Skip to content

Fix embedded agent PyJWT, urllib3 and oauthlib vulnerabilities - #382

Merged
rb3ckers merged 7 commits into
stackstate-7.78.2from
cve/trivy-python-dependencies-20261002
Oct 2, 2026
Merged

rb3ckers merged 7 commits into
stackstate-7.78.2from
cve/trivy-python-dependencies-20261002

Conversation

@ai-collaboration-app

@ai-collaboration-app ai-collaboration-app Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The embedded agent currently installs PyJWT 2.13.0, urllib3 2.7.0 and oauthlib 3.3.1. Upgrade the source requirements and packaged agent input to PyJWT 2.15.0, urllib3 2.8.0 and oauthlib 4.0.0. Pin oauthlib explicitly for the Kubernetes/requests-oauthlib dependency path and preserve all other packaged runtime inputs.

Adopts the existing commits from #379, #380 and #381. Those PRs update development requirements only; this PR supplies the missing production pins. Agent #542 consumes this exact signed commit, f50c336c6b23beb3f2e651dca558e1dba6a5781a, and exercises a maintained PyJWT options-reuse regression in the packaged images on both architectures. The producer candidate starts at the existing 7.78.2-6 release tree.

Validation: full existing CI matrix 36991969024 is green, including dependency/metadata validation, every integration suite and workflow lint. The combined candidate passes 93 local Dynatrace tests and their lint checks; #379/#380/#381's individual successful PyJWT 2.15.0 CI remains reusable. The complete preserved agent requirements resolve with hashes, install successfully on BCI Python 3.13, and pass pip check, the PyJWT regression and OAuth2Session/Kubernetes client smoke checks. Local Trivy rootfs scanning of that full installed environment identifies all three fixed package versions with zero of the 18 assigned Python CVEs; the same database detects all 18/18 against the original-version control. The companion agent's complete native Omnibus/image CI is green. Actual AMD64 and ARM64 DEBs contain PyJWT 2.15.0, urllib3 2.8.0 and oauthlib 4.0.0; their extracted rootfs scans have zero of the 18 assigned Python CVEs without VEX filtering. Both native image startup/security suites pass all three maintained tests, and both image Trivy reports contain none of these findings. Artifact digests and existing job links are recorded in agent #542.

Scope is the Trivy-only Python findings in cve-reporter run 36983036771/1, verified aggregate digest sha256:600d791947fc21560ab206d820e80af13dab87d0de836377c73cda6046e96345. PyJWT CVE-2026-103001 has no fixed-version field but bounds affected versions through 2.13.0; its options-reuse regression passes on 2.15.0 and fails on 2.13.0. Grype scanning and all existing CI gates remain unchanged. This PR adds no VEX statements, ignore rules, suppressions or exceptions. Only the assigned Trivy findings are remediated; Grype findings remain visible in scans. Any gate failure caused solely by Grype findings must be reported rather than bypassed. Merge and production release/adoption require human approval; this is source/candidate remediation rather than delivery closure.

dependabot Bot and others added 7 commits October 1, 2026 02:12
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@rb3ckers
rb3ckers merged commit 9489042 into stackstate-7.78.2 Oct 2, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants