Skip to content

fix: patch development and release dependency vulnerabilities - #850

Open
xianshijing-lk wants to merge 1 commit into
mainfrom
fix/dependency-security-2026
Open

xianshijing-lk wants to merge 1 commit into
mainfrom
fix/dependency-security-2026

Conversation

@xianshijing-lk

Copy link
Copy Markdown
Contributor

The repository lockfile contains vulnerable cryptography and other development/release dependencies. Lock cryptography 50.0.2, pytest 9.0.3, Pillow 12.3.0, requests 2.33.0, urllib3 2.8.0, Pygments 2.20.0, and the already used filelock 3.24.3, with security floors to prevent resolving older affected versions.

Patched tooling requires Python 3.10+, so apply that requirement only to the development group. Published SDKs retain Python 3.9 support. Run lint/type tooling on Python 3.12 and additionally type-check all SDK source against Python 3.9. This avoids uv backtracking to obsolete release tools/pycrypto when the cryptography floor excludes Python 3.9.0/3.9.1.

Validation: locked sync on Python 3.12; both mypy checks (102 files and 89 SDK files); Ruff lint/format checks; 36 API/mock-server/failover tests passed; 163 RTC tests passed against a local LiveKit server, with 3 skips. Dependency scans confirm the updated tooling packages have no known vulnerabilities. Runtime aiohttp/idna/multidict/PyJWT findings are handled by the follow-up runtime PR.

Fixes the cryptography finding PYSEC-2026-3552 / GHSA-g6cj-pr64-35w5, plus other tooling advisories. No SDK release is needed for this development-only change. Supersedes the tooling portion of #711 and the revision-only pytest update in #844.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread pyproject.toml
Comment on lines +8 to +16
[tool.uv]
# Security floors for transitive development and release dependencies.
constraint-dependencies = [
"cryptography>=50.0.0",
"filelock>=3.20.3",
"pillow>=12.3.0",
"pygments>=2.20.0",
"urllib3>=2.8.0",
]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟨 Release builds bypass patched dependency floors

When release jobs build wheels, constraint-dependencies does not constrain their pip and pipx installs. RTC builds and isolated build dependencies can still select older affected versions.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants