Prepare exp-mitmproxy 12.2.3.post2 security dependencies - #3
Merged
kfallah merged 3 commits intoSep 28, 2026
Merged
Conversation
Author
|
@greptileai review |
Author
|
@greptileai review |
Author
|
@greptileai review |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation
Dependency order
This PR targets codex/capture-package, the branch supplying Experiential's immutable Capture pin. It hardens the dependencies from #1 and aligns one type annotation with patched h2. The equivalent main-branch hardening is #2.
The updated lockfiles remove the affected ranges for all 38 baseline high-severity records and 71 of 73 records across all severities. The remaining baseline records are the development-only UUID notification dependency and pytest 8's temporary-directory advisory. The pinned pytest-asyncio 1.2.0 requires pytest <9, so the pytest >=9.0.3 fix needs a paired framework upgrade. Capture additionally retains Bootstrap 3, as shown by the npm audit. No alerts are dismissed.
Publish exp-mitmproxy 12.2.3.post2 from the final reviewed commit before publishing the Experiential repin. The existing Experiential release workflow requires the Capture dependency to be available from PyPI before publication.
Compatibility
Cryptography 49 and later stopped publishing Intel Mac wheels. The new security floor requires 50.0.1; Intel Mac Python installations consequently need a compatible source build. The existing Capture package CI covers Linux, Apple Silicon macOS and Windows. The main-branch dependency PR's Intel Mac install/build job passed with the same cryptography floor.