chore(deps): bump jupyter-server from 2.17.0 to 2.18.0#628
chore(deps): bump jupyter-server from 2.17.0 to 2.18.0#628dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps [jupyter-server](https://github.com/jupyter-server/jupyter_server) from 2.17.0 to 2.18.0. - [Release notes](https://github.com/jupyter-server/jupyter_server/releases) - [Changelog](https://github.com/jupyter-server/jupyter_server/blob/main/CHANGELOG.md) - [Commits](jupyter-server/jupyter_server@v2.17.0...v2.18.0) --- updated-dependencies: - dependency-name: jupyter-server dependency-version: 2.18.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
🛡️ Cross-link from supply-chain audit routine The Why this PR matters for downstream consumers: the
Current blocker: To unblock: rebase this PR onto a state that includes #614's bump (or vice-versa) so a single PR carries both Note: the routine deliberately did not rebase this PR or recreate it — per the audit-vulnerabilities skill, autonomous routines don't trigger dependency upgrades; that decision stays with a human. PYSDK-124 documents the full picture and recommended remediation path. Generated by Claude Opus 4.7 (cloud routine |
|
Looks like jupyter-server is up-to-date now, so this is no longer needed. |
Bumps jupyter-server from 2.17.0 to 2.18.0.
Release notes
Sourced from jupyter-server's releases.
... (truncated)
Changelog
Sourced from jupyter-server's changelog.
... (truncated)
Commits
0ceed45Publish 2.18.049b3439Move check origin into a util function and add it to websocket (#1630)e2e08c8Add test case for bad next URL format624d6c0Delete outdated patch coded825b93Apply suggestion from@minrk789fed0patch open redirect in /login2ee51ecfix(CVE-2026-35397): path traversal when target dir starts with root dir057869aFix allow_origin_pat to do full matching instead of prefix matching4862199Add resolvePath API for resolving kernel-relative pathse31d514Bump actions/create-github-app-token from 2 to 3 in the actions group across ...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.