Skip to content

fix(security): require patched urllib3 2.8.0 - #1352

Draft
seonghobae wants to merge 3 commits into
fix/co1347-auth-evidence-successorfrom
fix/co1351-urllib3-security
Draft

seonghobae wants to merge 3 commits into
fix/co1347-auth-evidence-successorfrom
fix/co1351-urllib3-security

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Exact-head security-lock repair — Proposed / HOLD

  • Exact head: 2a3156b1fe32e60492fc10f96fe26b6cf6a240e5
  • Exact tree: ad26d853fb76ca5c9753e54e701e4f396da74eaa
  • Source repair commit: e582818e6dcf3d3892f74577569574e4fdbb3e5d
  • Source repair tree: fcfe8eabed8398dd7711e3516b6cbbc7eb580adf
  • Predecessor RED head: 5f66743fd7675b89ff4906683b0ad4d4d6431fe6
  • State: Draft. Do not merge.

Finding and repair

The predecessor raised the application dependency floor and regenerated the application locks for urllib3 2.8.0, but requirements-security-ci.txt and requirements-security-tools.txt still pinned vulnerable urllib3 2.7.0. Repository metadata RED coverage reproduced the missing declarative security-tool floors.

The ordinary-forward repair:

  • adds urllib3>=2.8.0 to both security-tool input roots;
  • regenerates both security locks with urllib3==2.8.0 and exact hashes;
  • retains typing-extensions==4.16.0 as an explicit CI input so the documented --require-hashes install remains complete;
  • adds executable floor and pin-parity regression coverage;
  • records the Proposed evidence in CHANGELOG.md and docs/product-technical-gap-baseline.md.

No vulnerability ignore, security-gate relaxation, mutable dependency, provider/model fallback, force update, destructive rebase, or valid-delta retirement was introduced.

RED → GREEN evidence

  • RED: security CI/tools inputs lacked a urllib3 2.8.0 floor and both generated locks pinned 2.7.0.
  • RED: the first regenerated CI lock failed a clean Python 3.12 pip install --require-hashes because the prior transitive typing-extensions entry was no longer complete under the recorded generator.
  • GREEN: tests/test_repository_security_metadata.py — 18 passed.
  • GREEN: clean Python 3.12 pip install --require-hashes -r requirements-security-ci.txt — passed.
  • GREEN: pip-audit -r requirements-security-ci.txt — No known vulnerabilities found.
  • GREEN: pip-audit -r requirements-security-tools.txt — No known vulnerabilities found.
  • GREEN: git diff --check — passed.

These are exact-tree local checks, not protected hosted acceptance.

Exact-head hosted evidence

  • Security and Quality run 36929385395 completed skipped at exact head 2a3156b1fe32e60492fc10f96fe26b6cf6a240e5.
  • Its Rust, fuzzing, tests/package-quality, and CodeQL/supply-chain/SBOM jobs were all skipped; none is GREEN evidence.
  • Reviews: 0; approvals: 0; inline review threads: 0.

Stack and merge gates

#1346 remains the canonical earlier lock/security repair and #1348 → #1351 are unresolved prerequisites for this stacked branch. After the canonical protected descendant exists, integrate it non-force, resolve any remaining overlap, retarget in dependency order, and rerun all required Checks on the resulting exact head.

Until then, keep this PR Draft / Proposed / HOLD. A skipped workflow on a non-main stacked base is not GREEN. Protected exact-head Security/Quality, CodeQL, independent approval, ordinary merge, immutable release, and consumer verification remain required.

Official advisories

Raise the requests transitive dependency security floor and regenerate both dependency locks to remediate CVE-2026-97687, CVE-2026-97688, and CVE-2026-97689. Preserve all other package versions and security gates.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Regenerate both security-tool lock sets from explicit urllib3 2.8.0 floors. Preserve the CI hash-install contract with an explicit typing-extensions input and add regression coverage for every maintained lock.
Record the RED predecessor, exact source repair tree, executable verification evidence, and remaining Draft/Proposed stack gates.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant