Skip to content

fix(python-sdk): patch vulnerable async and tooling dependencies - #1720

Merged
Dhravya merged 2 commits into
mainfrom
capy/patch-vulnerable-async-and
Sep 29, 2026
Merged

Dhravya merged 2 commits into
mainfrom
capy/patch-vulnerable-async-and

Conversation

@Dhravya

@Dhravya Dhravya commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Patch the Python SDK lockfile to the first safe releases covering the current Critical/High advisories: anyio 4.14.2, urllib3 2.7.0, aiohttp 3.14.3, Black 26.3.1, and Click 8.3.3. Resolver-required Black dependencies also change (pathspec and pytokens). No SDK source or tests are changed.

Breaking compatibility change

The patched releases require Python >=3.10. Raise requires-python from 3.9 to 3.10, remove the 3.9 classifier, align mypy, and move the minimum-supermemory CI lane from Python 3.9 to 3.10 while retaining supermemory==3.50.0. Raise the existing aiohttp extra and Black dev requirement to their patched releases. Python 3.9 users can no longer install this SDK version; do not publish without accounting for this compatibility change.

Security coverage

Critical anyio GHSA-82r6-8w77-94w6; High urllib3 advisories including GHSA-qccp-gfcp-xxvc, aiohttp GHSA-6mq8-rvhq-8wgg / GHSA-cq5v-8q36-5273, Black GHSA-3936-cmfr-pm3m, and Click PYSEC-2026-2132. Whole-lock OSV scan finds no Critical/High matches; lower-severity findings remain.

Exact Dependabot alert numbers await access: the integration's repository alerts API returns HTTP 403. These advisory IDs must be mapped to the repository alerts before SOC 2 sign-off.

Validation

uv lock --check and uv build pass. Both CI lanes were reproduced locally through locked sync, wheel build/install, dependency check, wheel/version assertion, and tests: Python 3.10 with minimum supermemory==3.50.0 and Python 3.12 with locked supermemory==3.59.0 each passed 31 tests (11 skipped, two existing coroutine warnings). No test-file edits. Existing mypy reports missing requests stubs and, with temporary stubs, 27 existing source typing errors. Black/Flake8/isort flag unchanged source formatting; no formatting changes are included.

Open in Capy

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
supermemory-mcp bfc538c Sep 29 2026, 09:32 PM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
supermemory-app bfc538c Commit Preview URL

Branch Preview URL
Sep 29 2026, 09:33 PM

@socket-security

socket-security Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​black@​25.1.0 ⏵ 26.3.186 -1100 +16100100100

View full report

@Dhravya
Dhravya merged commit c4382f5 into main Sep 29, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant