Skip to content

fix(deps): upgrade pyjwt to 2.15.1 and urllib3 to 2.8.0 for published advisories - #1405

Merged
Brad-Edwards merged 3 commits into
devfrom
fix-dev-supply-chain-pyjwt-urllib3
Sep 30, 2026
Merged

Brad-Edwards merged 3 commits into
devfrom
fix-dev-supply-chain-pyjwt-urllib3

Conversation

@Brad-Edwards

@Brad-Edwards Brad-Edwards commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

dev fails the supply-chain osv-scan gate, which blocks the dev → main PR #1402. Two locked dependencies in implementations/python/uv.lock carry published advisories:

This PR upgrades both packages. The research-evidence captures hash the lockfile, so both are republished.

Requirement UIDs

  • None. This is a dependency security upgrade with no requirement scope.

Related Issues

No issue: remediates a supply-chain gate failure on dev found while checking #1402.

ADR Impact

  • None.

Changes

  • uv.lock: pyjwt 2.14.0 → 2.15.1 and urllib3 2.7.0 → 2.8.0. No other resolution changes.
  • Hash-complete smoke closures and wheelhouse manifests regenerated for all six targets with python -m tools.generate_python_closures.
  • Specification-coverage release 65.0.0 and formal-validation release 66.0.0 (baseline 65.0.0) are cut against the upgraded lock.
  • Participant-crossing model bundle crossing-models/rev2/manifest.json rebound to the new lock digest (its source_digests include uv.lock). The model artifacts are byte-identical; the same in-place rebind as efffbe55.
  • Revision pins advanced in tools/check_specification_coverage.py, tools/formal_semantic_validation/, and the three evidence test modules. Both research indexes now record the new releases.

Test Plan

  • Unit tests pass
  • Integration tests pass if applicable
  • Full completion suite required in CI before merge
  • No coverage regression

nox -s osv_scan passes (it failed on dev at 44a0fd9f). Both evidence checker CLIs pass integrity and replay. The evidence and tooling-policy modules pass with integration included (321 passed), and so do the crossing-export and repository-governance modules (584 passed together). nox -s verify-fast-feedback --base-rev origin/dev passes, and so does tools/check_tooling_artifact_policy.py.

Ground Control Checks

  • Tooling artifact policy passes with the regenerated closures
  • Research-evidence source state binds the upgraded lock (implementation_digest matches the live tree)

Traceability

  • Supply-chain failure on dev: CI run 36781383450, job supply-chain
  • Dropped upgrade: 7c57e70c (upgrade) and 2f09a2b9 (merge that reverted it)

Checklist

  • No security gate weakened; the advisories are fixed by upgrading
  • Captures generated after the last source edit

… advisories

The pyjwt 2.15.1 upgrade from #1404's branch was dropped by a later
merge-conflict resolution that took dev's uv.lock, so dev shipped
pyjwt 2.14.0 (GHSA-42vr-xj54-vc7v). urllib3 2.7.0 has three new
advisories fixed in 2.8.0 (GHSA-8988-9cw3-xx77, GHSA-gh4c-6fx4-qh6g,
GHSA-vxq7-64xx-v4gw). Both made the osv-scan supply-chain gate fail.

Regenerate the hash-complete smoke closures and republish both
research-evidence captures, which bind to the locked dependency set:
specification coverage 65.0.0 and formal semantic validation 66.0.0.
@Brad-Edwards
Brad-Edwards merged commit c6eff0b into dev Sep 30, 2026
33 of 35 checks passed
@Brad-Edwards
Brad-Edwards deleted the fix-dev-supply-chain-pyjwt-urllib3 branch September 30, 2026 22:39
Brad-Edwards added a commit that referenced this pull request Oct 1, 2026
* fix: reject unprovable required evidence media types

* test: republish research evidence captures above the #1405 releases

* Fix SonarCloud findings: isolate the raising call in exception tests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant