fix: semgrep 1.157.0 dans un venv isole du job security et plancher pyjwt 2.13 BUG-091
CI / lint (push) Successful in 2m27s
CI / security (push) Failing after 2m21s
CI / test (push) Successful in 4m19s
CI / build (push) Successful in 2m31s
CI / e2e (push) Successful in 15m1s

This commit is contained in:
2026-09-28 21:54:12 -04:00
parent c72f852a55
commit d6d081c0e9
12 changed files with 56 additions and 29 deletions
+3
View File
@@ -20,6 +20,9 @@ webauthn==2.6.0
psutil>=5.9
pywebpush>=2.3.0
mcp==1.28.1
# Plancher de sécurité (BUG-091) : pyjwt est une dépendance transitive (mcp) ;
# 2.12.x est vulnérable (PYSEC-2026-178, fix 2.13.0) et pip-audit bloque sinon.
pyjwt[crypto]>=2.13.0
sse-starlette==2.1.3
openpyxl>=3.1
xlrd==2.0.2