Skip to content

[Aikido] Pin Poetry and poetry-core versions to mitigate supply-chain vulnerability - #741

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137918523-6vwg
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137918523-6vwg

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a supply-chain vulnerability by pinning Poetry to version 1.8.5 and poetry-core to version 1.9.1, eliminating the risk of unintended version upgrades that could introduce malicious or compromised code. The fixes were applied across all release workflows (.github/workflows/publish.yml and test-publish.yml), the shared Makefile, the sample-apps/lambda-mongo/Makefile, and the pyproject.toml build system configuration. By explicitly specifying exact versions rather than using flexible version constraints, the build and deployment processes are now protected against supply-chain attacks targeting the Poetry toolchain.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811707778
HIGH
This is an in-scope CI supply-chain vulnerability. publish.yml runs pip install poetry and then make build, whose build target invokes poetry build before the pinned PyPI publishing action uploads the resulting distributions. A malicious or compromised Poetry release can therefore execute as part of the build and rewrite the workspace or distribution that is subsequently published to consumers. test-publish.yml and the shared Makefile retain independently reachable unpinned installations, while pyproject.toml also permits mutable PEP 517 resolution through poetry-core>=1.0.0. The pinned publication action and disabled checkout credentials reduce some ancillary risk but do not protect artifact integrity from a compromised build tool.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant