Skip to content

build(deps): bump urllib3 and pyjwt for security advisories - #209

Merged
ChelseaKR merged 1 commit into
mainfrom
agent/deps-urllib3
Oct 2, 2026
Merged

ChelseaKR merged 1 commit into
mainfrom
agent/deps-urllib3

Conversation

@ChelseaKR

Copy link
Copy Markdown
Owner

What

Bumps two packages in the Python lockfile to clear security advisories that fail the dependency audit:

  • urllib3 from 2.7.0 to 2.8.0.
  • pyjwt from 2.13.0 to 2.15.1, a minor update within the same major version.

No other package version changes. This overlaps the open Dependabot pull request that bumps pyjwt to 2.15.0; that one can be closed once this merges.

Why

  • urllib3 2.7.0 is affected by PYSEC-2026-4175, PYSEC-2026-4176 and PYSEC-2026-4177 (CVE-2026-97687 and CVE-2026-97688), all fixed in 2.8.0.
  • pyjwt 2.13.0 is affected by PYSEC-2026-4140 through PYSEC-2026-4152. pip-audit reports none of them against 2.15.1.

The CI security job runs pip-audit without muting, so it fails on main and on every pull request until this lands.

How

uv lock --upgrade-package urllib3 --upgrade-package pyjwt, which leaves every other pin as it was.

Verification

On this branch, locally: the Python test suite passes, and pip-audit over the locked dependency set reports no known vulnerabilities. CI on this pull request reruns the full set of checks.

Prepared with AI assistance; reviewed before submission.

urllib3 2.7.0 is affected by PYSEC-2026-4175, PYSEC-2026-4176 and PYSEC-2026-4177 (CVE-2026-97687, CVE-2026-97688), fixed in 2.8.0. pyjwt 2.13.0 is affected by PYSEC-2026-4140 to PYSEC-2026-4152, cleared by 2.15.1.
@ChelseaKR
ChelseaKR merged commit 1c9ced6 into main Oct 2, 2026
15 checks passed
@ChelseaKR
ChelseaKR deleted the agent/deps-urllib3 branch October 2, 2026 04:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant