fix(deps): upgrade pyjwt to 2.15.1 and urllib3 to 2.8.0 for published advisories - #1405
Merged
Merged
Conversation
… advisories The pyjwt 2.15.1 upgrade from #1404's branch was dropped by a later merge-conflict resolution that took dev's uv.lock, so dev shipped pyjwt 2.14.0 (GHSA-42vr-xj54-vc7v). urllib3 2.7.0 has three new advisories fixed in 2.8.0 (GHSA-8988-9cw3-xx77, GHSA-gh4c-6fx4-qh6g, GHSA-vxq7-64xx-v4gw). Both made the osv-scan supply-chain gate fail. Regenerate the hash-complete smoke closures and republish both research-evidence captures, which bind to the locked dependency set: specification coverage 65.0.0 and formal semantic validation 66.0.0.
Brad-Edwards
added a commit
that referenced
this pull request
Sep 30, 2026
Brad-Edwards
added a commit
that referenced
this pull request
Oct 1, 2026
* fix: reject unprovable required evidence media types * test: republish research evidence captures above the #1405 releases * Fix SonarCloud findings: isolate the raising call in exception tests
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
devfails thesupply-chainosv-scan gate, which blocks thedev→mainPR #1402. Two locked dependencies inimplementations/python/uv.lockcarry published advisories:pyjwt2.14.0: GHSA-42vr-xj54-vc7v, fixed in 2.15.0. fix: republish research evidence for the merged control-plane boundary source #1404's branch upgraded to 2.15.1 in7c57e70c, but a laterMerge origin/devresolution (2f09a2b9) tookdev's lockfile and dropped the upgrade.urllib32.7.0: GHSA-8988-9cw3-xx77, GHSA-gh4c-6fx4-qh6g, GHSA-vxq7-64xx-v4gw, all fixed in 2.8.0.This PR upgrades both packages. The research-evidence captures hash the lockfile, so both are republished.
Requirement UIDs
Related Issues
No issue: remediates a supply-chain gate failure on
devfound while checking #1402.ADR Impact
Changes
uv.lock:pyjwt2.14.0 → 2.15.1 andurllib32.7.0 → 2.8.0. No other resolution changes.python -m tools.generate_python_closures.crossing-models/rev2/manifest.jsonrebound to the new lock digest (itssource_digestsincludeuv.lock). The model artifacts are byte-identical; the same in-place rebind asefffbe55.tools/check_specification_coverage.py,tools/formal_semantic_validation/, and the three evidence test modules. Both research indexes now record the new releases.Test Plan
nox -s osv_scanpasses (it failed ondevat44a0fd9f). Both evidence checker CLIs pass integrity and replay. The evidence and tooling-policy modules pass with integration included (321 passed), and so do the crossing-export and repository-governance modules (584 passed together).nox -s verify-fast-feedback --base-rev origin/devpasses, and so doestools/check_tooling_artifact_policy.py.Ground Control Checks
implementation_digestmatches the live tree)Traceability
dev: CI run 36781383450, jobsupply-chain7c57e70c(upgrade) and2f09a2b9(merge that reverted it)Checklist