Repository navigation
fix(security): require patched urllib3 2.8.0 - #1352
Draft
seonghobae wants to merge 3 commits into
Draft
seonghobae wants to merge 3 commits into
seonghobae wants to merge 3 commits into
Conversation
Raise the requests transitive dependency security floor and regenerate both dependency locks to remediate CVE-2026-97687, CVE-2026-97688, and CVE-2026-97689. Preserve all other package versions and security gates. Co-Authored-By: Claude Code <noreply@anthropic.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Regenerate both security-tool lock sets from explicit urllib3 2.8.0 floors. Preserve the CI hash-install contract with an explicit typing-extensions input and add regression coverage for every maintained lock.
Record the RED predecessor, exact source repair tree, executable verification evidence, and remaining Draft/Proposed stack gates.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Exact-head security-lock repair — Proposed / HOLD
2a3156b1fe32e60492fc10f96fe26b6cf6a240e5ad26d853fb76ca5c9753e54e701e4f396da74eaae582818e6dcf3d3892f74577569574e4fdbb3e5dfcfe8eabed8398dd7711e3516b6cbbc7eb580adf5f66743fd7675b89ff4906683b0ad4d4d6431fe6Finding and repair
The predecessor raised the application dependency floor and regenerated the application locks for urllib3 2.8.0, but
requirements-security-ci.txtandrequirements-security-tools.txtstill pinned vulnerable urllib3 2.7.0. Repository metadata RED coverage reproduced the missing declarative security-tool floors.The ordinary-forward repair:
urllib3>=2.8.0to both security-tool input roots;urllib3==2.8.0and exact hashes;typing-extensions==4.16.0as an explicit CI input so the documented--require-hashesinstall remains complete;CHANGELOG.mdanddocs/product-technical-gap-baseline.md.No vulnerability ignore, security-gate relaxation, mutable dependency, provider/model fallback, force update, destructive rebase, or valid-delta retirement was introduced.
RED → GREEN evidence
pip install --require-hashesbecause the prior transitivetyping-extensionsentry was no longer complete under the recorded generator.tests/test_repository_security_metadata.py— 18 passed.pip install --require-hashes -r requirements-security-ci.txt— passed.pip-audit -r requirements-security-ci.txt— No known vulnerabilities found.pip-audit -r requirements-security-tools.txt— No known vulnerabilities found.git diff --check— passed.These are exact-tree local checks, not protected hosted acceptance.
Exact-head hosted evidence
skippedat exact head2a3156b1fe32e60492fc10f96fe26b6cf6a240e5.Stack and merge gates
#1346 remains the canonical earlier lock/security repair and #1348 → #1351 are unresolved prerequisites for this stacked branch. After the canonical protected descendant exists, integrate it non-force, resolve any remaining overlap, retarget in dependency order, and rerun all required Checks on the resulting exact head.
Until then, keep this PR Draft / Proposed / HOLD. A skipped workflow on a non-
mainstacked base is not GREEN. Protected exact-head Security/Quality, CodeQL, independent approval, ordinary merge, immutable release, and consumer verification remain required.Official advisories