Repository navigation
fix(deps): resolve pip-audit failures - #133
Conversation
…llib3, fsspec and snowflake-connector-python Audit - Production and Audit - All fail with 27 advisories in 7 packages: - pyjwt 2.13.0 -> 2.15.1 (PYSEC-2026-4140..4152, PYSEC-2026-4183). - pymongo 4.9.2 -> 4.18.2 on Python < 3.14, 4.18.1 -> 4.18.2 on 3.14 (CVE-2026-88029, CVE-2026-96747, CVE-2026-96748, CVE-2026-96749). The per-version pins are collapsed into one constraint. pymongo 4.18 requires dnspython >= 2.7, so dnspython is now 2.8.0 on all versions. Note: pymongo 4.18 no lonrs older than 4.4. - tornado 6.5.8 -> 6.5.10 (GHSA-3hv7-mjh2-fv65, GHSA-c2m8-h5v5-343r, GHSA-chx6-46f5-w4vp). - urllib3 2.7.0 -> 2.8.0 (PYSEC-2026-4175, PYSEC-2026-4176, PYSEC-2026-4177). - snowflake-connector-pytho-86597). - fsspec 2024.6.1 -> 2026.9.0 (CVE-2026-104851), transitive via pyathena. oauthlib PYSEC-2026-4114 is added to ignore-vulns: the fix is only in oauthlib 4.0.0, but databri4.6.0) caps oauthlib < 4.0.0. The advisory affects server-side PKCE validation; databricks-sql-connector on The lock update covers onlyetry lock would also upgrade about 20 unrelated dependencies for Python < 3.14. pip-audit on the exported prod and all requirements is clean apart from the ignored advisories.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe CI vulnerability audit now ignores Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to This change updates dependency versions and the audit ignore list to fix CI audit failures. No concrete merge-blocking risk was found. Teams running MongoDB servers older than 4.4 should note that pymongo 4.18 no longer supports them. 🚥 Pre-merge checks | ✅ 6✅ Passed checks (6 passed)
Comment |
|
📦 Python package built successfully!
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #133 +/- ##
=======================================
Coverage 77.26% 77.26%
=======================================
Files 115 115
Lines 6589 6589
Branches 961 961
=======================================
Hits 5091 5091
Misses 1186 1186
Partials 312 312
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
|
🚀 Review App Deployment Started
|
Summary
Audit - ProductionandAudit - Allfail on every PR (including #132) because of 27 advisories published aftermain's last green run. They're in 7 packages, and this PR fixes 6 of them. The oauthlib advisory can't be fixed yet, so it's ignored with a justification.Changes
ci.yml:PYSEC-2026-4114(oauthlib) added toignore-vulns.Python 3.10–3.13 move from pymongo 4.9 to 4.18 (3.14 was already on 4.18).
pymongo 4.18 no longer supports MongoDB servers older than 4.4 (3.6, 4.0 and 4.2,
all end-of-life). Users connecting to those servers will lose driver support.
The advisories include a heap out-of-bounds write and a connection-string
redirect that affect every pymongo version, so ignoring them wasn't a good
option.
oauthlib: ignored, not fixed
databricks-sql-connector(including thelatest, 4.6.0) requires
oauthlib<4.0.0.AuthorizationCodeGrant).databricks-sql-connectoronly uses the client side (WebApplicationClient), and the toolkit doesn't import oauthlib directly.databricks-sql-connectorallows oauthlib 4.Lock file
Only the 7 packages above changed in
poetry.lock. A plainpoetry lockonmainalso upgrades about 20 unrelated dependencies for Python < 3.14 (pydantic, pyzmq, debugpy, shapely, pyspark, …). So the new entries for these packages were spliced into the existing lock. Most of the diff is pymongo's wheel hashes.Testing
poetry check --lockpasses (Poetry 2.2.0, as in CI)tomlion 3.11 (viacoverage), which is already like that onmain.pip-auditon the exported prod and all requirements (same flags as CI): no known vulnerabilities apart from the ignored ones.pyjwt 2.13.0 → 2.15.1 (changelog)
PyJWKClientno longer follows redirects, limits on repeated JWKS refreshes, nested/malformed input handled without recursion errorsDecodeError;JWKSetCachestores the parsedPyJWKSet; malformed JWK Set members are skipped instead of failing the whole set; Python 3.15 support=padding (tokens from AWS ALB and similar)pymongo 4.9.2 → 4.18.2(changelog)
raises onordered=True/verboseResults=True` with unacknowledged writesparse_uri()returions- 4.16: requiresdnspython>=2.6.1`; Eventlet support removedstring host parsing, BSON e
dnspython 2.6.1 → 2.8.0(changelog)
tornado 6.5.8 → 6.5.10(6.5.9,
6.5.10)- 6.5.9: security fixes:
StaticFileHandlerno longer follows symlinks outsidethe static root; body-size
/simple_httpclient; thelimit on repeated100 Continueresponses;max_argument` applies to URLarguments too- 6.5.10: makes the 6.5.9 symlink change compatible with Jupyter (Jupyter failed
to load on 6.5.9)
urllib3 2.7.0 → 2.8.0(changelog)
proxy_ssl_contextinstead.Url.auth_decodedhelperssnowflake-connector-python 4.7.2 → 4.8.0 ([changelog](https://github.com/snow
flakedb/snowflake-connectorION.md))- 4.7.3: TLS hostname fix for account locators with underscores; faster
connect();split_statemeng in logs on by default- 4.7.4/4.7.5: retries on transient OAuth/TLS failures; incomplete result sets raiseOperationalErroring fewer rows- 4.8.0: SSO callback validates theOriginheader; newSNOWFLAKE_TLS_CIPHERS`;OCSP revocation checks ary enabled
**fsspec 2024.6.1 → 2026.9.(changelog)
simplecachefiles can be expired by age; PyArrow compatibility fixesResolves BLU-6487
Summary by CodeRabbit