Repository navigation
chore(deps): constrain PyJWT>=2.15.0 and urllib3>=2.8.0 to resolve dependabot alerts - #196
Merged
Merged
Conversation
jonpspri
requested review from
gandhipratik203,
lucarlig and
msureshkumar88
as code owners
October 5, 2026 09:42
jonpspri
force-pushed
the
dependabot-2026-10-05
branch
from
October 5, 2026 09:45
caf80ce to
441e3d3
Compare
Address open dependabot security alerts against the root uv.lock: - PyJWT 2.13.0 -> 2.15.0: fixes 10 advisories including the critical asymmetric-PEM detection bypass, JWKS redirect following, DER-keys-as- HMAC-secrets, and the RecursionError DoS (first patched in 2.15.0). PyJWT is a transitive dependency, so it is pinned via tool.uv.constraint-dependencies rather than added to project dependency lists. uv.lock rebuilt with 'uv lock'; no other packages changed. urllib3 (2.8.0, #192), anyio (4.14.2), cryptography (49.0.0), and hpack (4.2.0) alerts are already resolved at their locked versions. Alerts against deleted per-plugin uv.lock manifests are stale and will close on the next dependabot scan. Signed-off-by: Jonathan Springer <jps@s390x.com>
jonpspri
force-pushed
the
dependabot-2026-10-05
branch
from
October 5, 2026 09:45
441e3d3 to
855dace
Compare
lucarlig
approved these changes
Oct 5, 2026
lucarlig
left a comment
Collaborator
There was a problem hiding this comment.
No blocking findings in 855dace. The root dependency constraints and lockfile agree, and PyJWT is the only changed package record. urllib3 was already locked at 2.8.0 on the base branch; this PR adds its minimum-version constraint.
Verified uv lock --check with uv 0.12.13 and CI's pinned uv 0.9.30, a locked install of the ICA metering exporter, and make test-all (78 unit tests and 12 integration tests passed). All 37 active CI checks passed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves the actionable open dependabot security alerts against the root
uv.lock:is_pem_format, and the RecursionError DoS (first patched in 2.15.0).Both packages are transitive dependencies (via
mcp/cpex/requests), so they are pinned viatool.uv.constraint-dependenciesrather than added to any project's core dependency list.uv.lockrebuilt withuv lock— only these two packages changed.Alerts requiring no change
plugins/rust/python-package/*/uv.lock— those manifests were deleted in Update Python dependency locks and plugin catalog checks #121/fix(sql_sanitizer): analyse executable comments, join root uv workspace #159 when the plugins joined the root uv workspace; stale, will close on the next dependabot scan.output_length_guardalerts — plugin no longer exists onmain.Verification
uv lock --checkpassesuv sync --dev --all-packages— full install including all 7 maturin/Rust plugin buildspyjwt 2.15.0,urllib3 2.8.0; plugins import cleanly