From 5b75ffb06385986e5dccac0d1cee61a3b27ecbca Mon Sep 17 00:00:00 2001 From: yash-atwal Date: Mon, 21 Sep 2026 18:58:41 +0530 Subject: [PATCH 1/2] fix(deps): patch js-yaml, httplib2 and cryptography advisories - js-yaml: override to 4.3.2 (was 4.3.0). Fixes !!omap quadratic CPU DoS (GHSA-5p4m-2wfm-xmqj / CVE-2026-59870), patched in the 4.x line at 4.3.1. js-yaml is transitive dev tooling only (commitlint/husky). [CTO-5258] - httplib2: 0.19.0 -> 0.32.0. Fixes gzip/deflate decompression-bomb DoS (GHSA-j5g9-f88f-gfj3), first patched in 0.32.0. [CTO-5193] - cryptography: 49.0.0 -> 50.0.1 (fixes PKCS#7 Bleichenbacher oracle, GHSA-g6cj-pr64-35w5). Coupled with pyOpenSSL 26.3.0 -> 26.4.0, which is the release that raises its ceiling to cryptography<51. [CTO-5249] Co-Authored-By: Claude Opus 4.8 --- package-lock.json | 6 +++--- package.json | 3 +++ requirements.txt | 6 +++--- 3 files changed, 9 insertions(+), 6 deletions(-) diff --git a/package-lock.json b/package-lock.json index 328552cf..ac127eea 100644 --- a/package-lock.json +++ b/package-lock.json @@ -960,9 +960,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.3.0", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.0.tgz", - "integrity": "sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==", + "version": "4.3.2", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.2.tgz", + "integrity": "sha512-SFNOvSJ+Dgf/9An904Yx+CgSlIPCkIpao4qo51lpee25TIRejdH3rhR4EZMGoNx3/TP3O+wzWuiTFl4sqbltzA==", "dev": true, "funding": [ { diff --git a/package.json b/package.json index cc9a795f..d748416b 100644 --- a/package.json +++ b/package.json @@ -20,5 +20,8 @@ "@commitlint/cli": "^19.4.0", "@commitlint/config-conventional": "^19.2.2", "husky": "9.1.4" + }, + "overrides": { + "js-yaml": "4.3.2" } } diff --git a/requirements.txt b/requirements.txt index b5e4b367..2047d812 100644 --- a/requirements.txt +++ b/requirements.txt @@ -12,7 +12,7 @@ certifi==2024.7.4 cffi==2.0.0 chardet==3.0.4 configparser==5.0.1 -cryptography==49.0.0 +cryptography==50.0.1 decorator==4.4.2 defusedxml==0.7.1 Deprecated==1.2.10 @@ -29,7 +29,7 @@ futures==3.1.1 fuzzywuzzy==0.18.0 gunicorn==23.0.0 gitpython==3.1.50 -httplib2==0.19.0 +httplib2==0.32.0 hvac==0.10.5 idna==3.15 influxdb==5.3.1 @@ -63,7 +63,7 @@ Pygments==2.20.0 PyJWT==2.13.0 PyMySQL==1.1.1 PyNaCl==1.6.2 -pyOpenSSL==26.3.0 +pyOpenSSL==26.4.0 pyparsing==2.4.7 python-dateutil==2.8.1 python-Levenshtein==0.12.0 From 2f93cd6d85b2ad8751c3ded1668c09142b7d7c3b Mon Sep 17 00:00:00 2001 From: yash-atwal Date: Thu, 24 Sep 2026 10:27:32 +0530 Subject: [PATCH 2/2] fix(deps): bump pyparsing to 3.3.3 for httplib2 0.32.0 httplib2 0.32.0 requires pyparsing>=3.1,<4, which conflicts with the previous pyparsing==2.4.7 pin and broke the build. Bump pyparsing to 3.3.3 (nothing else in requirements caps it). [CTO-5193] Co-Authored-By: Claude Opus 4.8 --- requirements.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index 2047d812..652c3cff 100644 --- a/requirements.txt +++ b/requirements.txt @@ -64,7 +64,7 @@ PyJWT==2.13.0 PyMySQL==1.1.1 PyNaCl==1.6.2 pyOpenSSL==26.4.0 -pyparsing==2.4.7 +pyparsing==3.3.3 python-dateutil==2.8.1 python-Levenshtein==0.12.0 python3-openid==3.2.0