Repository navigation
fix(deps): security floors without Dependabot lock regressions - #153
Merged
Merged
Conversation
Raise constraint floors for pyjwt, tornado, urllib3, and virtualenv, then regenerate the lock with targeted --upgrade-package so mcp (≥1.29.0), pip-audit, and click stay put. Addresses the same class of lock regressions as #152 (semgrep/mcp/pip-audit/click downgrades) while still landing the security bumps (urllib3 2.8.0 GHSAs, pyjwt, tornado, virtualenv). Supersedes Dependabot #152 for merging.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dependabot #152 correctly bumps the security group (
pyjwt,tornado,urllib3,virtualenv) but its lock regenerate downgrades pins we previously raised in #149:Also raises
[tool.uv] constraint-dependenciesfloors so future Dependabot security PRs are less likely to regress below these versions.Test plan
uv lock --upgrade-packageonly for the four security packagesuv run pytest -m "unit and not slow"— 2724 passed (1 pre-existing tzdata env miss on main, unrelated; passes aftertzdatainstall)Closes nothing; leave #151 open (StrEnum gate still pending). After merge, #152 can be closed as superseded.