Skip to content

MAINT: Fix dependency alerts - #2981

Merged
Roman Lutz (romanlutz) merged 2 commits into
microsoft:mainfrom
romanlutz:romanlutz-dependency-security-alerts
Oct 5, 2026
Merged

Roman Lutz (romanlutz) merged 2 commits into
microsoft:mainfrom
romanlutz:romanlutz-dependency-security-alerts

Conversation

@romanlutz

Copy link
Copy Markdown
Contributor

Description

GitHub reported 31 Dependabot alerts across Python and frontend dependencies. This consolidates their fixes and also patches the additional high-severity nanoid advisory found during npm audit.

Related PRs: #2928 covers part of the PyJWT remediation, and #2924 covers the nested brace-expansion instance. This change includes those upgrades plus the remaining vulnerable versions and instances; neither existing PR was modified.

Dependency Previous lock Updated lock
PyJWT 2.13.0 2.15.1
JupyterLab 4.5.10 4.6.4
Notebook 7.5.6 7.6.3
virtualenv 20.36.1 21.14.5
Tornado 6.5.8 6.5.10
urllib3 2.7.0 2.8.0
brace-expansion, root 5.0.8 5.0.12
brace-expansion, nested 2.1.4 2.1.7
js-yaml 4.3.0 4.3.2
nanoid 3.3.16 3.3.19

Python security floors are raised alongside the targeted lock updates. The published PyJWT runtime minimum becomes 2.15.0. The new virtualenv>=21.7.13 entry is only a uv resolution constraint: pre-commit already brings in virtualenv through [dependency-groups].dev, so this does not add a PyRIT runtime dependency.

Notebook 7.6.3 requires JupyterLab 4.6.4. Required companion changes are limited to the filelock upgrade and the jupyter-builder/python-discovery additions. Frontend updates preserve compatible major versions, unrelated package entries, and platform metadata. No application code or CodeQL configuration is changed.

Tests and Documentation

Validation was completed on Windows with Python 3.14.4, uv 0.11.8, and Node 25.7.0. All 31 recorded GitHub vulnerable ranges, plus the additional nanoid range, are excluded from the updated lockfiles.

Command Result
uv lock --check --no-progress && uv sync --locked --no-progress Passed
uv tool run --from uv==0.9.17 uv lock --check --no-progress Passed with the CI uv version
npm ci --no-fund --no-audit Passed
npm run lint Passed
npm run type-check Passed
npm run test:coverage -- --runInBand Passed: 99 suites, 2,606 tests, coverage checks
npm audit --json Passed: zero vulnerabilities, including dev dependencies
git diff --check Passed

The npm commands above were run from frontend.

Affected Python authentication, networking, HTTP target, and MCP tests: 256 passed with this command from the repository root:

uv sync --locked --extra all --quiet && uv run --locked --extra all -m pytest -q tests\unit\auth\test_manual_copilot_authenticator.py tests\unit\auth\test_copilot_authenticator.py tests\unit\auth\test_browser_session_copilot_authenticator.py tests\unit\common\test_common_net_utility.py tests\unit\prompt_target\target\test_http_target.py tests\unit\prompt_target\target\test_http_api_target.py tests\unit\prompt_target\target\test_http_target_parsing.py tests\unit\prompt_target\target\test_mcp_tool_provider.py

Production build: passed, using the existing PYRIT_PYTHON override because bare python was not available on the local shell's PATH:

$python = uv run --no-sync python -c "import sys; print(sys.executable)"
$env:PYRIT_PYTHON = $python.Trim()
Set-Location frontend
npm run build

Tests/documentation changes: N/A for this dependency-only update. JupyText, the full Python unit suite, Linux/macOS and other Python/Node CI matrix combinations, and live integration/end-to-end tests were not run locally.

Roman Lutz (romanlutz) and others added 2 commits October 3, 2026 08:41
Resolve the 31 current Dependabot alerts with patched Python security floors and targeted lock updates. Patch the additional nanoid advisory found by npm audit, preserving compatible npm majors and platform metadata.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep setuptools available for tests importing build_scripts.build_backend now that JupyterLab no longer provides it transitively. Declare it only in the dev dependency group and retain all locked versions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

@varunj-msft varunj-msft left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm!

@romanlutz
Roman Lutz (romanlutz) added this pull request to the merge queue Oct 5, 2026
Merged via the queue into microsoft:main with commit 7059540 Oct 5, 2026
50 checks passed
@romanlutz
Roman Lutz (romanlutz) deleted the romanlutz-dependency-security-alerts branch October 5, 2026 17:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants