Skip to content

fix(deps): upgrade dependencies to address security vulnerabilities - #276

Open
dbezic (dbezic) wants to merge 3 commits into
mainfrom
users/dominikbezic/fix-package-versions
Open

dbezic (dbezic) wants to merge 3 commits into
mainfrom
users/dominikbezic/fix-package-versions

Conversation

@dbezic

@dbezic dbezic (dbezic) commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Upgrade the following dependencies to patched versions:

Dependency Previous Updated
mcp 1.26.0 1.28.1
langsmith 0.7.31 0.8.18
pyasn1 0.6.3 0.6.4
python-multipart 0.0.26 0.0.30
langchain-core 1.2.28 1.3.3
PyJWT 2.12.0 2.14.0
anyio 4.12.1 4.14.2
  • Update centralized minimum-version constraints to prevent resolution to affected versions.
  • Declare security-critical transitive dependencies in the affected library manifests
    so published wheels enforce the same minimums, not only workspace installs.
  • Cover LangChain, OpenAI, Semantic Kernel, Agent Framework, and Google ADK
    integrations without adding framework dependencies to unrelated core packages.
  • Publish the PyJWT floor from tooling and notifications as well as runtime,
    protecting consumers that install those packages independently.
  • Regenerate the lockfile, including the required transitive dependency
    langchain-protocol 0.0.19.
  • Preserve all unrelated package versions and existing dependency overrides.
  • Use PyJWT 2.14.0 to address the six additional advisories reported by Dependency
    Review against 2.13.0: GHSA-ffc3-869f-jxw9, GHSA-r6x4-923q-g947,
    GHSA-p4g4-x82p-q773, GHSA-9v7f-9g4p-ffgj, GHSA-w2cx-738m-mc7w,
    and GHSA-9j54-fg26-wv3r.

Validation

  • 511 targeted tests passed for the initial dependency upgrades.
  • 153 targeted JWT, runtime, tooling, token-cache, and dependency tests passed
    after upgrading PyJWT to 2.14.0.
  • 49 packaging tests passed, including 14 regression cases that build actual
    wheels and check each distribution's published runtime dependency requirements.
  • New wheel-metadata tests reproduced the publication gaps before the fixes and
    verify that unrelated framework dependencies are not added to lightweight packages.
  • Lockfile consistency and centralized dependency constraint checks passed.

Copilot AI balanced review requested due to automatic review settings October 1, 2026 12:55
@dbezic
dbezic (dbezic) requested a review from a team as a code owner October 1, 2026 12:55
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/pyjwt 2.14.0 UnknownUnknown
pip/python-multipart 0.0.30 UnknownUnknown
pip/anyio 4.14.2 UnknownUnknown
pip/langchain-core 1.3.3 UnknownUnknown
pip/langchain-protocol 0.0.19 UnknownUnknown
pip/langsmith 0.8.18 UnknownUnknown
pip/mcp 1.28.1 UnknownUnknown
pip/pyasn1 0.6.4 UnknownUnknown

Scanned Files

  • uv.lock

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several transitive security floors are not propagated into published package metadata.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Upgrades vulnerable dependencies and updates centralized resolution constraints.

Changes:

  • Raises minimum versions for seven dependencies.
  • Regenerates the lockfile with patched versions and langchain-protocol.
File Description
pyproject.toml Updates centralized dependency floors.
uv.lock Locks patched releases and transitive dependencies.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pyproject.toml
Comment on lines +93 to +94
"langsmith >= 0.8.18",
"mcp >= 1.28.1",
Copilot AI balanced review requested due to automatic review settings October 1, 2026 13:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several transitive security floors are not propagated to published package metadata.

Review effort: Balanced
Findings: 2 High severity

Open (2)

Comment thread pyproject.toml

# --- Data Validation & Utilities ---
"aiohttp >= 3.8.0",
"anyio >= 4.14.2",

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency floors, package metadata, lockfile, and regression coverage are consistent with the stated security remediation.

Review effort: Balanced
Findings: 2 High severity

Open (2)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants