Skip to content

[SYNPY-1928] Fixed security issues by updating packages - #1466

Merged
andrewelamb merged 1 commit into
developfrom
SYNPY-1928
Oct 2, 2026
Merged

andrewelamb merged 1 commit into
developfrom
SYNPY-1928

Conversation

@andrewelamb

@andrewelamb andrewelamb commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Problem:

  • Dependabot has 8 open security alerts on Pipfile.lock:
# Severity Package Issue Fixed in
65 High virtualenv The bash and fish activation scripts run commands that are embedded in paths 21.7.13
64 High virtualenv Command injection through --prompt in activate.bat 21.7.12
63 High virtualenv Downloaded seed wheels (pip and setuptools) do not get an integrity check 21.7.12
62 Medium virtualenv Prompt values go into pyvenv.cfg without sanitization (config injection) 21.7.11
60 High urllib3 stream() and read_chunked() keep an unbounded chunk-size line in memory 2.8.0
59 High urllib3 The HTTPS proxy TLS configuration can be ignored or overridden 2.8.0
61 Medium urllib3 Chunked Deflate streaming can go into an infinite loop 2.8.0
49 Low paramiko rsakey.py permits SHA-1 (GHSA-r374-rxx8-8654, CVE-2026-44405) 5.0.0
  • urllib3 is a runtime dependency (install_requires in setup.cfg). The lower bound was urllib3>=2.6.3, so users can install a vulnerable version. Pipfile.lock pinned 2.7.0.
  • virtualenv is a transitive dependency of pre-commit (dev extra). It is only in the develop section of Pipfile.lock, so it does not go to users. Only dev machines are affected.
  • paramiko comes from the optional pysftp extra (paramiko<4.0.0). The advisory says all versions up to 4.0.0 are affected.

Solution:

  • setup.cfg: changed urllib3>=2.6.3 to urllib3>=2.8.0. Users cannot install a vulnerable urllib3 version with the client now.
  • Pipfile.lock: regenerated with pipenv lock --python /usr/bin/python3.12 (pipenv 2023.12.1). requires.python_version is still 3.12.6.
Package Before After Alerts closed
urllib3 (default and develop) 2.7.0 2.8.0 #59, #60, #61
virtualenv (develop) 21.7.4 21.14.4 #62, #63, #64, #65
paramiko (develop) 3.5.1 3.5.1 #49 stays open
  • The full regeneration also changed other packages: 23 in default and 44 in develop. Most are patch or minor updates (for example, OpenTelemetry 1.44 → 1.45, boto3 1.43.69 → 1.43.107). These packages are new or have a major-version change:
    • filelock 3.32.2 → 4.0.9 (develop)
    • pymdown-extensions 11.0.1 → 12.1 (develop, docs build)
    • New: opentelemetry-exporter-http-transport and opentelemetry-exporter-otlp-common (transitive dependencies of OpenTelemetry 1.45)

Why paramiko alert #49 is not fixed in this PR

  • pysftp 0.2.9 does from paramiko import AgentKey, RSAKey, DSSKey at module level. paramiko 4.0.0 removed DSSKey, and 5.0.0 does not have it either. With paramiko 4.x or later, import pysftp fails with ImportError, and all SFTP operations fail. This is why the paramiko<4.0.0 pin was added (commit 05f82df5).
  • pysftp was last released in 2016 and is not maintained.
  • The risk is low. An attack needs a SHA-1 collision (high compute cost) and an attacker on the SSH connection.
  • Will be fixed in SYNPY-1643

@andrewelamb
andrewelamb requested a review from a team as a code owner October 2, 2026 16:27
@andrewelamb andrewelamb changed the title fixed security issues by updating packages [SYNPY-1928] Fixed security issues by updating packages Oct 2, 2026
@andrewelamb
andrewelamb merged commit e5f3fa2 into develop Oct 2, 2026
19 of 20 checks passed
@andrewelamb
andrewelamb deleted the SYNPY-1928 branch October 2, 2026 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants