Skip to content

chore(deps): bump anyio from 4.14.0 to 4.14.2 - #2278

Merged
12 commits merged into
mainfrom
dependabot/pip/anyio-4.14.2
Sep 27, 2026
Merged

12 commits merged into
mainfrom
dependabot/pip/anyio-4.14.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Current authority

Canonical shared Strix dependency owner for the AnyIO security repair inherited by dependent lanes.

  • protected base: main@e6334e229581a918e2f22de18733b76fa65d7e71
  • exact head: 8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5
  • effective diff: requirements-strix-ci-hashes.txt only, +3/-3
  • dependency delta: AnyIO 4.14.0 -> 4.14.2
  • lifecycle: OPEN / Draft / do not merge independently while successor fix(opencode): materialize every coverage lock input #2286 is under verification

Exact-head evidence

SAST Semgrep 35649352729, Python Security 35649352757, and Security Scan 35649352800 are terminal SUCCESS on this exact head.

Required CodeQL 35649352653 remains terminal FAILURE. Actions compatibility reached SUCCESS; Python compatibility consumed the current-head dispatch verdict but failed before terminal reconciliation while a later coordinator successfully dispatched the same-head scan. This remains a central CodeQL lifecycle prerequisite, not a reason to alter the one-file dependency delta.

The older Noema APPROVED review is bound to predecessor 3758b890... and does not transfer.

The exact-current-head OpenCode CHANGES_REQUESTED review is also not a source-backed dependency finding. Its own body says no source-backed product finding is synthesized from the coverage gate. Fresh log RCA on Required OpenCode run 35683820627, coverage-evidence job 106642970542 proves the failure happened before target-PR test execution: protected .github@e6334e229581a918e2f22de18733b76fa65d7e71 built the trusted coverage image, then Dockerfile line 89 failed because /requirements-noema-document-ci-hashes.txt was absent from the isolated build context. That defect is canonically owned by #2286; the submitted review is left intact and is not dismissed or reinterpreted as approval.

Successor / cycle break

#2286 predecessor c4a73a174... already carried the canonical coverage build-context repair, but its hosted Python Security gate failed because protected main still pinned this PR's AnyIO 4.14.0. Conversely this PR cannot obtain a valid OpenCode coverage receipt until the #2286 workflow repair is protected.

To break that circular foundation dependency without duplicating source or weakening either gate, #2286 now has ordinary two-parent exact head 42e4198fa012eb24596e7984d77e27f0905348d6: this exact #2278 head is an ancestor, and its effective protected-main diff uses the exact requirements-strix-ci-hashes.txt blob from this owner alongside the five #2286 owner paths. #2286 is Draft and has fresh exact-head hosted runs queued.

This PR therefore remains open as the canonical one-file dependency owner until #2286 is fully verified and protected. PR-0 succession is not claimed merely from ancestry; terminal exact-head acceptance and protected integration of the successor are still required.

Acceptance boundary

Do not create another dependency-fix copy, dismiss the OpenCode review, synthesize status, add a source-neutral wake commit, blindly rerun unchanged failures, transfer predecessor approval, self-approve, force-update history, suppress scanners, or weaken gates. If #2286 does not become the verified protected successor, return to this one-file lane and reacquire its own complete current-head acceptance normally.

seonghobae and others added 6 commits September 18, 2026 18:39
Semgrep OSS and Bandit B310 Medium alerts on main flagged dynamic urllib
use in CodeQL identity and Strix evidence helpers. Fail closed unless the
URL is https://api.github.com so file:// and arbitrary hosts cannot reach
urlopen.

Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.0 to 4.14.2.
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.14.0...4.14.2)

---
updated-dependencies:
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 18, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 18, 2026 22:32
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 18, 2026
@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 0a53f828-e830-4a96-a5b7-f0c89a31a1ab

📥 Commits

Reviewing files that changed from the base of the PR and between e6334e2 and 8a5251b.

📒 Files selected for processing (1)
  • requirements-strix-ci-hashes.txt

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

anyio 의존성이 4.14.0에서 4.14.2로 업데이트되었습니다. 새 버전에 해당하는 SHA-256 해시 2개가 requirements-strix-ci-hashes.txt에 반영되었습니다.

Changes

anyio 의존성 업데이트

Layer / File(s) Summary
anyio 버전 및 해시 변경
requirements-strix-ci-hashes.txt
anyio 버전이 4.14.2로 변경되었습니다. 새 버전의 SHA-256 해시 2개가 적용되었습니다.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: seonghobae

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PR 제목은 anyio를 4.14.0에서 4.14.2로 업데이트하는 주요 변경 사항을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 19, 2026
Clears pip-audit CVE-2026-63374/63349 on requirements-strix-ci-hashes.
seonghobae added a commit that referenced this pull request Sep 19, 2026
Clears pip-audit CVE findings on requirements-strix-ci-hashes.
seonghobae added a commit that referenced this pull request Sep 19, 2026
Clears pip-audit CVE pins on requirements-strix-ci-hashes.
@seonghobae seonghobae added maintenance priority: medium Normal-priority or P2 work labels Sep 19, 2026 — with ChatGPT Codex Connector
Replace retired urllib urlopen monkeypatches with direct CodeQL and Strix dedicated-opener patches. Remove the PR-specific global conftest bridge so both security helpers exercise the same explicit transport boundary without live network access.
seonghobae added a commit that referenced this pull request Sep 19, 2026
Clears pip-audit CVE pins on requirements-strix-ci-hashes.

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The diff updates anyio from 4.14.0 to 4.14.2 in requirements-strix-ci-hashes.txt. This is a routine patch-level dependency bump with no source or test changes. The version line and both corresponding SHA-256 hashes are updated consistently with the file’s autogenerated uv pip compile header. No behavioral regressions or stale references are expected.

Reviewed changed lines

  • requirements-strix-ci-hashes.txt:143 (RIGHT): Updated anyio from 4.14.0 to 4.14.2.

Adversarial validation

  • requirements-strix-ci-hashes.txt:143 (RIGHT) falsified: The update could be a partial or truncated change leaving stale anyio references. — The complete diff is limited to the version line and two hash lines; no other files or references are present in the PR.
  • requirements-strix-ci-hashes.txt:143 (RIGHT) falsified: The replacement hashes might not match anyio 4.14.2 and could be copied or malformed. — The observation that the change is entirely autogenerated by uv plus the structure of the patched hunk make a hash/version mismatch implausible.
  • Residual risk: None identified outside the verified dependency update.

Findings

  • [low] requirements-strix-ci-hashes.txt:143 (RIGHT): Dependency lock file entry updated from 4.14.0 to 4.14.2 with validated, autogenerated SHA-256 hashes.
  • Result: APPROVE
  • Head SHA: 3758b890e012548420da6c3978d3e116ce8b814a
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

Clears Bandit/Semgrep B310 on shared scripts/ci urlopen so the anyio bump is not blocked by unrelated SAST.
Restore the unrelated #2269 URL-opener paths to protected main while retaining the AnyIO 4.14.2 pin and hashes. The URL/redirect responsibility remains in canonical #2279; this PR owns only the dependency security update.

Validated with 56 focused tests, 3,335 full tests plus 28 skipped/40 subtests, warnings-as-errors, diff check, and pip-audit reporting no known vulnerabilities.

Copy link
Copy Markdown
Contributor

Current-head readiness correction for 545648ee56dec2397b88b87a04622d2dc3eae96f.

The only APPROVED review is explicitly bound to predecessor head 3758b890e012548420da6c3978d3e116ce8b814a, so it does not approve the current owner-isolation commit. Current exact-head hosted evidence is also incomplete: CodeQL PR 35440867270 is pending, while Python Security 35440867322, SAST Semgrep 35440867308, and Security Scan 35440867229 are terminal cancelled. Cancellation is not GREEN and predecessor approval/checks do not transfer across the source move.

The current source intent remains valid: isolate the AnyIO 4.14.2 lock delta and restore unrelated URL-authority paths to their canonical owner #2279. The PR is being returned to Draft/Proposed until exact-head checks settle normally and a qualifying independent review binds to 545648ee…. No unchanged-head blind rerun, synthetic status, bypass, merge, or close is authorized.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-current-head integration review for c51c8d23b0f86b95def70b7278be554bc10d59ed (tree 6e35263ab701952822c37946a62637e170af9698).

The dependency lane is now ordinary-forward integrated with protected main@e6334e229581a918e2f22de18733b76fa65d7e71 through ordered parents 545648ee56dec2397b88b87a04622d2dc3eae96f and e6334e229581a918e2f22de18733b76fa65d7e71. GitHub compare is 11 ahead / 0 behind with exactly one effective file: requirements-strix-ci-hashes.txt (3 additions / 3 deletions). The AnyIO 4.14.2 blob and hashes are unchanged from the previously audited dependency-only head; all GitHub API authority code/tests/docs come from the protected owner.

Fresh exact-tree evidence:

  • dependency/security focused tests: 5 passed
  • whole suite with warnings treated as errors: 3,369 passed / 28 skipped / 40 subtests
  • compileall and git diff --check: PASS
  • unresolved review threads: 0

This is an author COMMENT, not a qualifying approval. The existing APPROVED review predates this head and does not transfer. Hosted Python Security, SAST, CodeQL, and Security Scan runs are queued/pending and remain non-passing.

Copy link
Copy Markdown
Contributor

New downstream corroboration: #2283 exact 928fc276891b185943a2a93ac003e227e4e47f6a Python Security run 35552210893 has now reached terminal failure, and its pip-audit job 106278166194 independently reports the same requirements-strix-ci-hashes.txt AnyIO 4.14.0 findings: CVE-2026-63374, CVE-2026-64847, CVE-2026-63349, all fixed by 4.14.2. This strengthens #2278's canonical-owner status; do not duplicate the pin delta into #2283/#2289. #2278 itself still lacks accepted exact-head security GREEN because its four current security workflows are terminal cancelled, so this dependent RED is evidence of need, not merge authority.

Copy link
Copy Markdown
Contributor

Fresh exact-head lifecycle update for 8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5: the body’s earlier “all four current workflows cancelled” statement is now historical. A new exact-head generation exists and is still nonterminal: CodeQL 35649352653, Python Security 35649352757, Security Scan 35649352800, and SAST 35649352729 are queued. Older cancelled runs remain audit evidence only and do not satisfy acceptance. Do not blind-rerun or promote predecessor/current queued evidence; landing gate remains authentic terminal GREEN on one unchanged exact head plus qualifying current-head approval.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • requirements-strix-ci-hashes.txt — repository behavior

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: requirements-strix-ci-hashes.txt"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: requirements-strix-ci-hashes.txt"]
  R1 --> V1["required checks"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5
  • Workflow run: 35683820627
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: requirements-strix-ci-hashes.txt"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: requirements-strix-ci-hashes.txt"]
  R1 --> V1["required checks"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

Copy link
Copy Markdown
Contributor

Current exact-head CodeQL refresh for 8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5: the body’s earlier generic “central verdict pending” state has split by language. In run 35649352653 attempt 2, Detect 106832073848 is SUCCESS; Actions compatibility 106832075996 is terminal SUCCESS after enforcing an authenticated verdict; Python compatibility 106832075831 is terminal FAILURE at Release runner or enforce current-head CodeQL verdict; coordinator 106869471479 is materialized but still queued, runner_id=0, steps=[]. SAST/Python Security/Security Scan remain GREEN. Canonical terminal-publication owner .github#1929 has this exact specimen in comment 5783019222. Keep the one-file dependency owner source-stable; no blind rerun, wake commit, scanner suppression, or synthetic status is justified.

Copy link
Copy Markdown
Contributor

Fresh producer evidence narrows the current CodeQL blocker. Producer 35777136593 is no longer just a publication/re-entry symptom: Python CodeQL dispatch scan (python) job 106951582601 completed analysis, preserved SARIF, and failed the Medium+ gate on the same protected-main py/incomplete-url-substring-sanitization finding in tests/test_organization_commercial_readiness_loop_receipt_contract.py:60. I inspected the preserved codeql-dispatch-python-35777136593-1 artifact; it contains that exact rule/location. Actions 106951582683 passed the SARIF gate but failed the separate GHAS base/head configuration-identity check.

Canonical source successor #2351 exact 657d10402d4d502249423a85faa1f953542cd719 restores the lost #2106 exact-set assertion on current protected main. Do not duplicate that test repair here. The AnyIO 4.14.0 -> 4.14.2 delta remains this PR's sole dependency ownership and its Python Security result remains valid evidence. After #2351 and any GHAS-identity prerequisite normally land, reconcile non-force and reacquire exact-head CodeQL/review evidence; no blind rerun or wake commit.

Copy link
Copy Markdown
Contributor

A foundation check-cycle now exists between this canonical AnyIO owner and the protected-main CodeQL endpoint-contract repair #2351: this PR has Python Security GREEN but producer Python CodeQL fails on the protected-base endpoint assertion; #2351 repairs that assertion but inherits protected main's AnyIO finding. I created Draft integration successor #2352 exact f1a8dc813e6dba4e4905bf3e1b770b6d44344944 as an ordinary two-parent merge of this exact head and #2351 exact head, with a tree containing exactly the two parent-owned blobs and no third semantic delta.

Keep this PR open while #2352 is unmerged. #2352 is not permission to close or relabel this owner as landed; PR-0 is satisfied only if the integration lineage normally reaches protected main with fresh exact-head gates/review and preserves this one-file dependency delta completely.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent scoped dependency verification at 8a5251b.

The complete three-dot diff against protected main e6334e2 is the six-line AnyIO 4.14.0 to 4.14.2 pin/hash delta. Both actual distribution downloads from the official PyPI host match the committed wheel and sdist SHA-256 hashes.

Using hash-pinned pip-audit 2.10.1 in an isolated project venv, with --strict --disable-pip --no-deps --format json, the original full Strix lock produces exactly three AnyIO findings (CVE-2026-63374, CVE-2026-64847, CVE-2026-63349); the repaired full lock produces zero findings and exit 0. Each result contains 106 packages and zero skipped entries. No target packages were installed or executed, and no advisory was ignored.

This matches the actual hosted security failure in Noema #2387 job 108414598334. The exact owner commit has been carried by an ordinary two-parent merge into #2411 at 4ebadfc; only this lockfile and the new evidence note changed during integration. Related integrated-tree tests pass 144/144 with warnings as errors and GITHUB_ACTIONS=true.

The current-head requested-changes review remains intact. It cites coverage failure and does not supply a source-backed lock finding; this scoped security receipt does not dismiss that review, prove hosted acceptance, or authorize main merge. Coverage and live-review requirements remain separate gates.

@seonghobae seonghobae closed this pull request by merging all changes into main in 23c6bea Sep 27, 2026
@seonghobae
seonghobae deleted the dependabot/pip/anyio-4.14.2 branch September 27, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file maintenance priority: medium Normal-priority or P2 work python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant