Browse Source

chore(deps): bump PyJWT to 2.15.1, urllib3 to 2.8.0, virtualenv floor

maziggy 1 day ago
parent
commit
30f3b3b5f2
3 changed files with 10 additions and 7 deletions
  1. 1 1
      pyproject.toml
  2. 3 0
      requirements-dev.txt
  3. 6 6
      requirements.txt

+ 1 - 1
pyproject.toml

@@ -83,5 +83,5 @@ markers = [
 [dependency-groups]
 dev = [
     "cryptography>=46.0.7",
-    "pyjwt>=2.13.0",
+    "pyjwt>=2.15.1",
 ]

+ 3 - 0
requirements-dev.txt

@@ -27,5 +27,8 @@ pip-audit>=2.7.0
 # (Unpacker SEGV/DoS on reuse after caught error). Not a runtime dep of
 # Bambuddy — pinned here so the audit stays clean.
 msgpack>=1.2.1
+# Transitive of pre-commit. 21.7.13 closes four advisories in 21.6.x.
+# Not a runtime dep of Bambuddy — pinned here so the audit stays clean.
+virtualenv>=21.7.13
 # Secrets scan: gitleaks (Go binary, not a Python package).
 # Install: go install github.com/zricethezav/gitleaks/v8@latest

+ 6 - 6
requirements.txt

@@ -106,7 +106,7 @@ psutil>=6.0.0
 tzdata>=2024.1; sys_platform == "win32"
 
 # Authentication
-PyJWT>=2.13.0
+PyJWT>=2.15.1
 passlib[bcrypt]>=1.7.4
 ldap3>=2.9.0
 pyotp>=2.9.0
@@ -137,11 +137,11 @@ certifi>=2024.2.2
 # version detection and logs a warning at startup.
 curl_cffi>=0.7.0
 
-# Transitive pin: urllib3 2.6.3 has CVE-2026-44431 and CVE-2026-44432;
-# 2.7.0+ is the fixed release. Direct pin here because none of our
-# top-level deps require >=2.7.0 yet, so without this the resolver
-# would silently keep installing the vulnerable 2.6.x line.
-urllib3>=2.7.0
+# Transitive pin: urllib3 2.7.0 has three advisories (streaming
+# decompression limits, proxy TLS settings); 2.8.0 is the fixed release.
+# Direct pin here because none of our top-level deps require >=2.8.0 yet,
+# so without this the resolver would silently keep the vulnerable line.
+urllib3>=2.8.0
 
 # Transitive of fastapi. starlette 1.0.0 has PYSEC-2026-161; 1.1.x has
 # CVE-2026-54282/54283; 1.3.1 is the fixed release. fastapi's range still