Skip to content

security: bump oauthlib, PyJWT, urllib3 to patched versions - #53

Merged
steven-mi merged 1 commit into
mainfrom
security/dependabot-bulk-fix-2026-10
Oct 1, 2026
Merged

steven-mi merged 1 commit into
mainfrom
security/dependabot-bulk-fix-2026-10

Conversation

@steven-mi

Copy link
Copy Markdown
Contributor

Summary

Resolves all 18 open Dependabot / dependency-graph security alerts in this repo by bumping three vulnerable dependencies to their patched versions in pyproject.toml:

Package Was Now Advisories fixed
oauthlib >=3.2.1 >=4.0.0 GHSA-hj66-6f7g-4r5v (CVE-2026-49264), GHSA-xpv3-w29h-x7cv (CVE-2026-49265)
urllib3 >=1.24.2 >=2.8.0 GHSA-8988-9cw3-xx77 (CVE-2026-97687), GHSA-vxq7-64xx-v4gw (CVE-2026-97689), GHSA-gh4c-6fx4-qh6g (CVE-2026-97688)
PyJWT (unpinned transitive dep) >=2.15.0 GHSA-w6j9-cwv2-h6wq, GHSA-2gx3-rcp4-g85q, GHSA-r6x4-923q-g947, GHSA-p4g4-x82p-q773, GHSA-9v7f-9g4p-ffgj, GHSA-w2cx-738m-mc7w, GHSA-ffc3-869f-jxw9, GHSA-hxm8-2xgr-2p9m, GHSA-8wjv-2p76-3863, GHSA-9j54-fg26-wv3r, GHSA-jwrc-g2q2-pq5p, GHSA-42vr-xj54-vc7v, GHSA-gvp8-978c-rx2q

PyJWT was previously only a transitive dependency (pulled in by databricks-cli) with no version floor, so it is now pinned directly as a first-class dependency, following the same pattern already used in this file for oauthlib/urllib3.

Corresponding JIRA tickets: AIP-1184 through AIP-1201.

Verification

  • poetry lock resolves cleanly with the new constraints against databricks-cli==0.18.0 (which requires urllib3<3,>=1.26.7, oauthlib>=3.1.0, pyjwt>=1.7.0 — no conflicts).
  • poetry install succeeds; resolved versions: oauthlib==4.0.0, pyjwt==2.15.1, urllib3==2.8.0.
  • Ran poetry run pytest locally: 6 passed, 2 skipped, 4 failed. The 4 failures (test_sampling.py::test_sampling_end2end, test_sql.py::test_sql, tutorial/test_sources_and_writers.py::*) are all pyspark.errors.exceptions.base.PySparkRuntimeError: JAVA_GATEWAY_EXITED — caused by no JVM being installed in my local scratch environment, unrelated to the oauthlib/PyJWT/urllib3 bump. GitHub Actions' ubuntu-latest runner ships a JDK, so CI is expected to pass; will monitor CI and fix forward if something unexpected shows up.

Test plan

  • poetry lock / poetry install resolve without conflicts
  • Local pytest run (modulo missing local JVM)
  • CI green on this PR

🤖 Generated with Claude Code
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com

Addresses 18 open Dependabot/dependency-graph alerts:
- oauthlib >=4.0.0 (GHSA-hj66-6f7g-4r5v, GHSA-xpv3-w29h-x7cv)
- urllib3 >=2.8.0 (GHSA-8988-9cw3-xx77, GHSA-vxq7-64xx-v4gw, GHSA-gh4c-6fx4-qh6g)
- PyJWT >=2.15.0, newly pinned as a direct dependency since it is a transitive
  dependency of databricks-cli and was not previously constrained
  (GHSA-w6j9-cwv2-h6wq, GHSA-2gx3-rcp4-g85q, GHSA-r6x4-923q-g947,
  GHSA-p4g4-x82p-q773, GHSA-9v7f-9g4p-ffgj, GHSA-w2cx-738m-mc7w,
  GHSA-ffc3-869f-jxw9, GHSA-hxm8-2xgr-2p9m, GHSA-8wjv-2p76-3863,
  GHSA-9j54-fg26-wv3r, GHSA-jwrc-g2q2-pq5p, GHSA-42vr-xj54-vc7v,
  GHSA-gvp8-978c-rx2q)

Verified with `poetry lock` that the new constraints resolve cleanly
against databricks-cli 0.18.0 (requires urllib3<3,>=1.26.7, oauthlib>=3.1.0,
pyjwt>=1.7.0), and ran the test suite locally.
@steven-mi
steven-mi requested a review from a team as a code owner October 1, 2026 09:56
@clue-gyg clue-gyg removed the risk:low label Oct 1, 2026
@gyg-pr-tool
gyg-pr-tool Bot requested a review from diskun00 October 1, 2026 09:56
@steven-mi
steven-mi merged commit d4f0e77 into main Oct 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants