From 676456960a701e77cb0bc4cff09f12bd8ed7ab5b Mon Sep 17 00:00:00 2001 From: steven-mi Date: Thu, 1 Oct 2026 11:56:00 +0200 Subject: [PATCH] security: bump oauthlib, PyJWT, urllib3 to patched versions Addresses 18 open Dependabot/dependency-graph alerts: - oauthlib >=4.0.0 (GHSA-hj66-6f7g-4r5v, GHSA-xpv3-w29h-x7cv) - urllib3 >=2.8.0 (GHSA-8988-9cw3-xx77, GHSA-vxq7-64xx-v4gw, GHSA-gh4c-6fx4-qh6g) - PyJWT >=2.15.0, newly pinned as a direct dependency since it is a transitive dependency of databricks-cli and was not previously constrained (GHSA-w6j9-cwv2-h6wq, GHSA-2gx3-rcp4-g85q, GHSA-r6x4-923q-g947, GHSA-p4g4-x82p-q773, GHSA-9v7f-9g4p-ffgj, GHSA-w2cx-738m-mc7w, GHSA-ffc3-869f-jxw9, GHSA-hxm8-2xgr-2p9m, GHSA-8wjv-2p76-3863, GHSA-9j54-fg26-wv3r, GHSA-jwrc-g2q2-pq5p, GHSA-42vr-xj54-vc7v, GHSA-gvp8-978c-rx2q) Verified with `poetry lock` that the new constraints resolve cleanly against databricks-cli 0.18.0 (requires urllib3<3,>=1.26.7, oauthlib>=3.1.0, pyjwt>=1.7.0), and ran the test suite locally. --- pyproject.toml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pyproject.toml b/pyproject.toml index 2e87736..53b92bf 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -13,9 +13,12 @@ pyspark = ">=3.4.4" fire = ">=0.4" # this is not a direct dependency of the template, but a dependency of databricks-cli # that comes from mlflow, if we dont pin it here we get a lower version that has a security problem -oauthlib = ">=3.2.1" -urllib3 = ">=1.24.2" +oauthlib = ">=4.0.0" +urllib3 = ">=2.8.0" requests = "^2.23.3" +# PyJWT is a transitive dependency of databricks-cli; pinned here to pull in fixes for +# multiple GHSA advisories (JWK parsing, JWKS redirects/SSRF, HMAC/asymmetric key confusion) +PyJWT = ">=2.15.0" [tool.poetry.scripts] ddataflow = 'ddataflow.ddataflow:main'