MAINT: Fix dependency alerts - #2981
Merged
Roman Lutz (romanlutz) merged 2 commits intoOct 5, 2026
Merged
Roman Lutz (romanlutz) merged 2 commits into
Roman Lutz (romanlutz) merged 2 commits into
Conversation
Resolve the 31 current Dependabot alerts with patched Python security floors and targeted lock updates. Patch the additional nanoid advisory found by npm audit, preserving compatible npm majors and platform metadata. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep setuptools available for tests importing build_scripts.build_backend now that JupyterLab no longer provides it transitively. Declare it only in the dev dependency group and retain all locked versions. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Roman Lutz (romanlutz)
deleted the
romanlutz-dependency-security-alerts
branch
October 5, 2026 17:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
GitHub reported 31 Dependabot alerts across Python and frontend dependencies. This consolidates their fixes and also patches the additional high-severity nanoid advisory found during
npm audit.Related PRs: #2928 covers part of the PyJWT remediation, and #2924 covers the nested brace-expansion instance. This change includes those upgrades plus the remaining vulnerable versions and instances; neither existing PR was modified.
Python security floors are raised alongside the targeted lock updates. The published PyJWT runtime minimum becomes
2.15.0. The newvirtualenv>=21.7.13entry is only a uv resolution constraint:pre-commitalready brings in virtualenv through[dependency-groups].dev, so this does not add a PyRIT runtime dependency.Notebook 7.6.3 requires JupyterLab 4.6.4. Required companion changes are limited to the filelock upgrade and the jupyter-builder/python-discovery additions. Frontend updates preserve compatible major versions, unrelated package entries, and platform metadata. No application code or CodeQL configuration is changed.
Tests and Documentation
Validation was completed on Windows with Python 3.14.4, uv 0.11.8, and Node 25.7.0. All 31 recorded GitHub vulnerable ranges, plus the additional nanoid range, are excluded from the updated lockfiles.
uv lock --check --no-progress && uv sync --locked --no-progressuv tool run --from uv==0.9.17 uv lock --check --no-progressnpm ci --no-fund --no-auditnpm run lintnpm run type-checknpm run test:coverage -- --runInBandnpm audit --jsongit diff --checkThe npm commands above were run from
frontend.Affected Python authentication, networking, HTTP target, and MCP tests: 256 passed with this command from the repository root:
Production build: passed, using the existing
PYRIT_PYTHONoverride because barepythonwas not available on the local shell's PATH:Tests/documentation changes: N/A for this dependency-only update. JupyText, the full Python unit suite, Linux/macOS and other Python/Node CI matrix combinations, and live integration/end-to-end tests were not run locally.