Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ jobs:
echo "IMAGE_REF=${REGISTRY}/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV"

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4

- name: Log in to Container Registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4
Expand All @@ -82,7 +82,7 @@ jobs:

- name: Build immutable native candidate
id: build
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7
with:
context: .
platforms: linux/${{ matrix.arch }}
Expand Down Expand Up @@ -185,7 +185,7 @@ jobs:
echo "IMAGE_REF=${REGISTRY}/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV"

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4

- name: Log in to Container Registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/graph-pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7

- uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
- uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: '0.12.3'

Expand Down Expand Up @@ -82,5 +82,5 @@ jobs:
name: github-pages
url: ${{ steps.deployment.outputs.page_url }}
steps:
- uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5
- uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5
id: deployment
8 changes: 4 additions & 4 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,10 +35,10 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4

- name: Build AMD64 scan candidate
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7
with:
context: .
platforms: linux/amd64
Expand Down Expand Up @@ -95,10 +95,10 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4

- name: Build ARM64 scan candidate
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7
with:
context: .
platforms: linux/arm64
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ jobs:
python-version: '3.11'

- name: Set up uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
uses: astral-sh/setup-uv@c18668ad3cf93ea998bef934396af7bb5c839dc7 # v10.2.0
with:
version: '0.12.3'

Expand Down Expand Up @@ -536,7 +536,7 @@ jobs:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4
- name: Exercise immutable promotion against a disposable local registry
run: python scripts/check_release_promotion.py

Expand Down
10 changes: 6 additions & 4 deletions requirements-test.txt
Original file line number Diff line number Diff line change
Expand Up @@ -887,10 +887,12 @@ typing-extensions==4.16.0 \
# via
# pyopenssl
# sqlalchemy
urllib3==2.7.0 \
--hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \
--hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897
# via requests
urllib3==2.8.0 \
--hash=sha256:0cf3cae568d36aa9576b28dfb35f11328f1cb974ca7647d9475ebb86c75ac6e3 \
--hash=sha256:63bf2ead4c879426ebf22ef2a781eeb4aa3b4ae798a0435506f8687fd5bb9b63
# via
# -r requirements.in
# requests
webauthn==3.0.0 \
--hash=sha256:324e54e1f6eeef486623b5d90df6fcd74ae04ff0c137d2b818a8f709b6ca3ab8 \
--hash=sha256:b5d0c02b6efa16be683f8a75abd2073f5e59a15f42623cc22c31f27600259e64
Expand Down
2 changes: 2 additions & 0 deletions requirements.in
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,8 @@ qrcode>=8.2,<9
Authlib>=1.8.0,<2
# Compatibility: Authlib's Flask client uses the reviewed Requests 2.x transport API.
requests>=2.34,<3
# Compatibility: Requests 2.x supports urllib3 2.x; 2.8.0 fixes proxy TLS and chunk parsing vulnerabilities.
urllib3>=2.8.0,<3
# Compatibility: Bonsai 1.5.5 supports Python 3.10-3.14 and exposes the
# reviewed OpenLDAP StartTLS, certificate-policy, timeout, and referral APIs.
bonsai==1.5.5
10 changes: 6 additions & 4 deletions requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -856,10 +856,12 @@ typing-extensions==4.16.0 \
# via
# pyopenssl
# sqlalchemy
urllib3==2.7.0 \
--hash=sha256:231e0ec3b63ceb14667c67be60f2f2c40a518cb38b03af60abc813da26505f4c \
--hash=sha256:9fb4c81ebbb1ce9531cce37674bbc6f1360472bc18ca9a553ede278ef7276897
# via requests
urllib3==2.8.0 \
--hash=sha256:0cf3cae568d36aa9576b28dfb35f11328f1cb974ca7647d9475ebb86c75ac6e3 \
--hash=sha256:63bf2ead4c879426ebf22ef2a781eeb4aa3b4ae798a0435506f8687fd5bb9b63
# via
# -r requirements.in
# requests
webauthn==3.0.0 \
--hash=sha256:324e54e1f6eeef486623b5d90df6fcd74ae04ff0c137d2b818a8f709b6ca3ab8 \
--hash=sha256:b5d0c02b6efa16be683f8a75abd2073f5e59a15f42623cc22c31f27600259e64
Expand Down
6 changes: 6 additions & 0 deletions tests/test_dependency_policy.py
Original file line number Diff line number Diff line change
Expand Up @@ -197,6 +197,12 @@ def test_runtime_locks_exclude_vulnerable_cryptography_versions(path):
assert locked_version(path, "cryptography") >= Version("50.0.0")


@pytest.mark.parametrize("path", ["requirements.txt", "requirements-test.txt"])
def test_runtime_locks_exclude_vulnerable_urllib3_versions(path):
"""CVE-2026-97687 and CVE-2026-97689 affect urllib3 before 2.8.0."""
assert locked_version(path, "urllib3") >= Version("2.8.0")


@pytest.mark.parametrize("path", ["requirements.txt", "requirements-test.txt"])
def test_runtime_locks_include_reviewed_mfa_libraries(path):
"""TOTP verification and local SVG provisioning require reviewed APIs."""
Expand Down
10 changes: 5 additions & 5 deletions tests/test_supply_chain_policy.py
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@
'v8.0.1',
),
'actions/deploy-pages': (
'cd2ce8fcbc39b97be8ca5fce6e763baed58fa128',
'368f82528645a54fb793d4d04e342629a3f51346',
'v5',
),
'actions/setup-node': (
Expand Down Expand Up @@ -48,11 +48,11 @@
'v0.36.0',
),
'astral-sh/setup-uv': (
'20cfd1bf945f4377ade1205e4dbc17946fc9a30d',
'v10.0.1',
'c18668ad3cf93ea998bef934396af7bb5c839dc7',
'v10.2.0',
),
'docker/build-push-action': (
'53b7df96c91f9c12dcc8a07bcb9ccacbed38856a',
'c3c9e263c25d99ce0380d002d59b67737d91b0dc',
'v7',
),
'docker/login-action': (
Expand All @@ -64,7 +64,7 @@
'v6',
),
'docker/setup-buildx-action': (
'37fe631027851001ddb9b187196cc803df7f5f0e',
'f87e5991a6d7451dcb8d9637bfbc97413f497069',
'v4',
),
'docker/setup-qemu-action': (
Expand Down
Loading