SIGN IN SIGN UP

chore(deps): bump security-flagged dependencies (#135)

Consolidates 9 Dependabot security PRs into one lockfile update,
bumping each package to its first patched version:

- urllib3 2.6.3 -> 2.7.0 (GHSA-qccp-gfcp-xxvc, GHSA-mf9v-mfxr-j63j)
- python-multipart 0.0.22 -> 0.0.27 (GHSA-pp6c-gr5w-3c5g, GHSA-mj87-hwqh-73pj)
- authlib 1.6.9 -> 1.6.12 (GHSA-r95x-qfjj-fjj2, GHSA-jj8c-mmj3-mmgv)
- cryptography 46.0.5 -> 46.0.7 (GHSA-p423-j2cm-9vmq, GHSA-m959-cc7f-wv43)
- idna 3.11 -> 3.15 (GHSA-65pc-fj4g-8rjx)
- python-dotenv 1.2.1 -> 1.2.2 (GHSA-mf9w-mj56-hr94)
- pytest 9.0.2 -> 9.0.3 (GHSA-6w46-j5rx-g56g)
- requests 2.32.5 -> 2.33.0 (GHSA-gc5v-m9x4-r6x2)
- pygments 2.19.2 -> 2.20.0 (GHSA-5239-wwwm-4pmq)

Also realigns the lockfile with pyproject.toml (plane-sdk 0.2.10 -> 0.2.12,
root 0.2.10 -> 0.2.9), which the committed lock had drifted from.

Closes #94, #97, #100, #107, #112, #120, #122, #123, #128
S
sriram veeraghanta committed
369889e9231245c4dc4b1b399d40995587356f7c
Parent: 316455f
Committed by GitHub <noreply@github.com> on 6/1/2026, 11:32:00 AM