Skip to content

chore(deps): fix uv audit vulnerabilities - #70

Open
adsharma wants to merge 1 commit into
mainfrom
chore/uv-audit-upgrade
Open

adsharma wants to merge 1 commit into
mainfrom
chore/uv-audit-upgrade

Conversation

@adsharma

@adsharma adsharma commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Summary

uv audit reported 56 known vulnerabilities across 9 packages. This PR upgrades all affected packages to fixed versions. uv audit now reports no known vulnerabilities.

Changes

pyproject.toml — relaxed two over-constrained pins that blocked the fixed versions:

.github/workflows/ci.yml — bumped the two explicit black==26.3.0 installs to black==26.10.0 to match the audited version.

Transitive deps (no constraint changes needed, picked up on re-resolve):

Package Before After Fixes
aiohttp 3.13.5 3.14.4 28 vulns (fixed in 3.14.0–3.14.3)
fsspec 2026.3.0 2026.9.0 GHSA-27vj-qcqg-25rc (fixed in 2026.6.0)
idna 3.11 3.15+ (→3.20) GHSA-65pc-fj4g-8rjx (fixed in 3.15)
multidict 6.7.1 6.9.1 GHSA-54p9-h82j-f925
torch 2.11.0 2.14.1 GHSA-rrmf-rvhw-rf47 (fixed in 2.13.0)
urllib3 2.6.3 2.8.0 10 vulns (fixed in 2.7.0/2.8.0)
virtualenv 21.6.0 21.14.5 8 vulns (fixed in 21.7.11–21.7.13)

(Also: yarl 1.23.0 → 1.25.1, python-discovery 1.4.4 → 1.6.1 as part of the re-resolve.)

Note: uv.lock is gitignored in this repo, so the fix is expressed via constraints; CI resolves fresh with uv pip install -e .[dev].

Verification

  • uv audit: clean (0 vulnerabilities, down from 56)
  • black==26.10.0 --check src_py test: 58 files unchanged
  • Full test suite: left to CI on this PR

uv audit reported 56 known vulnerabilities across 9 packages.
Relax over-constrained pins so the resolver can pick fixed versions:

- black ==26.3.0 -> >=26.3.1 (GHSA-3936-cmfr-pm3m, fixed in 26.3.1;
  resolves to 26.10.0)
- setuptools ~=80.9 -> >=80.9 (GHSA-h35f-9h28-mq5c, fixed in 83.0.0;
  resolves to 84.0.0)

Transitive deps pick up fixes on re-resolve with no constraint
changes needed:
- aiohttp 3.13.5 -> 3.14.4, fsspec 2026.3.0 -> 2026.9.0,
  idna 3.11 -> 3.20, multidict 6.7.1 -> 6.9.1, torch 2.11.0 -> 2.14.1,
  urllib3 2.6.3 -> 2.8.0, virtualenv 21.6.0 -> 21.14.5

Also bump the explicit black==26.3.0 pins in .github/workflows/ci.yml
to black==26.10.0 to match the audited version.

Verified: uv audit reports no known vulnerabilities; black --check
passes on src_py and test. Full test suite left to CI.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant