Skip to content

fix: upgrade pyjwt to 2.15.1 and urllib3 to 2.8.0 for Snyk vulnerabilities - #500

Merged
hemang-snyk merged 1 commit into
mainfrom
cursor/snyk-fix-2026-09-30-cbcb
Sep 30, 2026
Merged

hemang-snyk merged 1 commit into
mainfrom
cursor/snyk-fix-2026-09-30-cbcb

Conversation

@cursor

@cursor cursor Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Why

Daily Snyk open-source scan (snyk test --all-projects --reachability --severity-threshold=low) found 16 issues in transitive deps (all reachability: no-path-found).

Package From To Issues
pyjwt (via mcp) 2.13.0 2.15.1 13 (7 critical, 2 high, 4 medium), e.g. SNYK-PYTHON-PYJWT-20248177, -20250951, -20245319, -20246066
urllib3 (via requests) 2.7.0 2.8.0 3 (2 high, 1 medium): SNYK-PYTHON-URLLIB3-20302844, -20302845, -20302846

How

  • [tool.uv].override-dependencies: bump pyjwt>=2.15.0, add urllib3>=2.8.0.
  • uv lock regenerated; only pyjwt and urllib3 changed in uv.lock.

Verification

  • Re-scan after fix: 0 issues.
  • uv sync --locked --all-extras, uv build, compileall src, import of all 45 agent_scan.* modules OK, CLI --help OK.
  • Tests left to CI.
Open in Web View Automation 

Note

Low Risk
Dependency-only security pin updates with no changes to application code; JWT/HTTP client behavior comes from upgraded third-party libraries only.

Overview
Addresses Snyk findings on transitive dependencies by tightening [tool.uv] override-dependencies: pyjwt minimum moves from >=2.13.0 to >=2.15.0 (resolved 2.15.1, pulled in via mcp), and urllib3>=2.8.0 is added (resolved 2.8.0, via requests).

uv.lock is regenerated so only those two packages change versions; no application source changes.

Reviewed by Cursor Bugbot for commit 4b9214e. Bugbot is set up for automated code reviews on this repo. Configure here.

…ities

Fixes 13 pyjwt issues (e.g. SNYK-PYTHON-PYJWT-20245619, SNYK-PYTHON-PYJWT-20250951)
and 3 urllib3 issues (SNYK-PYTHON-URLLIB3-20302844/20302845/20302846).

Co-authored-by: hemang.sarkar <hemang.sarkar@snyk.io>
@hemang-snyk
hemang-snyk marked this pull request as ready for review September 30, 2026 10:57
@hemang-snyk
hemang-snyk requested review from a team and marcelosousa as code owners September 30, 2026 10:57
@qodo-merge-etso

Copy link
Copy Markdown

PR Summary by Qodo

Raise PyJWT and urllib3 minimum versions to address Snyk findings

🐞 Bug fix ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Raise transitive PyJWT and urllib3 minimum versions to address 16 reported Snyk issues.
• Use the existing uv overrides without adding either package as a direct dependency.
Diagram

graph TD
  A["uv overrides"] --> B["uv resolver"] --> C["PyJWT 2.15+"]
  B --> D["urllib3 2.8+"]
Loading
High-Level Assessment

Using the existing transitive-dependency override mechanism is appropriate. Adding PyJWT and urllib3 as direct project dependencies would unnecessarily change the project's declared runtime requirements.

Files changed (1) +2 / -1

Other (1) +2 / -1
pyproject.tomlRaise security floors for PyJWT and urllib3 +2/-1

Raise security floors for PyJWT and urllib3

• Raises the PyJWT override from >=2.13.0 to >=2.15.0 and adds a urllib3 >=2.8.0 override. These constraints steer uv away from versions associated with the reported Snyk findings.

pyproject.toml

@hemang-snyk
hemang-snyk merged commit 0107123 into main Sep 30, 2026
11 checks passed
@qodo-merge-etso

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (1) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Package installs miss the security fixes 🐞 Bug ⛨ Security
Description
The PyJWT and urllib3 minimum versions are set only in [tool.uv].override-dependencies, which does
not become a requirement in the built wheel. When users install the published package through uvx
or pip, dependency resolution can still select versions below the new security floors because
neither constraint appears in [project].dependencies.
Code

pyproject.toml[41]

+    "urllib3>=2.8.0",
Relevance

●● Moderate

The packaging concern is plausible, but history lacks a close precedent for requiring direct project
dependency constraints.

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The package metadata lists neither dependency, while the new floors are confined to uv overrides.
The release target builds and publishes a wheel, and the documented uvx installation uses that
published package rather than this repository’s uv resolution.

pyproject.toml[9-42]
Makefile[62-71]
README.md[69-75]
README.md[109-121]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The uv-only overrides do not enforce the PyJWT and urllib3 security floors for installations of the published wheel.
## Fix Focus Areas
- pyproject.toml[9-28]
- pyproject.toml[39-41]
## Recommended Fix
Declare both minimum versions in `[project].dependencies` so they are included in the wheel metadata, then regenerate the lockfile and verify the built wheel's dependency requirements.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗



Informational

2. Dependency fix lacks a regression check 📘 Rule violation ☼ Reliability
Description
The pyjwt and urllib3 overrides change security-sensitive dependency versions without adding a
test that asserts their minimum safe versions. This PR changes only pyproject.toml in the supplied
diff, and the existing tests do not reference either package, so the test suite has no dedicated
check for this fix.
Code

pyproject.toml[41]

+    "urllib3>=2.8.0",
Relevance

●●● Strong

Dependency-related regression coverage was accepted previously, especially for installation and
dependency-resolution behavior.

PR-#123

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
Rule 4 calls for automated tests with bug fixes. The diff changes the dependency overrides but
includes no test changes, and a search of the existing tests found no references to pyjwt or
urllib3.

Rule 4: Every change must include automated tests; bug fixes add a regression test
pyproject.toml[39-41]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The dependency security fix adds no regression test for the minimum safe versions of pyjwt and urllib3.

## Fix Focus Areas
- pyproject.toml[39-41]
- tests/unit/test_dependency_security.py[1-1]

## Recommended Fix
Add an automated test that checks the installed versions of both packages against the minimum safe versions and run it in CI.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗


Grey Divider

Context sources
✅ Compliance rules (platform): 8 rules
✅ Cross-repo context — repo relationships
Review mode: ⚖️ Balanced: This is a localized dependency override affecting authentication-related PyJWT and HTTP urllib3 runtime behavior, so it warrants a careful single-pass review despite the small diff.

Grey Divider

Tip of the day
💡 Did you know, you can route each severity your way: inline, summary, both, or drop

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread pyproject.toml
"pyjwt>=2.13.0",
"pyjwt>=2.15.0",
"anyio>=4.14.2",
"urllib3>=2.8.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Informational

2. Dependency fix lacks a regression check 📘 Rule violation ☼ Reliability

The pyjwt and urllib3 overrides change security-sensitive dependency versions without adding a
test that asserts their minimum safe versions. This PR changes only pyproject.toml in the supplied
diff, and the existing tests do not reference either package, so the test suite has no dedicated
check for this fix.
Agent Prompt
## Issue description
The dependency security fix adds no regression test for the minimum safe versions of pyjwt and urllib3.

## Fix Focus Areas
- pyproject.toml[39-41]
- tests/unit/test_dependency_security.py[1-1]

## Recommended Fix
Add an automated test that checks the installed versions of both packages against the minimum safe versions and run it in CI.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗

Comment thread pyproject.toml
"pyjwt>=2.13.0",
"pyjwt>=2.15.0",
"anyio>=4.14.2",
"urllib3>=2.8.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Package installs miss the security fixes 🐞 Bug ⛨ Security

The PyJWT and urllib3 minimum versions are set only in [tool.uv].override-dependencies, which does
not become a requirement in the built wheel. When users install the published package through uvx
or pip, dependency resolution can still select versions below the new security floors because
neither constraint appears in [project].dependencies.
Agent Prompt
## Issue description
The uv-only overrides do not enforce the PyJWT and urllib3 security floors for installations of the published wheel.
## Fix Focus Areas
- pyproject.toml[9-28]
- pyproject.toml[39-41]
## Recommended Fix
Declare both minimum versions in `[project].dependencies` so they are included in the wheel metadata, then regenerate the lockfile and verify the built wheel's dependency requirements.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

Dismiss ↗ | View ↗

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants