Skip to content

fix(deps): resolve pip-audit failures - #133

Merged
mfranczel merged 1 commit into
mainfrom
michal/fix-pip-audit-findings
Oct 7, 2026
Merged

mfranczel merged 1 commit into
mainfrom
michal/fix-pip-audit-findings

Conversation

@mfranczel

@mfranczel mfranczel commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Audit - Production and Audit - All fail on every PR (including #132) because of 27 advisories published after main's last green run. They're in 7 packages, and this PR fixes 6 of them. The oauthlib advisory can't be fixed yet, so it's ignored with a justification.

Changes

Package Before After Advisories
pyjwt 2.13.0 2.15.1 PYSEC-2026-4140..4152, PYSEC-2026-4183
pymongo 4.9.2 (< 3.14), 4.18.1 (3.14) 4.18.2 CVE-2026-88029, CVE-2026-96747, CVE-2026-96748, CVE-2026-96749
dnspython 2.6.1 (≤ 3.12), 2.8.0 2.8.0 – (required by pymongo 4.18)
tornado 6.5.8 6.5.10 GHSA-3hv7-mjh2-fv65, GHSA-c2m8-h5v5-343r, GHSA-chx6-46f5-w4vp
urllib3 2.7.0 2.8.0 PYSEC-2026-4175, PYSEC-2026-4176, PYSEC-2026-4177
snowflake-connector-python 4.7.2 4.8.0 CVE-2026-86597
fsspec (transitive via pyathena) 2024.6.1 2026.9.0 CVE-2026-104851
  • ci.yml: PYSEC-2026-4114 (oauthlib) added to ignore-vulns.

⚠️ pymongo: MongoDB server support

Python 3.10–3.13 move from pymongo 4.9 to 4.18 (3.14 was already on 4.18).
pymongo 4.18 no longer supports MongoDB servers older than 4.4 (3.6, 4.0 and 4.2,
all end-of-life). Users connecting to those servers will lose driver support.
The advisories include a heap out-of-bounds write and a connection-string
redirect that affect every pymongo version, so ignoring them wasn't a good
option.

oauthlib: ignored, not fixed

  • The only fix is oauthlib 4.0.0, but databricks-sql-connector (including the
    latest, 4.6.0) requires oauthlib<4.0.0.
  • The advisory is a timing side-channel in server-side PKCE validation (AuthorizationCodeGrant). databricks-sql-connector only uses the client side (WebApplicationClient), and the toolkit doesn't import oauthlib directly.
  • Remove the ignore once databricks-sql-connector allows oauthlib 4.

Lock file

Only the 7 packages above changed in poetry.lock. A plain poetry lock on main also upgrades about 20 unrelated dependencies for Python < 3.14 (pydantic, pyzmq, debugpy, shapely, pyspark, …). So the new entries for these packages were spliced into the existing lock. Most of the diff is pymongo's wheel hashes.

Testing

  • poetry check --lock passes (Poetry 2.2.0, as in CI)
  • I exported the full dependency set (all extras and dev) and resolved it on Python 3.10–3.14. No package outside the lock is needed, except tomli on 3.11 (via coverage), which is already like that on main.
  • pip-audit on the exported prod and all requirements (same flags as CI): no known vulnerabilities apart from the ignored ones.

pyjwt 2.13.0 → 2.15.1 (changelog)

  • 2.14.0: security hardening: stricter HMAC key validation, PyJWKClient no longer follows redirects, limits on repeated JWKS refreshes, nested/malformed input handled without recursion errors
  • 2.15.0: errors from deeply nested payloads are wrapped in DecodeError; JWKSetCache stores the parsed PyJWKSet; malformed JWK Set members are skipped instead of failing the whole set; Python 3.15 support
  • 2.15.1: accepts trailing Base64URL = padding (tokens from AWS ALB and similar)

pymongo 4.9.2 → 4.18.2(changelog)

  • Drops support for MongoDB4.14) and 4.2 (4.18). Theminimum server is now 4.4.
  • 4.11: removes the MONGODBwrite raises onordered=True/verboseResults=True` with unacknowledged writes
  • 4.13: async API is stablepadding validation whenencoding
  • 4.14: parse_uri() returions- 4.16: requires dnspython>=2.6.1`; Eventlet support removed
  • 4.18: PyPy support deprec- 4.18.1/4.18.2: security fixes (GridFS ID injection, KMS endpoint, connection
    string host parsing, BSON e

dnspython 2.6.1 → 2.8.0(changelog)

  • 2.7.0: HTTP/3 support forsignatures (needscryptography ≥ 43), new record types and EDNS options
  • 2.8.0: B-tree zone implemction helpers, Win32 APIconfig method; requires Python ≥ 3.10
  • Only used here as a pymon)

tornado 6.5.8 → 6.5.10(6.5.9,
6.5.10)- 6.5.9: security fixes: StaticFileHandler no longer follows symlinks outside
the static root; body-size /simple_httpclient; thelimit on repeated 100 Continueresponses;max_argument` applies to URL
arguments too- 6.5.10: makes the 6.5.9 symlink change compatible with Jupyter (Jupyter failed
to load on 6.5.9)

urllib3 2.7.0 → 2.8.0(changelog)

  • Security: HTTPS proxy TLSnored or overridden;unbounded chunk-size line buffering; infinite loop in chunked Deflate streaming
  • Behaviour change: destinatity overrides no longerapply to HTTPS forwarding proxies. Use proxy_ssl_context instead.
  • Obsolete folded header lies (RFC 9112); newUrl.auth_decoded helpers

snowflake-connector-python 4.7.2 → 4.8.0 ([changelog](https://github.com/snow
flakedb/snowflake-connectorION.md))- 4.7.3: TLS hostname fix for account locators with underscores; faster
connect(); split_statemeng in logs on by default- 4.7.4/4.7.5: retries on transient OAuth/TLS failures; incomplete result sets raise OperationalErroring fewer rows- 4.8.0: SSO callback validates theOriginheader; newSNOWFLAKE_TLS_CIPHERS`;

OCSP revocation checks ary enabled
**fsspec 2024.6.1 → 2026.9.(changelog)

  • About two years of release through pyathena
  • Drops Python 3.8 and 3.9; adds Python 3.14
  • Removes deprecated asyncie-read fix; simplecachefiles can be expired by age; PyArrow compatibility fixes
  • 2026.6.0: fix for CVE-202

Resolves BLU-6487

Summary by CodeRabbit

  • Chores
    • Updated package version requirements, including higher minimum versions for several packages and broader Python-version coverage for two packages.
    • Updated security audit settings to account for an additional advisory and documented the audit’s applicability and version constraint.

…llib3, fsspec and snowflake-connector-python

Audit - Production and Audit - All fail with 27 advisories in 7 packages:

- pyjwt 2.13.0 -> 2.15.1 (PYSEC-2026-4140..4152, PYSEC-2026-4183).
- pymongo 4.9.2 -> 4.18.2 on Python < 3.14, 4.18.1 -> 4.18.2 on 3.14
  (CVE-2026-88029, CVE-2026-96747, CVE-2026-96748, CVE-2026-96749).
  The per-version pins are collapsed into one constraint. pymongo 4.18
  requires dnspython >= 2.7, so dnspython is now 2.8.0 on all versions.
  Note: pymongo 4.18 no lonrs older than 4.4.
- tornado 6.5.8 -> 6.5.10 (GHSA-3hv7-mjh2-fv65, GHSA-c2m8-h5v5-343r,
  GHSA-chx6-46f5-w4vp).
- urllib3 2.7.0 -> 2.8.0 (PYSEC-2026-4175, PYSEC-2026-4176, PYSEC-2026-4177).
- snowflake-connector-pytho-86597).
- fsspec 2024.6.1 -> 2026.9.0 (CVE-2026-104851), transitive via pyathena.

oauthlib PYSEC-2026-4114 is added to ignore-vulns: the fix is only in
oauthlib 4.0.0, but databri4.6.0) caps
oauthlib < 4.0.0. The advisory affects server-side PKCE validation;
databricks-sql-connector on

The lock update covers onlyetry lock would
also upgrade about 20 unrelated dependencies for Python < 3.14.

pip-audit on the exported prod and all requirements is clean apart from
the ignored advisories.
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: fd3cb417-7e2d-4f24-845a-77f49ed73428
📥 Commits

Reviewing files that changed from the base of the PR and between b6ae159 and 7ac3849.

⛔ Files ignored due to path filters (1)
  • poetry.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • pyproject.toml

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The CI vulnerability audit now ignores PYSEC-2026-4114 and includes comments about the advisory’s applicability and the oauthlib version constraint. The project also updates version constraints for pymongo, dnspython, snowflake-connector-python, urllib3, tornado, and pyjwt, and adds a minimum version for fsspec.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: m1so

Merge Risk: ⚪ Minimal · up to 7ac38

This change updates dependency versions and the audit ignore list to fix CI audit failures. No concrete merge-blocking risk was found. Teams running MongoDB servers older than 4.4 should note that pymongo 4.18 no longer supports them.

🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Updates Docs ✅ Passed PASS: This PR implements dependency and CI audit updates only. It does not add or change a user-facing feature, and no documentation update is required by this check. The linked repositories were not …
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary change: dependency updates and audit configuration changes to resolve pip-audit failures.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

📦 Python package built successfully!

  • Version: 2.8.0.dev2+2cf42a9
  • Wheel: deepnote_toolkit-2.8.0.dev2+2cf42a9-py3-none-any.whl
  • Install:
    pip install "deepnote-toolkit @ https://deepnote-staging-runtime-artifactory.s3.amazonaws.com/deepnote-toolkit-packages/2.8.0.dev2%2B2cf42a9/deepnote_toolkit-2.8.0.dev2%2B2cf42a9-py3-none-any.whl"

@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.26%. Comparing base (b6ae159) to head (7ac3849).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #133   +/-   ##
=======================================
  Coverage   77.26%   77.26%           
=======================================
  Files         115      115           
  Lines        6589     6589           
  Branches      961      961           
=======================================
  Hits         5091     5091           
  Misses       1186     1186           
  Partials      312      312           
Flag Coverage Δ
combined 77.26% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@deepnote-bot

Copy link
Copy Markdown

🚀 Review App Deployment Started

📝 Description 🌐 Link / Info
🌍 Review application ra-133
🔑 Sign-in URL Click to sign-in
📊 Application logs View logs
🔄 Actions Click to redeploy
🚀 ArgoCD deployment View deployment
⏰ Last deployed 2026-10-07 14:54:45 (UTC)
📜 Deployed commit 651d7b2c965e8a88e7b5aeabf81bcffd682134d3
🛠️ Toolkit version 2cf42a9

@mfranczel
mfranczel requested review from m1so and tkislan October 7, 2026 15:36
@mfranczel mfranczel self-assigned this Oct 7, 2026
@mfranczel
mfranczel marked this pull request as ready for review October 7, 2026 15:36
@mfranczel
mfranczel requested a review from a team as a code owner October 7, 2026 15:36
@linear-code

linear-code Bot commented Oct 7, 2026

Copy link
Copy Markdown

BLU-6487

@mfranczel
mfranczel merged commit abf4243 into main Oct 7, 2026
38 checks passed
@mfranczel
mfranczel deleted the michal/fix-pip-audit-findings branch October 7, 2026 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants