Skip to content

fix(deps): resolve dependabot vulnerability notifications - #66

Open
dandye wants to merge 1 commit into
mainfrom
fix__dependabot_vulnerabilities
Open

dandye wants to merge 1 commit into
mainfrom
fix__dependabot_vulnerabilities

Conversation

@dandye

@dandye dandye commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

Resolves 13 Dependabot security vulnerability alerts on chronicle/logstory by upgrading dependencies in uv.lock and src/logstory/requirements.txt:

  • urllib3: Upgraded 2.7.0 -> 2.8.0 in src/logstory/requirements.txt and uv.lock
    • CVE-2026-97687 (High): HTTPS proxy TLS configuration may be ignored or overridden
    • CVE-2026-97688 (Medium): Chunked Deflate streaming can enter an infinite loop
    • CVE-2026-97689 (High): HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
  • oauthlib: Upgraded 3.3.1 -> 4.0.0 in src/logstory/requirements.txt and uv.lock
    • CVE-2026-49264 (Medium): Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
    • CVE-2026-49265 (Medium): Timing Attack Vulnerability in PKCE code_verifier Comparison
  • virtualenv: Upgraded 21.7.4 -> 21.12.1 in uv.lock
    • CVE-2026-102930 (High): Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
    • CVE-2026-102938 (Medium): Unsanitized line boundaries in pyvenv.cfg prompt values allowing configuration injection
  • black: Upgraded 25.12.0 -> 26.5.1 (via pyink 26.5.1) in uv.lock
    • CVE-2026-32274 (High): Arbitrary file writes from unsanitized user input in cache file name

Verification

  • uv sync --all-extras: Completed successfully with all updated dependencies installed.
  • uv run pytest: 175/175 tests passed.
  • uv run pytest --cov=logstory: 83.47% test coverage (exceeds 80% requirement).
  • uv run ruff check .: All checks passed.
  • uv run pyink --check src tests: 24 files left unchanged.
  • CHANGELOG.md: Updated with security release notes.

Upgrade dependencies in uv.lock and src/logstory/requirements.txt:
- urllib3: 2.7.0 -> 2.8.0 (resolves CVE-2026-97687, CVE-2026-97688, CVE-2026-97689)
- oauthlib: 3.3.1 -> 4.0.0 (resolves CVE-2026-49264, CVE-2026-49265)
- virtualenv: 21.7.4 -> 21.12.1 (resolves CVE-2026-102930, CVE-2026-102938)
- black: 25.12.0 -> 26.5.1 via pyink 26.5.1 (resolves CVE-2026-32274)
- Update CHANGELOG.md with security release notes

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant