From 30f3b3b5f25fc3ba57a98728cd72d626cddd8d06 Mon Sep 17 00:00:00 2001 From: maziggy Date: Fri, 2 Oct 2026 15:51:15 +0200 Subject: [PATCH] chore(deps): bump PyJWT to 2.15.1, urllib3 to 2.8.0, virtualenv floor --- pyproject.toml | 2 +- requirements-dev.txt | 3 +++ requirements.txt | 12 ++++++------ 3 files changed, 10 insertions(+), 7 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index 338892ea4..df7798044 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -83,5 +83,5 @@ markers = [ [dependency-groups] dev = [ "cryptography>=46.0.7", - "pyjwt>=2.13.0", + "pyjwt>=2.15.1", ] diff --git a/requirements-dev.txt b/requirements-dev.txt index 7f96464c3..748c20182 100644 --- a/requirements-dev.txt +++ b/requirements-dev.txt @@ -27,5 +27,8 @@ pip-audit>=2.7.0 # (Unpacker SEGV/DoS on reuse after caught error). Not a runtime dep of # Bambuddy — pinned here so the audit stays clean. msgpack>=1.2.1 +# Transitive of pre-commit. 21.7.13 closes four advisories in 21.6.x. +# Not a runtime dep of Bambuddy — pinned here so the audit stays clean. +virtualenv>=21.7.13 # Secrets scan: gitleaks (Go binary, not a Python package). # Install: go install github.com/zricethezav/gitleaks/v8@latest diff --git a/requirements.txt b/requirements.txt index d994b5e92..df59f34b3 100644 --- a/requirements.txt +++ b/requirements.txt @@ -106,7 +106,7 @@ psutil>=6.0.0 tzdata>=2024.1; sys_platform == "win32" # Authentication -PyJWT>=2.13.0 +PyJWT>=2.15.1 passlib[bcrypt]>=1.7.4 ldap3>=2.9.0 pyotp>=2.9.0 @@ -137,11 +137,11 @@ certifi>=2024.2.2 # version detection and logs a warning at startup. curl_cffi>=0.7.0 -# Transitive pin: urllib3 2.6.3 has CVE-2026-44431 and CVE-2026-44432; -# 2.7.0+ is the fixed release. Direct pin here because none of our -# top-level deps require >=2.7.0 yet, so without this the resolver -# would silently keep installing the vulnerable 2.6.x line. -urllib3>=2.7.0 +# Transitive pin: urllib3 2.7.0 has three advisories (streaming +# decompression limits, proxy TLS settings); 2.8.0 is the fixed release. +# Direct pin here because none of our top-level deps require >=2.8.0 yet, +# so without this the resolver would silently keep the vulnerable line. +urllib3>=2.8.0 # Transitive of fastapi. starlette 1.0.0 has PYSEC-2026-161; 1.1.x has # CVE-2026-54282/54283; 1.3.1 is the fixed release. fastapi's range still