1017
## [1.3.0] — 2026-05-26
1118

1219
Initial public release. Code was extracted from a private working copy used by

0 commit comments

Comments
 (0)