Skip to content

fix(deps): patch open security alerts - #324

Merged
abiorh-claw merged 2 commits into
mainfrom
codex/ws-sec-001-dependency-alerts
Aug 12, 2026
Merged

abiorh-claw merged 2 commits into
mainfrom
codex/ws-sec-001-dependency-alerts

Conversation

@Abiorh001

@Abiorh001 Abiorh001 commented Aug 12, 2026 •

Copy link
Copy Markdown
Collaborator

PR Trust Bundle: WS-SEC-001-01

Chunk

WS-SEC-001-01 - Patch dependency alerts

Goal And Context

Patch the six open Dependabot findings without changing Workstream product
behavior. The bounded contract is
WS-SEC-001-01-patch-dependency-alerts.md.

What Changed And Why

  • Upgraded cryptography and the approved pypdf artifact to patched lines.
  • Upgraded backend pytest/pytest-asyncio and retained mutation pytest/uv
    tooling to mutually compatible patched lines.
  • Preserved exact artifact and mutation-manifest hashes.
  • Synchronized the parser approval manifest, normative specification, and
    durable initiative state.

Scope Control

Only dependency declarations, generated locks, dependency approval records,
the matching normative version declarations, and WS-SEC-001 loop evidence
changed. No product behavior, API, persistence, migration, authorization,
workflow, test, coverage, or CI gate changed.

Acceptance Proof

  • Backend lock resolves cryptography 50.0.0, pypdf 6.15.0, pytest 9.1.1,
    and pytest-asyncio 1.4.0.
  • Mutation requirements hash-install pytest 9.0.3 and uv 0.11.15.
  • The direct PDF pin, approval manifest, lock, and normative specification
    agree on the approved version and artifact identity.
  • Focused dependency/parser/mutation tests and real-PostgreSQL authorization
    tests passed before publication; the exact-head GitHub workflow supplies the
    complete semantic-lane and coverage proof.

Reviewer Results

Reviewer Result Blocking findings Notes
Security PASS WITH LOW RISKS None Stale normative pypdf references fixed
CI integrity PASS WITH LOW RISKS None No CI files or gates changed
Test delta PASS WITH LOW RISKS None No tests or thresholds changed
Senior engineering PASS WITH LOW RISKS None Resolver-marker churn noted as non-blocking
CodeRabbit Addressed None open after fixes Three threads triaged; valid findings fixed

CI Integrity And Remaining Risks

No workflow, test, lint, coverage, or package-script gate was weakened. Backend
dev ranges may resolve later compatible minor releases in future fresh pip
installs; the exact PR head must pass GitHub Backend before merge.

Human Review And Merge Ownership

Review the dependency versions, exact hashes, synchronized pypdf records, and
green exact-head checks. Only the user may approve and merge this PR.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The change documents WS-SEC-001 completion and updates approved pypdf, pytest, and uv dependency records, including hashes, URLs, version constraints, and PDF extraction references.

Changes

Dependency alert remediation

Layer / File(s) Summary
Remediation scope and completion records
.agent-loop/CURRENT_STATE.md, .agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/*
Documents the remediation scope, acceptance criteria, verification commands, risk classification, and completed status.
pypdf version and integrity records
backend/config/guide_extractor_dependencies.json, backend/pyproject.toml, docs/spec_artifact_storage_service.md
Updates pypdf from 6.14.2 to 6.15.0 with revised wheel metadata, hashes, URLs, release data, and PDF extraction references.
Mutation tooling dependency updates
scripts/mutation-requirements.in, scripts/mutation-requirements.txt, backend/pyproject.toml
Updates pytest to 9.0.3 and uv to 0.11.15, including generated metadata and package hashes.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: abiorh-claw

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the change and scope, but it omits several required template sections, including commands, test delta, evidence, and complete gate and ownership checklists. Add the missing template sections and complete the required evidence, test delta, CI integrity, external review, remaining risk, human focus, and merge ownership details.
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the main change: patching open dependency security alerts.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/ws-sec-001-dependency-alerts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Abiorh001
Abiorh001 force-pushed the codex/ws-sec-001-dependency-alerts branch from dd0200c to b7cddc9 Compare August 12, 2026 10:20

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🧹 Nitpick comments (1)
backend/pyproject.toml (1)

41-42: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Raise the pytest-asyncio lower bound to 1.3.

Versions 1.0.0–1.2.0 declare pytest<9, which conflicts with pytest>=9.0.3. Update backend/uv.lock to use the matching >=1.3,<2.0 constraint.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend/pyproject.toml` around lines 41 - 42, Update the pytest-asyncio
dependency constraint in pyproject.toml from >=1.0,<2.0 to >=1.3,<2.0, then
regenerate backend/uv.lock so its resolved metadata and constraint match the
updated requirement alongside pytest>=9.0.3.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
@.agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/chunks/WS-SEC-001-01-patch-dependency-alerts.md:
- Around line 43-55: Add fail-fast shell options immediately after the opening
fence; extend the dependency checks to perform a hash-locked dry run of
scripts/mutation-requirements.txt using the same backend installation context;
and update the pytest-asyncio requirement to pin version 1.4.0 or set its
minimum to 1.4.0 while preserving the existing tested dependency workflow.

In @.agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/STATUS.md:
- Around line 4-5: Update the tooling dependency outcome in the status record to
explicitly name the backend pytest/pytest-asyncio pair and the mutation
pytest/uv pair, preserving the existing patched-version wording.

In `@backend/pyproject.toml`:
- Line 21: Synchronize the pypdf dependency records in pyproject.toml,
guide_extractor_dependencies.json, and uv.lock to version 6.15.0 using the
identical wheel URL and SHA-256 hash shown in the diff. Update
docs/spec_artifact_storage_service.md only to declare the approved pypdf
version.

---

Nitpick comments:
In `@backend/pyproject.toml`:
- Around line 41-42: Update the pytest-asyncio dependency constraint in
pyproject.toml from >=1.0,<2.0 to >=1.3,<2.0, then regenerate backend/uv.lock so
its resolved metadata and constraint match the updated requirement alongside
pytest>=9.0.3.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: c6071cd1-62d6-4582-8401-454f4e699738

📥 Commits

Reviewing files that changed from the base of the PR and between ccef963 and b7cddc9.

⛔ Files ignored due to path filters (1)
  • backend/uv.lock is excluded by !**/*.lock
📒 Files selected for processing (9)
  • .agent-loop/CURRENT_STATE.md
  • .agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/CHUNK_MAP.md
  • .agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/STATUS.md
  • .agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/chunks/WS-SEC-001-01-patch-dependency-alerts.md
  • backend/config/guide_extractor_dependencies.json
  • backend/pyproject.toml
  • docs/spec_artifact_storage_service.md
  • scripts/mutation-requirements.in
  • scripts/mutation-requirements.txt

Comment thread .agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/STATUS.md Outdated
Comment thread backend/pyproject.toml
"PyJWT[crypto]>=2.13,<3.0",
"pydantic-settings>=2.6,<3.0",
"pypdf @ https://files.pythonhosted.org/packages/49/e6/136aa8993a2ae7214e0b0ef2edaa0d2e08d1d4e4982635b08a835ff31ec8/pypdf-6.14.2-py3-none-any.whl#sha256=3f07891af76dc002657e04993ab9b4de81de29f9013b9761d0b7968bff12e946",
"pypdf @ https://files.pythonhosted.org/packages/af/72/ce3067ac31e214a66388159f8462ddb8c13dd00170f24d555a1f1ae8ee91/pypdf-6.15.0-py3-none-any.whl#sha256=14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

url='https://files.pythonhosted.org/packages/af/72/ce3067ac31e214a66388159f8462ddb8c13dd00170f24d555a1f1ae8ee91/pypdf-6.15.0-py3-none-any.whl'
sha256='14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee'

for file in \
  backend/pyproject.toml \
  backend/config/guide_extractor_dependencies.json \
  docs/spec_artifact_storage_service.md
do
  test -f "$file"
  rg -n -F "$url" "$file"
  rg -n -F "$sha256" "$file"
done

Repository: Flow-Research/workstream

Length of output: 862


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf '%s\n' '--- candidate dependency and lock files ---'
git ls-files | rg '(^|/)(pyproject\.toml|.*(lock|dependencies|artifact_storage).*)$' || true

printf '%s\n' '--- all pypdf references ---'
rg -n -i -C 2 'pypdf|14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee|pypdf-6\.15\.0' . --glob '!*.pyc' || true

printf '%s\n' '--- relevant tracked-file excerpts ---'
for file in backend/pyproject.toml backend/config/guide_extractor_dependencies.json docs/spec_artifact_storage_service.md; do
  if test -f "$file"; then
    echo "### $file"
    rg -n -i -C 4 'pypdf|pdf|dependency|lock' "$file" || true
  else
    echo "### $file (missing)"
  fi
done

Repository: Flow-Research/workstream

Length of output: 50382


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

python3 - <<'PY'
import json
import re
import tomllib
from pathlib import Path

expected = {
    "version": "6.15.0",
    "filename": "pypdf-6.15.0-py3-none-any.whl",
    "url": "https://files.pythonhosted.org/packages/af/72/ce3067ac31e214a66388159f8462ddb8c13dd00170f24d555a1f1ae8ee91/pypdf-6.15.0-py3-none-any.whl",
    "sha256": "14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee",
}

pyproject = tomllib.loads(Path("backend/pyproject.toml").read_text())
requirements = pyproject["project"]["dependencies"]
pinned = [r for r in requirements if r.startswith("pypdf @ ")]
print("pyproject:", pinned)
assert len(pinned) == 1
assert expected["url"] in pinned[0]
assert f"`#sha256`={expected['sha256']}" in pinned[0]

manifest = json.loads(Path("backend/config/guide_extractor_dependencies.json").read_text())
entry = next(d for d in manifest["dependencies"] if d["name"] == "pypdf")
artifact = entry["approved_artifacts"][0]
print("manifest:", entry["version"], artifact)
assert entry["version"] == expected["version"]
assert artifact["filename"] == expected["filename"]
assert artifact["url"] == expected["url"]
assert artifact["sha256"] == expected["sha256"]

lock = Path("backend/uv.lock").read_text()
package = re.search(
    r'(?ms)^\[\[package\]\]\n(?:(?!^\[\[package\]\]).)*?^name = "pypdf"\n(?:(?!^\[\[package\]\]).)*?^version = "([^"]+)".*?^source = \{ url = "([^"]+)" \}.*?^wheels = \[\n\s+\{ url = "([^"]+)", hash = "sha256:([^"]+)" \ },\n\]',
    lock,
)
assert package, "pypdf package record not found in backend/uv.lock"
print("uv.lock:", package.groups())
assert package.group(1) == expected["version"]
assert package.group(2) == expected["url"]
assert package.group(3) == expected["url"]
assert package.group(4) == expected["sha256"]

docs = Path("docs/spec_artifact_storage_service.md").read_text()
versions = re.findall(r"`pypdf==([^`]+)`", docs)
print("docs pypdf version declarations:", versions)
assert versions and all(v == expected["version"] for v in versions)
print("all authoritative records agree")
PY

printf '%s\n' '--- dependency synchronization checks ---'
rg -n -C 3 'guide_extractor_dependencies|uv\.lock|pyproject\.toml|approved_artifacts|canonical allowlist|exact wheel URLs and hashes' \
  backend/scripts/check_guide_extractor_dependencies.py \
  backend/tests/test_guide_extractor_dependencies.py \
  docs/spec_artifact_storage_service.md | head -200

Repository: Flow-Research/workstream

Length of output: 282


Keep the pinned pypdf records synchronized.

backend/pyproject.toml, backend/config/guide_extractor_dependencies.json, and backend/uv.lock must use pypdf 6.15.0 with the same wheel URL and SHA-256 hash. docs/spec_artifact_storage_service.md needs only the approved version declaration.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@backend/pyproject.toml` at line 21, Synchronize the pypdf dependency records
in pyproject.toml, guide_extractor_dependencies.json, and uv.lock to version
6.15.0 using the identical wheel URL and SHA-256 hash shown in the diff. Update
docs/spec_artifact_storage_service.md only to declare the approved pypdf
version.

@abiorh-claw
abiorh-claw self-requested a review August 12, 2026 11:16
@abiorh-claw
abiorh-claw merged commit c99976b into main Aug 12, 2026
11 checks passed
@abiorh-claw
abiorh-claw deleted the codex/ws-sec-001-dependency-alerts branch August 12, 2026 11:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants