Skip to content

Clear Dependabot high alerts (pyo3) - #70

Merged
thomasrockhu-codecov merged 1 commit into
mainfrom
th/cve-pyo3
Aug 12, 2026
Merged

Clear Dependabot high alerts (pyo3)#70
thomasrockhu-codecov merged 1 commit into
mainfrom
th/cve-pyo3

Conversation

@thomasrockhu-codecov

Copy link
Copy Markdown
Contributor

Summary

  • Bump pyo3 to 0.29.x to clear GHSA-36hh-v3qg-5jq4.
  • Mark SqliteReportBuilder as #[pyclass(unsendable)] for pyo3 0.29 Sync requirements.

Test plan

  • cargo check --workspace / CI passes
  • Confirm Dependabot highs clear after merge

@codecov

codecov Bot commented Aug 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.22%. Comparing base (215b5fc) to head (627d278).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #70   +/-   ##
=======================================
  Coverage   98.22%   98.22%           
=======================================
  Files          21       21           
  Lines        6025     6025           
=======================================
  Hits         5918     5918           
  Misses        107      107           
Components Coverage Δ
core 98.32% <ø> (ø)
bindings 74.07% <ø> (ø)
python 100.00% <ø> (ø)

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@codspeed-hq

codspeed-hq Bot commented Aug 7, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 4 untouched benchmarks


Comparing th/cve-pyo3 (627d278) with main (215b5fc)

Open in CodSpeed

@thomasrockhu-codecov
thomasrockhu-codecov merged commit 665e89f into main Aug 12, 2026
11 checks passed
@thomasrockhu-codecov
thomasrockhu-codecov deleted the th/cve-pyo3 branch August 12, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants