Skip to content

Scheduled weekly dependency update for week 40 - #1033

Merged
JarryShaw merged 2 commits into
mainfrom
pyup-scheduled-update-2026-10-05
Oct 5, 2026
Merged

JarryShaw merged 2 commits into
mainfrom
pyup-scheduled-update-2026-10-05

Conversation

@pyup-bot

@pyup-bot pyup-bot commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Update sphinx-autodoc-typehints from 3.13.7 to 3.13.8.

Changelog

3.13.8

<!-- Release notes generated using configuration in .github/release.yaml at main -->

What's Changed
* 🐛 fix(resolver): resolve guarded class imports by gaborbernat in https://github.com/tox-dev/sphinx-autodoc-typehints/pull/775


**Full Changelog**: https://github.com/tox-dev/sphinx-autodoc-typehints/compare/3.13.7...3.13.8
Links

Update scapy from 2.7.0 to 2.8.0.

Changelog

2.8.0

*Hi everyone. This release is a bit different, as it is heavily focused on security fixes as we are clearing our backlog of AI-Assisted reports. We have also clarified the guidelines around AI, contributions and security reports. To contributors, feel free to reach out if you haven't heard back from us in a whilte !*

Deprecation notice

- This major version will be **the last to support Python 3.7 and 3.8**. While this was initially planned for 2.7.0, support was extended because of how used those versions still were. They have been EoL for more than 2 years, and we highly encourage remaining users to upgrade.

A note about contributing guidelines

We have clarified our CONTRIBUTING and SECURITY guidelines. This notably includes some new guidance related to the use of AI, and some instructions regarding the submission of security issues. We encourage contributors to take a moment to read the updated versions.

Security

Scapy has taken part in `OpenAI + Trail of Bits` collab's initiative called ["Patch the Planet"](https://openai.com/index/patch-the-planet/). As part of this initiative, we have received a free security coverage of our code overseen by [KernelClint](https://github.com/KernelClint) (Trail of Bits) and multiple OpenAI agents. This has led to the discovery of around 130+ bugs, among which were 54 issues that could be considered related to security, with various degrees of severity. You can find a partial list on https://github.com/secdev/scapy/security/advisories and [here](https://github.com/secdev/scapy/pulls?q=is%3Apr+state%3Amerged+author%3Akernelclint) but <ins>**please bear in mind that some reports have been written entirely by AI**</ins>.

After analysis, we have marked 5 vulnerabilities with a "High" level of impact, which justify an immediate upgrade to `2.8.0`, or backporting if packaged by downstream repositories:
- [Patch the Planet: arbitrary read of on-disk files while parsing TLS packets](https://github.com/secdev/scapy/security/advisories/GHSA-g94r-m85q-4mpj)
- [Patch the Planet: out-of-band read while receiving packets through libpcap](https://github.com/secdev/scapy/security/advisories/GHSA-c547-xwrv-q9jm)
- [Patch the Planet: A malicious SMB directory entry makes recursive downloads overwrite arbitrary local files](https://github.com/secdev/scapy/security/advisories/GHSA-7vg7-7f47-97qf)
- [Patch the Planet: SMB server mishandling of share case insensitivity leads to default folder always being served](https://github.com/secdev/scapy/security/advisories/GHSA-72w4-gq3w-rrpp)
- [Patch the Planet: A zero-width NetFlow template keeps `NetflowSession` running forever](https://github.com/secdev/scapy/security/advisories/GHSA-f6x2-gmgm-25p8)

The other issues have been triaged as "Moderate" or "Low" and don't justify immediate action from users or downstream package maintainers (those include crashes, issues in various protocol implementations, automatons and answering machines, mis-implementations of protocols like our TLS stack, etc. but nothing that leads to a potential compromission of the host machine).

We would like to thank again `OpenAI` and `Trail of Bits` (and in particular KernelClint) for this opportunity and the time spent on this project.

Changelog

- **Windows protocols**:
- Kerberos: IAKERB support, WinSSP, KDC pinning, S4U+FAST fix, NTLM MIC server-side check
- SMB: various SMB2 fixes, new `smbclient()` features
- DCE/RPC: fragmentation fixes, proper client auth denial, context commit fixes
- NTLM/SPNEGO/WinSSP: late fallback mechanism, encryption support, doc fixes
- **[new]** registry abstraction layer for [MS-RRP] RPC
- [MS-NRTP] fix
- **Automotive related changes**: 
- Added SAE J1939 support
- Added standalone UDS/KWP/OBD/GMLAN packets
- Improved CAN/ISO-TP soft-socket robustness
- Added configurable busy-response retries in automotive scanners
- Work has begun to clean up the remaining compatibility code that allowed the transition from Python 2.
- Minor security fixes (the full list is available in the Security tab):
- RADIUS: verify Message-Authenticator
- fwdmachine: verify upstream TLS certs, correct TLS server context
- tls/sslv2: stricter security handling
- Several fuzzing-found crash fixes (HSRP, Bluetooth, Kerberos)
- Bound/robustness fixes across pcap, pcapng, ISOTP, TCP reassembly, BGP, IPv6, HTTP, DNS, LDAP, modbus parsing
- **Bluetooth**:
- Many new vendor-specific command modules (Realtek, Barrot, Intel, Espressif, CSR, Zephyr)
- Fixed link-layer byte order, normalized field naming
- New HCI event handler registration mechanism
- **New protocols/contrib**:
- DICOM support
- CBOR implementation (fields + packets)
- SAE J1939 protocol + soft socket
- PTP protocol
- MySQL classic protocol
- **802.11**: added HE Operation, HT Operation, EHT Operation, and Radio Measurement elements
- **Performance**: minor improvements to packet dissection/build speed, reduced unnecessary copying in reassembly paths (netbios, pcapng, HTTP/2, LDAP, ISOTP, TFTP)
- **DNS**: EDNS0 padding option, client-subnet fixes, off-by-four fix
- IGMP: full rework, merged implementations
- Misc fixes: TCP MD5 option calculation, BPF error reporting, FreeBSD 32-bit BPF support, hexdiff bounds check
Links

@JarryShaw JarryShaw added dependencies Pull requests that update a dependency file python Pull requests that update Python code review: running A cross-review is in flight against the current head - no verdict yet labels Oct 5, 2026
@JarryShaw

Copy link
Copy Markdown
Owner

Cross-review verdict on dd07915e0: GOOD TO GO (ran on Opus; opened by pyup-bot).

sphinx-autodoc-typehints 3.13.7 → 3.13.8: no change to the docs. Upstream adds two lines at the top of resolve_type_guarded_imports, so a class passed in resolves through its module. conf.py:19 imports that function and the import is unchanged. Our hook bind_type_checking_names (conf.py:292) always passes a module, so the new branch never runs for it. Built locally with -n in a throwaway venv: 1303 warnings at each version, the same set after normalising paths and line numbers, and the HTML output is byte-identical. CI shows the same: Pages run 37344241904 reports build succeeded, 45 warnings at 3.13.8, and main's run 37343364302 reports the same at 3.13.7.

scapy 2.7.0 → 2.8.0: CI does not test this pin, and 2.8.0 is already in use. examples/benchmark/requirements-common.txt is installed only by examples/benchmark/Dockerfile:110; no workflow installs it, so the green checks prove nothing about this line. CI already uses 2.8.0 anyway. The Scapy extra is unpinned, main's Pages build installs scapy-2.8.0, and conda/requirements.txt:18 is already scapy==2.8.0. Still unverified: the benchmark Docker image itself, which nothing builds.

One follow-up after merge, docs-only: the bind_type_checking_names docstring (conf.py:313-316) says the library "skips classes outright". 3.13.8 is the release that stops doing that. The hook is still needed and works the same, because it binds every module up front, but its stated reason will be out of date.

@JarryShaw JarryShaw added review: good-to-go Cross-review at the current head says ready; CI state is separate and removed review: running A cross-review is in flight against the current head - no verdict yet labels Oct 5, 2026
@JarryShaw
JarryShaw merged commit e1e71eb into main Oct 5, 2026
73 checks passed
@JarryShaw
JarryShaw deleted the pyup-scheduled-update-2026-10-05 branch October 5, 2026 17:28
@JarryShaw JarryShaw removed the review: good-to-go Cross-review at the current head says ready; CI state is separate label Oct 5, 2026
@JarryShaw JarryShaw added this to the 1.5 milestone Oct 6, 2026
@JarryShaw JarryShaw moved this to Done in PyPCAPKit Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants