pip-audit flagged fixable advisories in the web stack: - cryptography -> >=48.0.1 (GHSA-537c-gmf6-5ccf) - python-multipart -> >=0.0.31 (CVE-2026-53538/53539/53540) - starlette (transitive via fastapi) -> add direct floor >=1.3.1 (CVE-2026-48817/48818/54282/54283) Venv synced to cryptography 49.0.0, python-multipart 0.0.32, starlette 1.3.1; full tests/api/ suite green against the bump. Also drops the stray browser-use[core] dev dep (the browser-use skill uses a global CLI; the package is imported nowhere in DECNET).
6.0 KiB
6.0 KiB