Issue
The project currently uses Starlette >=0.27, which includes versions with known security vulnerabilities. The dependency should be updated to >=0.49.1 to address these issues.
Impact
- Main project:
pyproject.toml
- Example servers:
examples/servers/simple-streamablehttp/pyproject.toml
examples/servers/simple-streamablehttp-stateless/pyproject.toml
Resolution
A pull request has been created to update the Starlette dependency across all affected files:
References
- Updated version: Starlette 0.49.1
- Minimum required version:
>=0.49.1