Skip to content

security: sdk pip-audit findings (pypdf, python-multipart, urllib3, etc.) #469

@bmdhodl

Description

@bmdhodl

Vulnerability

Severity: mixed (high + moderate)
Source: Nightshift supervisor security scan 2026-05-13
Package/file: sdk/ (Python deps)

Details

pip-audit on K:/agent47/sdk reports vulnerable versions across multiple deps:

Suggested fix

cd K:/agent47/sdk
pip install --upgrade pypdf pytest python-dotenv python-multipart requests urllib3 uv
# regenerate lockfile, run tests, commit

Why not auto-fixed

Python dep upgrades require lockfile regeneration + test suite verification; supervisor only auto-fixes npm audit issues that pass build.

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityAuto-managed by SecurityAnalyst

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions