Skip to content

chore(deps): constrain PyJWT>=2.15.0 and urllib3>=2.8.0 to resolve dependabot alerts - #196

Merged
lucarlig merged 1 commit into
mainfrom
dependabot-2026-10-05
Oct 5, 2026
Merged

lucarlig merged 1 commit into
mainfrom
dependabot-2026-10-05

Conversation

@jonpspri

@jonpspri jonpspri commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

Resolves the actionable open dependabot security alerts against the root uv.lock:

  • PyJWT 2.13.0 → 2.15.0 — covers 10 advisories, including the critical asymmetric-PEM detection bypass, JWKS redirect following, DER-keys-as-HMAC-secrets, ReDoS in is_pem_format, and the RecursionError DoS (first patched in 2.15.0).
  • urllib3 2.7.0 → 2.8.0 — covers unbounded chunk-size-line buffering, HTTPS proxy TLS override, and chunked-deflate infinite loop (2 high, 1 medium).

Both packages are transitive dependencies (via mcp/cpex/requests), so they are pinned via tool.uv.constraint-dependencies rather than added to any project's core dependency list. uv.lock rebuilt with uv lock — only these two packages changed.

Alerts requiring no change

Verification

  • uv lock --check passes
  • uv sync --dev --all-packages — full install including all 7 maturin/Rust plugin builds
  • Import check: pyjwt 2.15.0, urllib3 2.8.0; plugins import cleanly

Address open dependabot security alerts against the root uv.lock:

- PyJWT 2.13.0 -> 2.15.0: fixes 10 advisories including the critical
  asymmetric-PEM detection bypass, JWKS redirect following, DER-keys-as-
  HMAC-secrets, and the RecursionError DoS (first patched in 2.15.0).

PyJWT is a transitive dependency, so it is pinned via
tool.uv.constraint-dependencies rather than added to project dependency
lists. uv.lock rebuilt with 'uv lock'; no other packages changed.

urllib3 (2.8.0, #192), anyio (4.14.2), cryptography (49.0.0), and hpack
(4.2.0) alerts are already resolved at their locked versions. Alerts
against deleted per-plugin uv.lock manifests are stale and will close on
the next dependabot scan.

Signed-off-by: Jonathan Springer <jps@s390x.com>
@jonpspri
jonpspri force-pushed the dependabot-2026-10-05 branch from 441e3d3 to 855dace Compare October 5, 2026 09:45

@lucarlig lucarlig left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blocking findings in 855dace. The root dependency constraints and lockfile agree, and PyJWT is the only changed package record. urllib3 was already locked at 2.8.0 on the base branch; this PR adds its minimum-version constraint.

Verified uv lock --check with uv 0.12.13 and CI's pinned uv 0.9.30, a locked install of the ICA metering exporter, and make test-all (78 unit tests and 12 integration tests passed). All 37 active CI checks passed.

@lucarlig
lucarlig merged commit bee7a69 into main Oct 5, 2026
42 checks passed
@lucarlig
lucarlig deleted the dependabot-2026-10-05 branch October 5, 2026 11:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants