chore(deps): update dependency marshmallow to v3.26.2 [security]#49
chore(deps): update dependency marshmallow to v3.26.2 [security]#49renovate[bot] wants to merge 1 commit intodevelop-ngfrom
Conversation
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
|
Welcome @renovate[bot]! 🎉Great PR! I've analyzed your code changes for:
Ready to see the full review?
Let's make your code even better together! 🚀 |
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
Here's the code health analysis summary for commits Analysis Summary
|
This PR contains the following updates:
3.20.1→3.26.2==3.20.1→==3.26.2GitHub Vulnerability Alerts
CVE-2025-68480
Impact
Schema.load(data, many=True)is vulnerable to denial of service attacks. A moderately sized request can consume a disproportionate amount of CPU time.Patches
4.1.2, 3.26.2
Workarounds
Release Notes
marshmallow-code/marshmallow (marshmallow)
v3.26.2Compare Source
Bug fixes:
2025-68480: Merge error store messages without rebuilding collections.Thanks 카푸치노 for reporting and :user:
deckar01for the fix.v3.26.1Compare Source
v3.26.0Compare Source
v3.25.1Compare Source
v3.25.0Compare Source
v3.24.2Compare Source
v3.24.1Compare Source
v3.24.0Compare Source
v3.23.3Compare Source
v3.23.2Compare Source
v3.23.1Compare Source
v3.23.0Compare Source
v3.22.0Compare Source
v3.21.3Compare Source
v3.21.2Compare Source
v3.21.1Compare Source
v3.21.0Compare Source
v3.20.2Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.
This change is