mirror of
https://github.com/DeusData/codebase-memory-mcp.git
synced 2026-10-02 04:54:47 +08:00
urllib3 2.7.0, pinned in pkg/pypi/requirements-publish.txt for the PyPI publish step, is affected by three advisories published on 2026-09-30, all fixed in 2.8.0: - GHSA-8988-9cw3-xx77 (high): HTTPS proxy TLS configuration may be ignored or overridden - GHSA-vxq7-64xx-v4gw (high): unbounded chunk-size line buffering in HTTPResponse.stream() / read_chunked() - GHSA-gh4c-6fx4-qh6g (medium): chunked deflate streaming can loop forever OSSF Scorecard reports them as code-scanning alert #33 (VulnerabilitiesID), which the CodeQL gate counts as an open alert, so every PR's gate is blocked until the pin moves. Only urllib3 changes. The file was regenerated with the documented recipe (pip-compile 7.5.1 on a linux/amd64 python:3.12 image) in upgrade-only mode (--upgrade-package urllib3==2.8.0), so every other pin and hash is byte-identical. Both new hashes match PyPI's published digests for urllib3-2.8.0-py3-none-any.whl and urllib3-2.8.0.tar.gz. Proof: `pip install --require-hashes --no-deps -r requirements-publish.txt` on linux/amd64 python:3.12 installs the full set with every hash verified, imports urllib3 2.8.0, twine and build, and `pip check` reports no broken requirements. Signed-off-by: Martin Vogel <martin.vogel.tech@gmail.com>