Skip to content

Conversation

updates:
- [github.com/astral-sh/uv-pre-commit: 0.8.23 → 0.9.18](astral-sh/uv-pre-commit@0.8.23...0.9.18)
- [github.com/astral-sh/ruff-pre-commit: v0.14.3 → v0.14.10](astral-sh/ruff-pre-commit@v0.14.3...v0.14.10)
- [github.com/pre-commit/mirrors-mypy: v1.18.2 → v1.19.1](pre-commit/mirrors-mypy@v1.18.2...v1.19.1)
- [github.com/crate-ci/typos: v1 → typos-dict-v0.13.13](crate-ci/typos@v1...typos-dict-v0.13.13)
@codecov
Copy link

codecov bot commented Dec 22, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.89%. Comparing base (0a46b61) to head (675e337).
⚠️ Report is 6 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #52   +/-   ##
=======================================
  Coverage   90.89%   90.89%           
=======================================
  Files           7        7           
  Lines         747      747           
=======================================
  Hits          679      679           
  Misses         68       68           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

aieng-bot-maintain[bot] and others added 2 commits December 27, 2025 16:41
Security updates:
- Update filelock from 3.20.0 to 3.20.1 (fixes GHSA-w853-jp5j-5j7f)

Severity: High

The vulnerability (CVE-2025-24789) is a Time-of-Check-Time-of-Use (TOCTOU)
race condition that allows local attackers to corrupt or truncate arbitrary
user files through symlink attacks. This affects all users of filelock on
Unix, Linux, macOS, and Windows systems.

The fix in version 3.20.1 adds:
- O_NOFOLLOW flag on Unix/Linux/macOS to prevent symlink following
- GetFileAttributesW API check on Windows to detect reparse points

Co-authored-by: AI Engineering Maintenance Bot <[email protected]>
@amrit110 amrit110 merged commit 527f5d9 into main Dec 27, 2025
7 checks passed
@amrit110 amrit110 deleted the pre-commit-ci-update-config branch December 27, 2025 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants