|
@@ -41,14 +41,15 @@ aioftp>=0.22.0
|
|
|
# Virtual Printer (emulates Bambu printer for slicer uploads)
|
|
# Virtual Printer (emulates Bambu printer for slicer uploads)
|
|
|
pyftpdlib>=2.0.0
|
|
pyftpdlib>=2.0.0
|
|
|
# Upstream's X.509 / PKCS#7 surface is in our trust path via asyncssh,
|
|
# Upstream's X.509 / PKCS#7 surface is in our trust path via asyncssh,
|
|
|
-# pyOpenSSL, py-vapid, http_ece, pywebpush, so this floor tracks the current
|
|
|
|
|
-# fix release: 46.x had GHSA-537c-gmf6-5ccf (fixed in 48.0.1), and 49.0.0 has
|
|
|
|
|
-# PYSEC-2026-3552 (fixed in 50.0.0).
|
|
|
|
|
|
|
+# pyOpenSSL and the virtual printer's certificates, so this floor tracks the
|
|
|
|
|
+# current fix release: 46.x had GHSA-537c-gmf6-5ccf (fixed in 48.0.1), and
|
|
|
|
|
+# 49.0.0 has PYSEC-2026-3552 (fixed in 50.0.0).
|
|
|
cryptography>=50.0.0
|
|
cryptography>=50.0.0
|
|
|
-# Transitive of asyncssh / pywebpush, and the gate on the line above: each
|
|
|
|
|
-# pyOpenSSL release caps `cryptography` to a narrow window (26.3.0 allows
|
|
|
|
|
-# <50, 26.4.0 allows <51), so a stale pyOpenSSL silently pins cryptography
|
|
|
|
|
-# below its fix line -- pip cannot upgrade past the cap even when asked.
|
|
|
|
|
|
|
+# Nothing in the app imports it, but it is installed, and it is the gate on
|
|
|
|
|
+# the line above: each pyOpenSSL release caps `cryptography` to a narrow
|
|
|
|
|
+# window (26.3.0 allows <50, 26.4.0 allows <51), so a stale pyOpenSSL
|
|
|
|
|
+# silently pins cryptography below its fix line -- pip cannot upgrade past
|
|
|
|
|
+# the cap even when asked.
|
|
|
# Raise this floor in the same commit as any cryptography floor.
|
|
# Raise this floor in the same commit as any cryptography floor.
|
|
|
pyopenssl>=26.4.0
|
|
pyopenssl>=26.4.0
|
|
|
|
|
|
|
@@ -63,9 +64,6 @@ defusedxml>=0.7.0 # Safe XML parsing (prevents XXE attacks)
|
|
|
# Excel Export
|
|
# Excel Export
|
|
|
openpyxl>=3.1.0
|
|
openpyxl>=3.1.0
|
|
|
|
|
|
|
|
-# Notifications
|
|
|
|
|
-pywebpush>=2.0.0
|
|
|
|
|
-
|
|
|
|
|
# Utilities
|
|
# Utilities
|
|
|
# 0.0.27 → 0.0.31 clears three CVEs in the parser surface that FastAPI
|
|
# 0.0.27 → 0.0.31 clears three CVEs in the parser surface that FastAPI
|
|
|
# uses for multipart form bodies (CVE-2026-53538/53539/53540).
|
|
# uses for multipart form bodies (CVE-2026-53538/53539/53540).
|
|
@@ -151,12 +149,10 @@ urllib3>=2.7.0
|
|
|
# resolver from picking them.
|
|
# resolver from picking them.
|
|
|
starlette>=1.3.1
|
|
starlette>=1.3.1
|
|
|
|
|
|
|
|
-# Transitive of pywebpush (unpinned `aiohttp` requirement). pywebpush declares
|
|
|
|
|
-# no bound in either direction, so without this floor the resolver happily
|
|
|
|
|
-# installs a vulnerable line: 3.13.5 has CVE-2026-34993 and CVE-2026-47265
|
|
|
|
|
-# (fixed in 3.14.0), and 3.14.1 has PYSEC-2026-3545/3546/3547 (3.14.3 clears
|
|
|
|
|
-# all three). Our direct usage in services/external_camera.py (ClientSession,
|
|
|
|
|
-# ClientTimeout, ClientError, iter_chunked) is unaffected by either bump.
|
|
|
|
|
|
|
+# Used directly by services/external_camera.py (ClientSession, ClientTimeout,
|
|
|
|
|
+# ClientError, iter_chunked). The floor keeps the resolver off vulnerable
|
|
|
|
|
+# lines: 3.13.5 has CVE-2026-34993 and CVE-2026-47265 (fixed in 3.14.0), and
|
|
|
|
|
+# 3.14.1 has PYSEC-2026-3545/3546/3547 (3.14.3 clears all three).
|
|
|
aiohttp>=3.14.3
|
|
aiohttp>=3.14.3
|
|
|
|
|
|
|
|
# Plate Detection (optional - enables build plate empty detection)
|
|
# Plate Detection (optional - enables build plate empty detection)
|