You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Scheduled weekly dependency update for week 40 - #1033
<!-- Release notes generated using configuration in .github/release.yaml at main -->
What's Changed
* 🐛 fix(resolver): resolve guarded class imports by gaborbernat in https://github.com/tox-dev/sphinx-autodoc-typehints/pull/775
**Full Changelog**: https://github.com/tox-dev/sphinx-autodoc-typehints/compare/3.13.7...3.13.8
*Hi everyone. This release is a bit different, as it is heavily focused on security fixes as we are clearing our backlog of AI-Assisted reports. We have also clarified the guidelines around AI, contributions and security reports. To contributors, feel free to reach out if you haven't heard back from us in a whilte !*
Deprecation notice
- This major version will be **the last to support Python 3.7 and 3.8**. While this was initially planned for 2.7.0, support was extended because of how used those versions still were. They have been EoL for more than 2 years, and we highly encourage remaining users to upgrade.
A note about contributing guidelines
We have clarified our CONTRIBUTING and SECURITY guidelines. This notably includes some new guidance related to the use of AI, and some instructions regarding the submission of security issues. We encourage contributors to take a moment to read the updated versions.
Security
Scapy has taken part in `OpenAI + Trail of Bits` collab's initiative called ["Patch the Planet"](https://openai.com/index/patch-the-planet/). As part of this initiative, we have received a free security coverage of our code overseen by [KernelClint](https://github.com/KernelClint) (Trail of Bits) and multiple OpenAI agents. This has led to the discovery of around 130+ bugs, among which were 54 issues that could be considered related to security, with various degrees of severity. You can find a partial list on https://github.com/secdev/scapy/security/advisories and [here](https://github.com/secdev/scapy/pulls?q=is%3Apr+state%3Amerged+author%3Akernelclint) but <ins>**please bear in mind that some reports have been written entirely by AI**</ins>.
After analysis, we have marked 5 vulnerabilities with a "High" level of impact, which justify an immediate upgrade to `2.8.0`, or backporting if packaged by downstream repositories:
- [Patch the Planet: arbitrary read of on-disk files while parsing TLS packets](https://github.com/secdev/scapy/security/advisories/GHSA-g94r-m85q-4mpj)
- [Patch the Planet: out-of-band read while receiving packets through libpcap](https://github.com/secdev/scapy/security/advisories/GHSA-c547-xwrv-q9jm)
- [Patch the Planet: A malicious SMB directory entry makes recursive downloads overwrite arbitrary local files](https://github.com/secdev/scapy/security/advisories/GHSA-7vg7-7f47-97qf)
- [Patch the Planet: SMB server mishandling of share case insensitivity leads to default folder always being served](https://github.com/secdev/scapy/security/advisories/GHSA-72w4-gq3w-rrpp)
- [Patch the Planet: A zero-width NetFlow template keeps `NetflowSession` running forever](https://github.com/secdev/scapy/security/advisories/GHSA-f6x2-gmgm-25p8)
The other issues have been triaged as "Moderate" or "Low" and don't justify immediate action from users or downstream package maintainers (those include crashes, issues in various protocol implementations, automatons and answering machines, mis-implementations of protocols like our TLS stack, etc. but nothing that leads to a potential compromission of the host machine).
We would like to thank again `OpenAI` and `Trail of Bits` (and in particular KernelClint) for this opportunity and the time spent on this project.
Changelog
- **Windows protocols**:
- Kerberos: IAKERB support, WinSSP, KDC pinning, S4U+FAST fix, NTLM MIC server-side check
- SMB: various SMB2 fixes, new `smbclient()` features
- DCE/RPC: fragmentation fixes, proper client auth denial, context commit fixes
- NTLM/SPNEGO/WinSSP: late fallback mechanism, encryption support, doc fixes
- **[new]** registry abstraction layer for [MS-RRP] RPC
- [MS-NRTP] fix
- **Automotive related changes**:
- Added SAE J1939 support
- Added standalone UDS/KWP/OBD/GMLAN packets
- Improved CAN/ISO-TP soft-socket robustness
- Added configurable busy-response retries in automotive scanners
- Work has begun to clean up the remaining compatibility code that allowed the transition from Python 2.
- Minor security fixes (the full list is available in the Security tab):
- RADIUS: verify Message-Authenticator
- fwdmachine: verify upstream TLS certs, correct TLS server context
- tls/sslv2: stricter security handling
- Several fuzzing-found crash fixes (HSRP, Bluetooth, Kerberos)
- Bound/robustness fixes across pcap, pcapng, ISOTP, TCP reassembly, BGP, IPv6, HTTP, DNS, LDAP, modbus parsing
- **Bluetooth**:
- Many new vendor-specific command modules (Realtek, Barrot, Intel, Espressif, CSR, Zephyr)
- Fixed link-layer byte order, normalized field naming
- New HCI event handler registration mechanism
- **New protocols/contrib**:
- DICOM support
- CBOR implementation (fields + packets)
- SAE J1939 protocol + soft socket
- PTP protocol
- MySQL classic protocol
- **802.11**: added HE Operation, HT Operation, EHT Operation, and Radio Measurement elements
- **Performance**: minor improvements to packet dissection/build speed, reduced unnecessary copying in reassembly paths (netbios, pcapng, HTTP/2, LDAP, ISOTP, TFTP)
- **DNS**: EDNS0 padding option, client-subnet fixes, off-by-four fix
- IGMP: full rework, merged implementations
- Misc fixes: TCP MD5 option calculation, BPF error reporting, FreeBSD 32-bit BPF support, hexdiff bounds check
Cross-review verdict on dd07915e0: GOOD TO GO (ran on Opus; opened by pyup-bot).
sphinx-autodoc-typehints 3.13.7 → 3.13.8: no change to the docs. Upstream adds two lines at the top of resolve_type_guarded_imports, so a class passed in resolves through its module. conf.py:19 imports that function and the import is unchanged. Our hook bind_type_checking_names (conf.py:292) always passes a module, so the new branch never runs for it. Built locally with -n in a throwaway venv: 1303 warnings at each version, the same set after normalising paths and line numbers, and the HTML output is byte-identical. CI shows the same: Pages run 37344241904 reports build succeeded, 45 warnings at 3.13.8, and main's run 37343364302 reports the same at 3.13.7.
scapy 2.7.0 → 2.8.0: CI does not test this pin, and 2.8.0 is already in use.examples/benchmark/requirements-common.txt is installed only by examples/benchmark/Dockerfile:110; no workflow installs it, so the green checks prove nothing about this line. CI already uses 2.8.0 anyway. The Scapy extra is unpinned, main's Pages build installs scapy-2.8.0, and conda/requirements.txt:18 is already scapy==2.8.0. Still unverified: the benchmark Docker image itself, which nothing builds.
One follow-up after merge, docs-only: the bind_type_checking_names docstring (conf.py:313-316) says the library "skips classes outright". 3.13.8 is the release that stops doing that. The hook is still needed and works the same, because it binds every module up front, but its stated reason will be out of date.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
dependenciesPull requests that update a dependency filepythonPull requests that update Python code
2 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update sphinx-autodoc-typehints from 3.13.7 to 3.13.8.
Changelog
3.13.8
Links
Update scapy from 2.7.0 to 2.8.0.
Changelog
2.8.0
Links