Skip to content

Patch vulnerable Python and web dependencies - #2

Merged
kfallah merged 5 commits into
mainfrom
codex/security-dependencies-20260927
Sep 28, 2026
Merged

kfallah merged 5 commits into
mainfrom
codex/security-dependencies-20260927

Conversation

@kfallah

@kfallah kfallah commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

  • Raise Python security floors to cryptography 50.0.1, Tornado 6.5.10 and pyasn1 0.6.4. Refresh PyOpenSSL to 26.4.0 and lock urllib3 2.8.0 with a 2.7.0 floor in the development and deployment groups.
  • Upgrade the affected web dependency families, including Lodash and Vite. Replace esbuild-jest's obsolete Jest 26 dependency tree with Babel's transformer for the existing Jest 29 runner.
  • Apply compatible Babel, humanfs, once and AJV updates for the remaining patchable moderate and low advisories.
  • Patch h2 4.4.1, hpack 4.2.0, IDNA 3.15, Flask 3.1.3, Werkzeug 3.1.6, setuptools 83.0.0, uv 0.11.15 and Pygments 2.20.0. Match the HTTP/2 wrapper's input annotation to h2's buffer protocol contract.
  • Regenerate the checked-in web assets from the patched lockfile. Remove the source HTML reference to vendor.less, which is absent from the current main branch.
  • Keep the Debian 11/glibc build baseline on signed snapshots from the final LTS day after live security-package URLs returned 404. Expiration checks are disabled only for those timestamped archive sources; APT signature verification remains enabled.
  • Build wheel/sdist with the patched tools from the frozen lockfile. The old reusable workflow installed setuptools 75 and could not satisfy the security floor of 83. The network-isolated build step and artifact name are preserved.

Security evidence

The baseline is the 38 open high-severity GitHub Dependabot alert records for this repository on 2026-09-27. Comparing every matching locked package version with those advisory ranges shows all 38 are patched or removed. npm audit reports zero high, critical or low advisories; six moderate package entries remain, all tracing to UUID through Jest's desktop notification dependency.

Across all severities, the proposed lockfiles patch or remove 71 of 73 baseline alert records. The remaining two are the development-only UUID notification dependency and pytest 8's temporary-directory advisory. The pinned pytest-asyncio 1.2.0 requires pytest <9, so the pytest >=9.0.3 fix needs a paired framework upgrade. No alerts are dismissed by this PR.

Validation

  • Python dependency resolution: passed.
  • Whole-repository Ruff: passed.
  • npm ci, TypeScript and ESLint: passed.
  • Production web bundle build: passed.
  • Whole-repository mypy: passed for 253 source files after the HTTP/2 update.
  • Wheel/sdist build using setuptools 83: passed locally.
  • GitHub CI: passed on final commit dbcd343, including the Python matrix, web suite, Intel Mac build, Linux builds, Windows build, patched wheel build and CodeQL.
  • Greptile: requested, but no review has started. Repository review access needs confirmation before the required 5/5 can be obtained.

Compatibility and rollout

Cryptography 49 and later no longer publish Intel Mac wheels. These pins require cryptography 50.0.1, so Intel Mac Python installations need a compatible source build. The Intel Mac CI install/build job and web suite passed on the final commit.

The currently consumed exp-mitmproxy Capture package lives on codex/capture-package. Its security update and the Experiential repin are separate dependent changes. This main-branch update alone does not update that installed package.

@kfallah

kfallah commented Sep 28, 2026

Copy link
Copy Markdown
Author

@greptileai review

@kfallah

kfallah commented Sep 28, 2026

Copy link
Copy Markdown
Author

@greptileai review

@kfallah

kfallah commented Sep 28, 2026

Copy link
Copy Markdown
Author

@greptileai review

@kfallah

kfallah commented Sep 28, 2026

Copy link
Copy Markdown
Author

@greptileai review

@kfallah

kfallah commented Sep 28, 2026

Copy link
Copy Markdown
Author

@greptileai review

@kfallah
kfallah merged commit b20f0ed into main Sep 28, 2026
52 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant