Skip to content

build(deps): patch vulnerabilities and batch Dependabot updates - #704

Merged
frgfm merged 2 commits into
mainfrom
fix/dependency-security-and-update-policy
Oct 2, 2026
Merged

frgfm merged 2 commits into
mainfrom
fix/dependency-security-and-update-policy

Conversation

@frgfm

@frgfm frgfm commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Daily dependency updates were creating repeated minimum-version and observability PRs while the lockfile retained vulnerable packages. This change batches routine maintenance monthly, patches the remaining inexpensive dependency findings not covered by #695, and prevents an empty JWT signing secret from overriding the generated fallback.

Dependency fixes

Package Locked upgrade Distinct advisories removed Highest upstream severity
AnyIO 4.13.0 → 4.14.2 2 Critical
PyJWT 2.12.1 → 2.15.1 14 Critical
urllib3 2.7.0 → 2.8.0 3 High
Jinja2 3.0.3 → 3.1.6 5 Moderate

Raise the PyJWT requirement to >=2.15.0 and remove the vulnerable Jinja2<3.1 docs constraint. Set the Sphinx minimum to the already locked 5.3.0 for compatibility with Jinja2 3.1; no other docs tooling upgrade is needed. Preserve the existing lockfile format and unrelated versions.

Upstream severity does not imply every exploit is reachable here: JWT verification uses a shared secret and HS256 rather than JWKS or mixed algorithms; Jinja2 is docs-only. urllib3's response handling fixes apply to Requests-based downstream HTTP calls.

Empty JWT secret fix

Docker Compose supplies JWT_SECRET="" when it is unset. Pydantic settings loading previously overwrote the random class default with that empty value, permitting an empty signing key with the old JWT library and causing login failures with the patched library. Generate the default per settings instance and normalize empty values after loading; preserve configured nonempty secrets exactly. Regression tests cover absent, empty, and explicit environment values.

Dependabot policy

  • Monthly grouped updates with a seven-day release cooldown: at most two routine Python PRs, one Actions PR, and one LocalStack PR.
  • Python minor/patch version updates cover all packages, split into quality tools and remaining dependencies. increase-if-necessary avoids needless minimum-version raises and the wildcard group includes sentry-sdk[fastapi].
  • Remove explicit target-branch and the package allowlist; group security fixes across all packages separately. allow.update-types, cooldown, schedule, and version PR limits do not delay security updates or exclude required major security fixes.
  • Use the supported Docker Compose updater for root Compose files. Keep uv Dockerfile/workflow pins coordinated manually.

Existing automated PR recommendations

PR Recommendation Reason
#695 Merged into main; preserved by this rebase SoupSieve 2.9 fixes GHSA-gjv8-xp57-g29c and GHSA-j934-xhv5-fg8f. It also updates idna, Starlette, and pydantic-settings.
#702 Discard Routine Sentry minimum-version bump; none of the audited vulnerabilities addressed.
#693 Defer to monthly maintenance; discard the current PR if clearing the queue Routine PostHog/Sentry updates, no identified security fixes.
#689 Defer to monthly maintenance; discard the current PR if clearing the queue Quality tools only, no identified security fixes.

All four had 22 passing checks when initially inspected. #695 is now merged; this PR is rebased onto that change.

Audit scope and validation

After rebasing onto main with #695 merged, the all-groups lockfile audit reports no known vulnerabilities. This PR removes the 24 distinct advisories in AnyIO, PyJWT, urllib3, and Jinja2; #695 already removed the two SoupSieve findings.

GitHub's push summary reports 24 open alerts on the default branch (2 critical, 5 high, 16 moderate, 1 low). Its Dependabot and code-scanning alert endpoints return HTTP 403 with the available integration, so those 24 alerts cannot be reconciled individually against this audit; alert-read access is needed for that remaining review. These are dependency/advisory audit results, not a claim that the repository's private alert list is empty. Local packages and the Git-pinned camera client are excluded from package advisory matching; their registry dependencies are included. Container OS packages and source code scanning were not audited.

Pre-rebase validation:

  • Backend suite: 666 passed, 1 skipped against native PostgreSQL and S3 emulator (test-backend.sh -q --maxfail=1).
  • Client suite: 16 passed, disposable database and live local API. The empty-secret integration run also verifies login after the fix; an initial attempt hit the existing timing-sensitive 10µs timeout assertion before a successful rerun.
  • Authentication smoke: valid token accepted; expired and tampered tokens rejected with 401; noncanonical signature rejected with 406.
  • Direct docs-extra installs and strict Sphinx builds pass on Python 3.10 and 3.11.
  • Ruff lint/format, ty, pinned uv 0.11.14 lock check, dependency synchronization, Dependabot schema validation, and git diff --check pass.

GitHub CI on pre-rebase head 9f8a514: all 23 checks passed, including backend/client tests, end-to-end, Docker and client builds, CodeQL, Socket, and coverage.
Rebase validation on 1566817 (base 710648e): lockfile and dependency synchronization checks passed, 14 configuration/security tests passed, and the all-groups dependency audit is clean. CI is rerunning for the rebased head.

@github-actions github-actions Bot added topic: build Related to build, installation & CI topic: ci labels Oct 2, 2026
@socket-security

socket-security Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​jinja2@​3.0.3 ⏵ 3.1.698 +1100 +11100100100
Updatedpypi/​pyjwt@​2.12.1 ⏵ 2.15.1100 +1100 +75100100100

View full report

@codecov

codecov Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.87%. Comparing base (710648e) to head (1566817).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #704   +/-   ##
=======================================
  Coverage   93.87%   93.87%           
=======================================
  Files          59       59           
  Lines        3214     3218    +4     
=======================================
+ Hits         3017     3021    +4     
  Misses        197      197           
Flag Coverage Δ
backend 93.99% <100.00%> (+<0.01%) ⬆️
client 91.30% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@frgfm
frgfm force-pushed the fix/dependency-security-and-update-policy branch from 9f8a514 to 1566817 Compare October 2, 2026 17:14
@frgfm frgfm self-assigned this Oct 2, 2026
@frgfm
frgfm merged commit 25f3d2e into main Oct 2, 2026
23 checks passed
@frgfm
frgfm deleted the fix/dependency-security-and-update-policy branch October 2, 2026 17:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant