Skip to content

chore(deps): bump urllib3 to 2.8.0 and virtualenv to 21.7.13 for pip-audit - #214

Open
tmatup wants to merge 1 commit into
mainfrom
chore/deps-urllib3-virtualenv
Open

tmatup wants to merge 1 commit into
mainfrom
chore/deps-urllib3-virtualenv

Conversation

@tmatup

@tmatup tmatup commented Oct 2, 2026

Copy link
Copy Markdown
Member

Short version

The Quality Gate's pip-audit step (it checks locked Python dependencies against public security advisories) now fails on every PR. New advisories were published for two locked packages. This PR bumps both to fixed versions in uv.lock. No code changes.

What changed

Package Before After Advisories fixed
urllib3 2.7.0 2.8.0 PYSEC-2026-4175, 4176, 4177
virtualenv 21.2.0 21.7.13 PYSEC-2026-4011, 4012, 4013, 4014
python-discovery 1.2.0 1.6.1 none; virtualenv needs it

Why virtualenv 21.7.13 and not the latest: the latest release, 21.14.5, was uploaded to PyPI on 2026-10-02 at 17:42 UTC, a few hours before this PR. The CI runner pool enforces a minimum package age (safe-chain), so an install of a release that new would likely be refused. 21.7.13 (2026-09-18) is the oldest release that fixes all four advisories.

Example of the failure, from run 37059822719 on #213:

urllib3    2.7.0   PYSEC-2026-4177 2.8.0 ...
virtualenv 21.2.0  PYSEC-2026-4013 21.7.13 ...
##[error]Process completed with exit code 1.

Verification

  • uv run pip-audit with CI's exact flags: No known vulnerabilities found, 1 ignored.
  • make check: passes.
  • pytest -m "not live and not lint": 6,030 passed. The 10 failures are all in tests/test_judge_litellm.py, because the optional litellm extra is not installed on my machine. They are the same failures on main locally and they pass in CI.

This unblocks #213.

🤖 Generated with Claude Code
Co-Authored-By: Claude

🤖 Generated with Claude Code

https://claude.ai/code/session_016sCMS4Kv57eDUxpmW24z9e

…audit

pip-audit in the Quality Gate now fails every PR on new advisories:
urllib3 2.7.0 (PYSEC-2026-4175/4176/4177, fixed in 2.8.0) and virtualenv
21.2.0 (PYSEC-2026-4011..4014, fixed by 21.7.13). virtualenv is pinned to
21.7.13, the oldest fixed release, because the latest (21.14.5) was
published hours ago and is inside the safe-chain minimum package age.
python-discovery moves 1.2.0 -> 1.6.1 as virtualenv's dependency.

🤖 Generated with Claude Code
Co-Authored-By: [Claude](mailto:noreply@anthropic.com)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016sCMS4Kv57eDUxpmW24z9e
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Claude finished @tmatup's task in 1m 13s —— View job


Code Review In Progress

Todo List:

  • Read .github/code_review.md for review guidelines
  • Review project conventions in CLAUDE.md
  • Examine the full diff (git diff origin/main...HEAD)
  • Read the full uv.lock file for context
  • Analyze changes for security fixes
  • Check for completeness and consistency
  • Post review findings

@uipreliga uipreliga left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: coder_eval PR #214 "chore(deps): bump urllib3 to 2.8.0 and virtualenv to 21.7.13 for pip-audit" by @tmatup · chore/deps-urllib3-virtualenv → main · OPEN

Scope: coder_eval PR #214 "chore(deps): bump urllib3 to 2.8.0 and virtualenv to 21.7.13 for pip-audit" by @tmatup · chore/deps-urllib3-virtualenv → main · OPEN · branch chore/deps-urllib3-virtualenv · 966a988 · 2026-10-02T22:59Z · workflow variant

Change class: trivial — lockfile-only dependency bump (uv.lock), no source or config code path touched

A clean, well-scoped security bump. The uv.lock change clears the seven PYSEC advisories that fail pip-audit on main (urllib3 PYSEC-2026-4175/4176/4177, virtualenv PYSEC-2026-4011..4014). The PR body explains why virtualenv 21.7.13 was chosen over the latest release (the CI safe-chain minimum package age), and all 18 CI checks pass on the head, including the Docker/Harbor round trip. Nothing blocks the merge; the two notes below are optional. Overall 10 / 10 on all eight axes.

Summary

Axis Score 🔴 🟠 🟡 🔵 Top Issue
1. Code Quality & Style 10 / 10 0 0 0 0 —
2. Type Safety 10 / 10 0 0 0 0 —
3. Test Health 10 / 10 0 0 0 0 —
4. Security 10 / 10 0 0 0 0 —
5. Architecture & Design 10 / 10 0 0 0 0 —
6. Error Handling & Resilience 10 / 10 0 0 0 0 —
7. API Surface & Maintainability 10 / 10 0 0 0 0 —
8. Evaluation Harness Quality 10 / 10 0 0 0 0 —

Overall Score: 10 / 10 · Weakest Axis: Code Quality & Style at 10 / 10
Totals: 🔴 0 · 🟠 0 · 🟡 0 · 🔵 0 across 8 axes.

Blockers

None.

Non-blocking, but please consider before merge

None.

Nits

None.

What's Missing

Nightly pipeline:

  • 🔵 The change does not say what happens to the nightly or Docker run path. docker/Dockerfile:97 and docker/Dockerfile.runtime:63 install runtime deps with uv export --frozen from uv.lock, so urllib3 2.7.0 -> 2.8.0 ships into every driver: docker image. urllib3 is a runtime dependency through requests and botocore, and botocore is the --backend bedrock judge transport. A minor urllib3 bump on that path needs a line saying the Docker image rebuild and the bedrock judge path were smoke-tested, or that they are not affected. virtualenv and python-discovery come in only through pre-commit (dev), so they have no nightly impact. (trigger: uv.lock)

Parallel paths:

  • 🔵 pyproject.toml [tool.uv] constraint-dependencies still pins urllib3>=2.6.3 (the CVE floor) and the change does not touch it. If 2.8.0 was taken for a security fix, raise the floor to urllib3>=2.8.0 in the same change. Otherwise a later uv lock that re-resolves can move urllib3 back below the fixed version with no signal. If the bump is routine (no advisory), nothing is needed. Say which case applies in the PR. (trigger: uv.lock)

Harness & Lint Improvements

Nothing identified.

Top 5 Priority Actions

  1. Optional: raise the CVE floor in pyproject.toml:234 from urllib3>=2.6.3 to urllib3>=2.8.0 (and consider adding virtualenv>=21.7.13), to match the existing "Fix known CVEs in transitive dependencies" pattern in constraint-dependencies. Then a later re-resolve cannot silently go below the fixed versions.
  2. Optional: add one line to the PR body about the Docker path. urllib3 ships into every driver: docker image through uv export --frozen (docker/Dockerfile:97, docker/Dockerfile.runtime:63), and it is the transport under requests/botocore (the bedrock judge). The green Docker/Harbor round-trip check already covers this, so a single sentence is enough.
  3. Merge to unblock #213, which fails pip-audit on main without this change.

Stats: 0 🔴 · 0 🟠 · 0 🟡 · 0 🔵 across 8 axes reviewed.

@uipreliga uipreliga left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fix what you agree with and 🚢

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants