Repository navigation
fix(deps): patch open security alerts - #324
Conversation
📝 WalkthroughWalkthroughThe change documents WS-SEC-001 completion and updates approved ChangesDependency alert remediation
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
dd0200c to
b7cddc9
Compare
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (1)
backend/pyproject.toml (1)
41-42: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winRaise the
pytest-asynciolower bound to1.3.Versions
1.0.0–1.2.0declarepytest<9, which conflicts withpytest>=9.0.3. Updatebackend/uv.lockto use the matching>=1.3,<2.0constraint.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@backend/pyproject.toml` around lines 41 - 42, Update the pytest-asyncio dependency constraint in pyproject.toml from >=1.0,<2.0 to >=1.3,<2.0, then regenerate backend/uv.lock so its resolved metadata and constraint match the updated requirement alongside pytest>=9.0.3.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
@.agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/chunks/WS-SEC-001-01-patch-dependency-alerts.md:
- Around line 43-55: Add fail-fast shell options immediately after the opening
fence; extend the dependency checks to perform a hash-locked dry run of
scripts/mutation-requirements.txt using the same backend installation context;
and update the pytest-asyncio requirement to pin version 1.4.0 or set its
minimum to 1.4.0 while preserving the existing tested dependency workflow.
In @.agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/STATUS.md:
- Around line 4-5: Update the tooling dependency outcome in the status record to
explicitly name the backend pytest/pytest-asyncio pair and the mutation
pytest/uv pair, preserving the existing patched-version wording.
In `@backend/pyproject.toml`:
- Line 21: Synchronize the pypdf dependency records in pyproject.toml,
guide_extractor_dependencies.json, and uv.lock to version 6.15.0 using the
identical wheel URL and SHA-256 hash shown in the diff. Update
docs/spec_artifact_storage_service.md only to declare the approved pypdf
version.
---
Nitpick comments:
In `@backend/pyproject.toml`:
- Around line 41-42: Update the pytest-asyncio dependency constraint in
pyproject.toml from >=1.0,<2.0 to >=1.3,<2.0, then regenerate backend/uv.lock so
its resolved metadata and constraint match the updated requirement alongside
pytest>=9.0.3.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: c6071cd1-62d6-4582-8401-454f4e699738
⛔ Files ignored due to path filters (1)
backend/uv.lockis excluded by!**/*.lock
📒 Files selected for processing (9)
.agent-loop/CURRENT_STATE.md.agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/CHUNK_MAP.md.agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/STATUS.md.agent-loop/initiatives/WS-SEC-001-dependency-alert-remediation/chunks/WS-SEC-001-01-patch-dependency-alerts.mdbackend/config/guide_extractor_dependencies.jsonbackend/pyproject.tomldocs/spec_artifact_storage_service.mdscripts/mutation-requirements.inscripts/mutation-requirements.txt
| "PyJWT[crypto]>=2.13,<3.0", | ||
| "pydantic-settings>=2.6,<3.0", | ||
| "pypdf @ https://files.pythonhosted.org/packages/49/e6/136aa8993a2ae7214e0b0ef2edaa0d2e08d1d4e4982635b08a835ff31ec8/pypdf-6.14.2-py3-none-any.whl#sha256=3f07891af76dc002657e04993ab9b4de81de29f9013b9761d0b7968bff12e946", | ||
| "pypdf @ https://files.pythonhosted.org/packages/af/72/ce3067ac31e214a66388159f8462ddb8c13dd00170f24d555a1f1ae8ee91/pypdf-6.15.0-py3-none-any.whl#sha256=14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee", |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
url='https://files.pythonhosted.org/packages/af/72/ce3067ac31e214a66388159f8462ddb8c13dd00170f24d555a1f1ae8ee91/pypdf-6.15.0-py3-none-any.whl'
sha256='14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee'
for file in \
backend/pyproject.toml \
backend/config/guide_extractor_dependencies.json \
docs/spec_artifact_storage_service.md
do
test -f "$file"
rg -n -F "$url" "$file"
rg -n -F "$sha256" "$file"
doneRepository: Flow-Research/workstream
Length of output: 862
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- candidate dependency and lock files ---'
git ls-files | rg '(^|/)(pyproject\.toml|.*(lock|dependencies|artifact_storage).*)$' || true
printf '%s\n' '--- all pypdf references ---'
rg -n -i -C 2 'pypdf|14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee|pypdf-6\.15\.0' . --glob '!*.pyc' || true
printf '%s\n' '--- relevant tracked-file excerpts ---'
for file in backend/pyproject.toml backend/config/guide_extractor_dependencies.json docs/spec_artifact_storage_service.md; do
if test -f "$file"; then
echo "### $file"
rg -n -i -C 4 'pypdf|pdf|dependency|lock' "$file" || true
else
echo "### $file (missing)"
fi
doneRepository: Flow-Research/workstream
Length of output: 50382
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
python3 - <<'PY'
import json
import re
import tomllib
from pathlib import Path
expected = {
"version": "6.15.0",
"filename": "pypdf-6.15.0-py3-none-any.whl",
"url": "https://files.pythonhosted.org/packages/af/72/ce3067ac31e214a66388159f8462ddb8c13dd00170f24d555a1f1ae8ee91/pypdf-6.15.0-py3-none-any.whl",
"sha256": "14e001d6504822cb1ca9c7ed9a69bccb320f59b320730f55af804361abe4d5ee",
}
pyproject = tomllib.loads(Path("backend/pyproject.toml").read_text())
requirements = pyproject["project"]["dependencies"]
pinned = [r for r in requirements if r.startswith("pypdf @ ")]
print("pyproject:", pinned)
assert len(pinned) == 1
assert expected["url"] in pinned[0]
assert f"`#sha256`={expected['sha256']}" in pinned[0]
manifest = json.loads(Path("backend/config/guide_extractor_dependencies.json").read_text())
entry = next(d for d in manifest["dependencies"] if d["name"] == "pypdf")
artifact = entry["approved_artifacts"][0]
print("manifest:", entry["version"], artifact)
assert entry["version"] == expected["version"]
assert artifact["filename"] == expected["filename"]
assert artifact["url"] == expected["url"]
assert artifact["sha256"] == expected["sha256"]
lock = Path("backend/uv.lock").read_text()
package = re.search(
r'(?ms)^\[\[package\]\]\n(?:(?!^\[\[package\]\]).)*?^name = "pypdf"\n(?:(?!^\[\[package\]\]).)*?^version = "([^"]+)".*?^source = \{ url = "([^"]+)" \}.*?^wheels = \[\n\s+\{ url = "([^"]+)", hash = "sha256:([^"]+)" \ },\n\]',
lock,
)
assert package, "pypdf package record not found in backend/uv.lock"
print("uv.lock:", package.groups())
assert package.group(1) == expected["version"]
assert package.group(2) == expected["url"]
assert package.group(3) == expected["url"]
assert package.group(4) == expected["sha256"]
docs = Path("docs/spec_artifact_storage_service.md").read_text()
versions = re.findall(r"`pypdf==([^`]+)`", docs)
print("docs pypdf version declarations:", versions)
assert versions and all(v == expected["version"] for v in versions)
print("all authoritative records agree")
PY
printf '%s\n' '--- dependency synchronization checks ---'
rg -n -C 3 'guide_extractor_dependencies|uv\.lock|pyproject\.toml|approved_artifacts|canonical allowlist|exact wheel URLs and hashes' \
backend/scripts/check_guide_extractor_dependencies.py \
backend/tests/test_guide_extractor_dependencies.py \
docs/spec_artifact_storage_service.md | head -200Repository: Flow-Research/workstream
Length of output: 282
Keep the pinned pypdf records synchronized.
backend/pyproject.toml, backend/config/guide_extractor_dependencies.json, and backend/uv.lock must use pypdf 6.15.0 with the same wheel URL and SHA-256 hash. docs/spec_artifact_storage_service.md needs only the approved version declaration.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@backend/pyproject.toml` at line 21, Synchronize the pypdf dependency records
in pyproject.toml, guide_extractor_dependencies.json, and uv.lock to version
6.15.0 using the identical wheel URL and SHA-256 hash shown in the diff. Update
docs/spec_artifact_storage_service.md only to declare the approved pypdf
version.
PR Trust Bundle: WS-SEC-001-01
Chunk
WS-SEC-001-01- Patch dependency alertsGoal And Context
Patch the six open Dependabot findings without changing Workstream product
behavior. The bounded contract is
WS-SEC-001-01-patch-dependency-alerts.md.What Changed And Why
cryptographyand the approvedpypdfartifact to patched lines.tooling to mutually compatible patched lines.
durable initiative state.
Scope Control
Only dependency declarations, generated locks, dependency approval records,
the matching normative version declarations, and WS-SEC-001 loop evidence
changed. No product behavior, API, persistence, migration, authorization,
workflow, test, coverage, or CI gate changed.
Acceptance Proof
cryptography50.0.0,pypdf6.15.0, pytest 9.1.1,and pytest-asyncio 1.4.0.
agree on the approved version and artifact identity.
tests passed before publication; the exact-head GitHub workflow supplies the
complete semantic-lane and coverage proof.
Reviewer Results
CI Integrity And Remaining Risks
No workflow, test, lint, coverage, or package-script gate was weakened. Backend
dev ranges may resolve later compatible minor releases in future fresh pip
installs; the exact PR head must pass GitHub Backend before merge.
Human Review And Merge Ownership
Review the dependency versions, exact hashes, synchronized pypdf records, and
green exact-head checks. Only the user may approve and merge this PR.