Skip to content

fix(deps): patch urllib3 security vulnerabilities - #123

Merged
Sam-24-dev merged 1 commit into
mainfrom
fix/security-urllib3
Oct 5, 2026
Merged

Sam-24-dev merged 1 commit into
mainfrom
fix/security-urllib3

Conversation

@Sam-24-dev

Copy link
Copy Markdown
Owner

Summary

  • Patch the effective Python 3.11 lockfile from urllib3 2.7.0 to 2.8.0 for PYSEC-2026-4175, PYSEC-2026-4176 and PYSEC-2026-4177.
  • Keep urllib3 transitive through requests. Preserve requirements.txt, all 28 other locked versions, and the existing lock-generation convention.
  • This is a manual one-line lock amendment; pip-compile was not available and was not run or installed.

Scope and evidence

Observed local validation

All runtime checks used the explicitly authorized isolated .venv311 Python 3.11.9, not an unrelated existing project environment.

  • Installed only the candidate lock: python.exe -B -m pip install --disable-pip-version-check --no-cache-dir --no-deps --only-binary=:all: -r backend/requirements.lock. All 29 project pins match the environment; no source builds, extra tool installs, or global package changes.
  • Verified isolated executable/prefix, disabled user/system site packages, urllib3.version == 2.8.0, and its module path inside .venv311.
  • python.exe -B -m pip check: No broken requirements found.
  • Existing pip-audit 2.9.0: -r backend/requirements.lock --no-deps --disable-pip --strict --progress-spinner off (external temporary HTTP cache): No known vulnerabilities found, exit 0. No advisory exceptions. CI uses its existing pinned pip-audit 2.10.1.
  • Safeguarded pytest.main, with candidate Python and external temporary fixtures:
    • tests/test_github_etl.py tests/test_reddit_etl.py tests/test_stackoverflow_etl.py -q -ra -p no:cacheprovider --tb=short: 42 passed, no skips.
    • tests/ with the same flags: 427 passed, no skips.
    • The harness blocks network and .env access, redirects output paths outside the repository, disables bytecode/plugin autoload/cacheprovider, and copies existing tracked CSV blob bytes only into temporary test fixtures.
    • An initial complete-suite attempt returned 426 passed / 1 failed because the redirected header fixture lacked its input CSV; after supplying the unchanged Git blob fixture bytes, the full 427-test suite passed. No source/test changes were made to resolve this harness issue.
  • compileall for backend, scripts and tests: exit 0; pycache prefix outside the worktree.
  • Bandit 1.8.6: -r backend scripts -x '/pycache/' -ll: exit 0, no findings.
  • detect-secrets baseline hook on the staged lock and git diff --cached --check: exit 0.
  • Whole-tree Ruff 0.11.13 diagnostic: exit 1 for two pre-existing F401 findings in backend/base_etl.py:18 and scripts/check_frontend_assets.py:7. Both were independently reproduced against identical base Git blobs. No Python source changed; these unrelated lint findings are not hidden or fixed here.
  • Candidate tracked status clean after commit; .venv311 ignored. No data, secrets, AGENTS.md, logs, screenshots, agent/MCP files or temporary artifacts are committed.

Limits and rollback boundary

Copilot AI balanced review requested due to automatic review settings October 5, 2026 19:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.

@Sam-24-dev
Sam-24-dev merged commit 3a78bea into main Oct 5, 2026
6 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants