Skip to content

Build(deps): Bump pydantic-settings from 2.14.1 to 2.14.2 in /python#6650

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python/pydantic-settings-2.14.2
Open

Build(deps): Bump pydantic-settings from 2.14.1 to 2.14.2 in /python#6650
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python/pydantic-settings-2.14.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 20, 2026

Copy link
Copy Markdown
Contributor

Bumps pydantic-settings from 2.14.1 to 2.14.2.

Release notes

Sourced from pydantic-settings's releases.

v2.14.2

What's Changed

This is a security patch release.

Security

Fixes GHSA-4xgf-cpjx-pc3j: NestedSecretsSettingsSource with secrets_nested_subdir=True could follow a symbolic link inside secrets_dir pointing outside it, reading out-of-tree files into settings values and bypassing the secrets_dir_max_size cap. Affected versions: >= 2.12.0, < 2.14.2.

Full Changelog: pydantic/pydantic-settings@v2.14.1...v2.14.2

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Issues related to the Python codebase labels Jun 20, 2026
Copilot AI review requested due to automatic review settings June 20, 2026 15:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@github-actions github-actions Bot changed the title Build(deps): Bump pydantic-settings from 2.14.1 to 2.14.2 in /python Python: Build(deps): Bump pydantic-settings from 2.14.1 to 2.14.2 in /python Jun 20, 2026
Bumps [pydantic-settings](https://github.com/pydantic/pydantic-settings) from 2.14.1 to 2.14.2.
- [Release notes](https://github.com/pydantic/pydantic-settings/releases)
- [Commits](pydantic/pydantic-settings@v2.14.1...v2.14.2)

---
updated-dependencies:
- dependency-name: pydantic-settings
  dependency-version: 2.14.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Python: Build(deps): Bump pydantic-settings from 2.14.1 to 2.14.2 in /python Build(deps): Bump pydantic-settings from 2.14.1 to 2.14.2 in /python Jun 22, 2026
@dependabot dependabot Bot force-pushed the dependabot/uv/python/pydantic-settings-2.14.2 branch from c06306e to c7d3425 Compare June 22, 2026 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Issues related to the Python codebase

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant