Repository navigation
fix: patch development and release dependency vulnerabilities - #850
Open
xianshijing-lk wants to merge 1 commit into
Open
xianshijing-lk wants to merge 1 commit into
xianshijing-lk wants to merge 1 commit into
Conversation
xianshijing-lk
requested review from
changt,
cloudwebrtc and
lukasIO
as code owners
October 9, 2026 01:51
Comment on lines
+8
to
+16
| [tool.uv] | ||
| # Security floors for transitive development and release dependencies. | ||
| constraint-dependencies = [ | ||
| "cryptography>=50.0.0", | ||
| "filelock>=3.20.3", | ||
| "pillow>=12.3.0", | ||
| "pygments>=2.20.0", | ||
| "urllib3>=2.8.0", | ||
| ] |
Contributor
There was a problem hiding this comment.
🟨 Release builds bypass patched dependency floors
When release jobs build wheels, constraint-dependencies does not constrain their pip and pipx installs. RTC builds and isolated build dependencies can still select older affected versions.
Was this helpful? React with 👍 or 👎 to provide feedback.
cloudwebrtc
approved these changes
Oct 9, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The repository lockfile contains vulnerable cryptography and other development/release dependencies. Lock cryptography 50.0.2, pytest 9.0.3, Pillow 12.3.0, requests 2.33.0, urllib3 2.8.0, Pygments 2.20.0, and the already used filelock 3.24.3, with security floors to prevent resolving older affected versions.
Patched tooling requires Python 3.10+, so apply that requirement only to the development group. Published SDKs retain Python 3.9 support. Run lint/type tooling on Python 3.12 and additionally type-check all SDK source against Python 3.9. This avoids uv backtracking to obsolete release tools/pycrypto when the cryptography floor excludes Python 3.9.0/3.9.1.
Validation: locked sync on Python 3.12; both mypy checks (102 files and 89 SDK files); Ruff lint/format checks; 36 API/mock-server/failover tests passed; 163 RTC tests passed against a local LiveKit server, with 3 skips. Dependency scans confirm the updated tooling packages have no known vulnerabilities. Runtime aiohttp/idna/multidict/PyJWT findings are handled by the follow-up runtime PR.
Fixes the cryptography finding PYSEC-2026-3552 / GHSA-g6cj-pr64-35w5, plus other tooling advisories. No SDK release is needed for this development-only change. Supersedes the tooling portion of #711 and the revision-only pytest update in #844.