Repository navigation
fix: upgrade pyjwt to 2.15.1 and urllib3 to 2.8.0 for Snyk vulnerabilities - #500
Conversation
…ities Fixes 13 pyjwt issues (e.g. SNYK-PYTHON-PYJWT-20245619, SNYK-PYTHON-PYJWT-20250951) and 3 urllib3 issues (SNYK-PYTHON-URLLIB3-20302844/20302845/20302846). Co-authored-by: hemang.sarkar <hemang.sarkar@snyk.io>
PR Summary by QodoRaise PyJWT and urllib3 minimum versions to address Snyk findings
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
Code Review by Qodo
1. Package installs miss the security fixes
|
| "pyjwt>=2.13.0", | ||
| "pyjwt>=2.15.0", | ||
| "anyio>=4.14.2", | ||
| "urllib3>=2.8.0", |
There was a problem hiding this comment.
2. Dependency fix lacks a regression check 📘 Rule violation ☼ Reliability
The pyjwt and urllib3 overrides change security-sensitive dependency versions without adding a test that asserts their minimum safe versions. This PR changes only pyproject.toml in the supplied diff, and the existing tests do not reference either package, so the test suite has no dedicated check for this fix.
Agent Prompt
## Issue description
The dependency security fix adds no regression test for the minimum safe versions of pyjwt and urllib3.
## Fix Focus Areas
- pyproject.toml[39-41]
- tests/unit/test_dependency_security.py[1-1]
## Recommended Fix
Add an automated test that checks the installed versions of both packages against the minimum safe versions and run it in CI.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
| "pyjwt>=2.13.0", | ||
| "pyjwt>=2.15.0", | ||
| "anyio>=4.14.2", | ||
| "urllib3>=2.8.0", |
There was a problem hiding this comment.
1. Package installs miss the security fixes 🐞 Bug ⛨ Security
The PyJWT and urllib3 minimum versions are set only in [tool.uv].override-dependencies, which does not become a requirement in the built wheel. When users install the published package through uvx or pip, dependency resolution can still select versions below the new security floors because neither constraint appears in [project].dependencies.
Agent Prompt
## Issue description
The uv-only overrides do not enforce the PyJWT and urllib3 security floors for installations of the published wheel.
## Fix Focus Areas
- pyproject.toml[9-28]
- pyproject.toml[39-41]
## Recommended Fix
Declare both minimum versions in `[project].dependencies` so they are included in the wheel metadata, then regenerate the lockfile and verify the built wheel's dependency requirements.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
Why
Daily Snyk open-source scan (
snyk test --all-projects --reachability --severity-threshold=low) found 16 issues in transitive deps (all reachability:no-path-found).How
[tool.uv].override-dependencies: bumppyjwt>=2.15.0, addurllib3>=2.8.0.uv lockregenerated; only pyjwt and urllib3 changed inuv.lock.Verification
uv sync --locked --all-extras,uv build,compileall src, import of all 45agent_scan.*modules OK, CLI--helpOK.Note
Low Risk
Dependency-only security pin updates with no changes to application code; JWT/HTTP client behavior comes from upgraded third-party libraries only.
Overview
Addresses Snyk findings on transitive dependencies by tightening
[tool.uv]override-dependencies:pyjwtminimum moves from>=2.13.0to>=2.15.0(resolved 2.15.1, pulled in viamcp), andurllib3>=2.8.0is added (resolved 2.8.0, viarequests).uv.lockis regenerated so only those two packages change versions; no application source changes.Reviewed by Cursor Bugbot for commit 4b9214e. Bugbot is set up for automated code reviews on this repo. Configure here.