Skip to content

fix(deps): security floors without Dependabot lock regressions - #153

Merged
TexasCoding merged 1 commit into
mainfrom
maint/152-security-lock-clean
Oct 2, 2026
Merged

TexasCoding merged 1 commit into
mainfrom
maint/152-security-lock-clean

Conversation

@TexasCoding

Copy link
Copy Markdown
Owner

Summary

Dependabot #152 correctly bumps the security group (pyjwt, tornado, urllib3, virtualenv) but its lock regenerate downgrades pins we previously raised in #149:

Package main #152 (bad) this PR
pyjwt 2.13.0 2.15.0 2.15.1
tornado 6.5.8 6.5.9 6.5.10
urllib3 2.7.0 2.8.0 2.8.0 (GHSA-8988-9cw3-xx77, GHSA-vxq7-64xx-v4gw, GHSA-gh4c-6fx4-qh6g)
virtualenv 21.7.7 21.7.13 21.14.3
mcp 1.29.0 1.23.3 ⬇️ 1.29.0 (kept)
semgrep 1.178.0 1.156.0 ⬇️ 1.179.0 (minor up)
pip-audit 2.10.1 2.9.0 ⬇️ 2.10.1 (kept)
click 8.4.2 8.1.8 ⬇️ 8.4.2 (kept)

Also raises [tool.uv] constraint-dependencies floors so future Dependabot security PRs are less likely to regress below these versions.

Test plan

  • uv lock --upgrade-package only for the four security packages
  • Confirmed mcp/pip-audit/click not downgraded
  • uv run pytest -m "unit and not slow" — 2724 passed (1 pre-existing tzdata env miss on main, unrelated; passes after tzdata install)
  • CI green on this PR

Closes nothing; leave #151 open (StrEnum gate still pending). After merge, #152 can be closed as superseded.

Raise constraint floors for pyjwt, tornado, urllib3, and virtualenv, then
regenerate the lock with targeted --upgrade-package so mcp (≥1.29.0),
pip-audit, and click stay put. Addresses the same class of lock
regressions as #152 (semgrep/mcp/pip-audit/click downgrades) while still
landing the security bumps (urllib3 2.8.0 GHSAs, pyjwt, tornado,
virtualenv).

Supersedes Dependabot #152 for merging.
@TexasCoding
TexasCoding merged commit 5350882 into main Oct 2, 2026
7 checks passed
@TexasCoding
TexasCoding deleted the maint/152-security-lock-clean branch October 2, 2026 11:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant