Skip to content

Conversation

@cjllanwarne
Copy link
Collaborator

@cjllanwarne cjllanwarne commented Oct 27, 2025

Change Description

Fixes #15148 and https://github.com/hail-is/hail-security/issues/66

Security Assessment

Delete all except the correct answer:

  • This change potentially impacts the Hail Batch instance as deployed by Broad Institute in GCP

Impact Rating

  • This change has a low security impact

Impact Description

Regular dependency update, plus updating aiomysql past a known vulnerability (though the specific issue wasn't a risk for us, it still shows up in scans)

Appsec Review

  • Required: The impact has been assessed and approved by appsec

@cjllanwarne cjllanwarne requested a review from grohli October 27, 2025 19:56
@cjllanwarne cjllanwarne requested a review from a team as a code owner October 27, 2025 19:56
Copy link

@sarahgibs sarahgibs left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved.

Copy link
Contributor

@grohli grohli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update!

@hail-ci-robot hail-ci-robot merged commit dc1324d into hail-is:main Nov 3, 2025
2 checks passed
@cjllanwarne cjllanwarne deleted the cjl_update_dependencies branch November 3, 2025 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update dependency lock files

4 participants