Skip to content

Bump dagster from 1.11.13 to 1.13.1 in /examples/docs_projects/project_atproto_dashboard#154

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/examples/docs_projects/project_atproto_dashboard/dagster-1.13.1
Open

Bump dagster from 1.11.13 to 1.13.1 in /examples/docs_projects/project_atproto_dashboard#154
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/examples/docs_projects/project_atproto_dashboard/dagster-1.13.1

Bump dagster in /examples/docs_projects/project_atproto_dashboard

2d952a7
Select commit
Loading
Failed to load commit list.
Socket Security / Socket Security: Pull Request Alerts succeeded Apr 18, 2026 in 10m 28s

Pull Request #154 Alerts: Complete with warnings

Report Status Message
PR #154 Alerts ⚠️ Found 2 project alerts

Pull request alerts notify when new issues are detected between the diff of the pull request and it's target branch.

Details

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Telemetry collection: pypi dagster

Note: This module implements a background telemetry uploader that reads local Dagster log files and POSTs compressed contents to a remote telemetry endpoint, then deletes uploaded files. It does not contain obvious obfuscated or stealthy backdoor code, but it does perform potentially sensitive data exfiltration (logs -> remote server) and uses insecure defaults (plain HTTP, compression/header mismatch). There are correctness/robustness bugs (content-encoding mismatch, a typo in exception handling) that may hide failures. If you do not trust the receiving endpoint or if logs may contain sensitive data, treat this as a moderate supply-chain/privacy risk and either disable telemetry via DAGSTER_DISABLE_TELEMETRY or review/modify the uploader to use HTTPS, authentication/allowlist, and safer file handling.

From: examples/data-quality-patterns/uv.lockpypi/dagster@1.13.1

ℹ Read more on: This package | This alert | What is telemetry?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Most telemetry comes with settings to disable it. Consider disabling telemetry if you do not want to be tracked.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/dagster@1.13.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Telemetry collection: pypi dagster

Note: This module implements a background telemetry uploader that reads local Dagster log files and POSTs compressed contents to a remote telemetry endpoint, then deletes uploaded files. It does not contain obvious obfuscated or stealthy backdoor code, but it does perform potentially sensitive data exfiltration (logs -> remote server) and uses insecure defaults (plain HTTP, compression/header mismatch). There are correctness/robustness bugs (content-encoding mismatch, a typo in exception handling) that may hide failures. If you do not trust the receiving endpoint or if logs may contain sensitive data, treat this as a moderate supply-chain/privacy risk and either disable telemetry via DAGSTER_DISABLE_TELEMETRY or review/modify the uploader to use HTTPS, authentication/allowlist, and safer file handling.

From: examples/data-quality-patterns/uv.lockpypi/dagster@1.13.1

ℹ Read more on: This package | This alert | What is telemetry?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Most telemetry comes with settings to disable it. Consider disabling telemetry if you do not want to be tracked.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore pypi/dagster@1.13.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report