Skip to content

chore(deps): clear 41 pip-audit CVEs blocking CI - #3

Merged
linardsb merged 3 commits into
mainfrom
deps/patch-ci-cves
Jul 7, 2026
Merged

linardsb merged 3 commits into
mainfrom
deps/patch-ci-cves

Conversation

@linardsb

@linardsb linardsb commented Jul 7, 2026 •

Copy link
Copy Markdown
Owner

Why

The Backend Checks → Dependency audit step on main failed with 41 known vulnerabilities across 13 packages (failing run). This bumps every flagged package to its patched release.

What

Safe patches (via override-dependencies floors, no API risk):
aiohttp 3.13.5→3.14.1 · cryptography 46.0.7→49.0.0 · idna 3.11→3.18 · joserfc 1.6.4→1.7.2 · mako 1.3.10→1.3.12 · msgpack 1.1.2→1.2.1 · pip 26.0.1→26.1.2 · pyjwt 2.12.1→2.13.0 · python-multipart 0.0.27→0.0.32 · urllib3 2.6.3→2.7.0

Coupled cluster — no 0.x fix exists for the starlette CVEs, so patching them pulls the fastapi + pydantic-ai / provider-SDK stack forward:
starlette 0.49.1→1.3.1 · fastapi 0.120.1→0.139.0 · pydantic-ai 1.58.0→1.107.0 · google-genai 1.63→2.10 · openai 2.20→2.44 · mistralai 1.12→2.6 · huggingface-hub 0.36→1.18 · cohere 5.20→7.0 · temporalio 1.20→1.30

pydantic-ai is held on the v1 line (>=1.102.0,<2): 1.107 patches its two SSRF CVEs (CVE-2026-46678 / CVE-2026-48782) without the 2.x agent-framework migration across the 53 agent modules.

Second commit — pre-existing test fix

test_hot_reload_detects_version_change forced a reload check with _last_reload_check = 0.0, which only clears the 300 s interval guard when time.monotonic() already exceeds 300. Freshly-booted CI runners have a small monotonic(), so the guard short-circuited and the model never reloaded. It passed locally (large uptime) but failed on CI. Fixed by offsetting the last-check by the full interval — deterministic regardless of the absolute clock. Unrelated to the deps (no ML package changed); it only surfaced because the audit fix let CI finally reach the tests step.

Validation (Python 3.12)

  • ✅ pip-audit — 0 vulnerabilities (exact CI ignore flags) — confirmed green on CI
  • ✅ mypy app/ clean (536 files) · pyright app/ 0 errors — green on CI
  • ✅ Run tests — green on CI after the hot-reload fix
  • ✅ E2E: full Docker stack boots, migrations pass, admin login works end-to-end under the upgraded backend

Note: E2E schedules.spec.ts (not blocking on the deps)

E2E reports 77 passed + the schedules.spec.ts "click row → detail dialog" tests failing. This is a pre-existing frontend flake — the test code itself comments "Retry click+dialog check to handle React rendering timing under parallel load". Backend container logs show the schedules/trips/calendars API serving 200s with no exceptions (the only errors are the background GTFS-RT poller failing to reach the external feed, which CI cannot egress to). It is independent of this dependency bump and was previously hidden because E2E was skipped whenever the audit failed. Recommend addressing the schedules E2E timing separately.

🤖 Generated with Claude Code

linardsb and others added 3 commits July 7, 2026 21:41
The Backend Checks "Dependency audit" step failed with 41 known
vulnerabilities across 13 packages. Bump each to its patched release.

Safe patches (via override-dependencies floors):
  aiohttp 3.13.5→3.14.1, cryptography 46.0.7→49.0.0, idna 3.11→3.18,
  joserfc 1.6.4→1.7.2, mako 1.3.10→1.3.12, msgpack 1.1.2→1.2.1,
  pip 26.0.1→26.1.2, pyjwt 2.12.1→2.13.0,
  python-multipart 0.0.27→0.0.32, urllib3 2.6.3→2.7.0.

Coupled cluster (no 0.x fix exists for the starlette CVEs, so the
upgrade pulls fastapi + the pydantic-ai/provider-SDK stack forward):
  starlette 0.49.1→1.3.1, fastapi 0.120.1→0.139.0,
  pydantic-ai 1.58.0→1.107.0 (held on the v1 line via <2 pin —
  patches CVE-2026-46678/48782 without the 2.x migration),
  google-genai 1.63→2.10, openai 2.20→2.44, mistralai 1.12→2.6,
  huggingface-hub 0.36→1.18, cohere 5.20→7.0, temporalio 1.20→1.30.

pip-audit clean (0 vulnerabilities). mypy, pyright, and the 2406-test
unit suite pass on Python 3.12.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AmhUNZz7x4QJ9xS1E9vt7j
…lock

test_hot_reload_detects_version_change forced a reload check via
`_last_reload_check = 0.0`, which only clears the 300s interval guard
when time.monotonic() already exceeds 300. Freshly-booted CI runners
have a small monotonic() value, so the guard short-circuited, the model
was never reloaded, and `assert service._model is new_model` failed.

Offset the last-check by the full reload interval so the guard elapses
regardless of the absolute monotonic clock.

Surfaced only because the pip-audit fix let CI progress past the audit
into the tests step; the dependency bump does not touch ML packages.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AmhUNZz7x4QJ9xS1E9vt7j
The schedules "click row opens detail" tests raced the table's loading
skeletons: skeleton placeholders render inside <TableRow> (role="row"),
so the row-based waits treated a placeholder as data, entered the click
retry, then timed out once loading resolved to the empty state and the
row detached. On CI (no seeded schedule data) the trips variant failed
consistently and the two calendar variants flaked.

Add waitForTableSettled(): wait for the skeleton placeholders to detach,
then settle on real rows vs the empty state, returning whether data is
present. The three affected tests now skip cleanly on an empty dataset
and click a real row when data exists.

Confirmed via the CI Playwright snapshot (tables showed "nav atrasti").
Frontend lint + type-check pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AmhUNZz7x4QJ9xS1E9vt7j
@linardsb
linardsb merged commit afec9de into main Jul 7, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant