What Happened
- This pull request updates the transitive dependency jupyter-server from 2.17.0 to 2.18.2 to remediate CVE-2026-35397, and refreshes the lockfiles (uv.lock, poetry.lock, enterprise/poetry.lock) so environments resolve the fixed package version.
- This pull request updates the transitive dependency jupyter-server from 2.17.0 to 2.18.2 to remediate CVE-2026-35397, and refreshes the lockfiles (uv.lock, poetry.lock, enterprise/poetry.lock) so environments resolve the fixed package version.
- 1 evidence item attached for review.