fix(deps): patch 31 known CVEs across Python and npm lockfiles
OSV weekly scan reported 50 known vulnerabilities in pinned deps. This bumps everything with a released, semver-compatible fix: Python (uv.lock): - aiohttp 3.14.1 -> 3.14.3 (GHSA-cq5v-8q36-5273, GHSA-mfx4-hv73-q22v, GHSA-mq44-7p77-q5h7) - h2 4.3.0 -> 4.4.1 (CVE-2026-71554 request smuggling; exclude-newer exception documented in pyproject, remove after 2026-08-17) npm (root workspace): - brace-expansion 5.0.8 -> 5.0.9, undici 6.27->6.28 / 7.28->7.29, js-yaml 4.3.1, nanoid 3.3.17/3.3.18, ip-address 10.4.0, mermaid 11.16.1 + dompurify 3.4.13 (root overrides so the streamdown transitive copy is pinned too) - electron 40.10.2 -> 40.10.6 (GHSA-r4w5-6pfg-jxp5; the 41.x major for GHSA-9f4c-93c8-jc8g is deferred to its own PR) npm (website): mermaid, dompurify, js-yaml, nanoid, fast-uri 3.1.5, postcss 8.5.23, undici 7.29.0 npm (photon sidecar): @opentelemetry/core 2.8.0 via override, undici npm (whatsapp-bridge): body-parser 1.20.6 min-release-age excludes added to .npmrc/website/.npmrc for the sub-2wk CVE-fix releases, each with a removal date. Remaining findings are blocked upstream: cryptography <49 cap (alibabacloud-tea-openapi), image-size (no fixed release), tar 6.x transitive majors, electron 41. Local rescan: 50 -> 19 known vulns, 0 introduced.
This commit is contained in:
+9
-7
@@ -173,10 +173,10 @@ daytona = ["daytona==0.155.0"]
|
||||
vercel = ["vercel==0.7.2"]
|
||||
hindsight = ["hindsight-client==0.6.1"]
|
||||
dev = ["debugpy==1.8.20", "pytest==9.1.1", "pytest-asyncio==1.3.0", "mcp==1.28.1", "starlette==1.3.1", "ty==0.0.21", "ruff==0.15.10", "setuptools==83.0.0"] # starlette: CVE-2026-48710; setuptools: 83 (torch >=2.13 requires setuptools 83)
|
||||
messaging = ["python-telegram-bot[webhooks]==22.6", "discord.py[voice]==2.7.1", "aiohttp==3.14.1", "brotlicffi==1.2.0.1", "slack-bolt==1.29.0", "slack-sdk==3.43.0", "qrcode==7.4.2"] # aiohttp 3.14.1: CVE-2026-34513/34518/34519/34520/34525 + 34993(RCE)/47265
|
||||
messaging = ["python-telegram-bot[webhooks]==22.6", "discord.py[voice]==2.7.1", "aiohttp==3.14.3", "brotlicffi==1.2.0.1", "slack-bolt==1.29.0", "slack-sdk==3.43.0", "qrcode==7.4.2"] # aiohttp 3.14.3: prior CVEs + GHSA-cq5v-8q36-5273/GHSA-mfx4-hv73-q22v/GHSA-mq44-7p77-q5h7
|
||||
cron = [] # croniter is now a core dependency; this extra kept for back-compat
|
||||
slack = ["slack-bolt==1.29.0", "slack-sdk==3.43.0", "aiohttp==3.14.1"]
|
||||
matrix = ["mautrix[encryption]==0.21.0", "aiosqlite==0.22.1", "asyncpg==0.31.0", "aiohttp-socks==0.11.0", "aiohttp==3.14.1"] # aiohttp 3.14.1: CVE-2026-34993(RCE)/47265 + 34513/34518/34519/34520/34525 (mautrix/aiohttp-socks only cap aiohttp<4 / >=3.10, so pin the patched floor directly)
|
||||
slack = ["slack-bolt==1.29.0", "slack-sdk==3.43.0", "aiohttp==3.14.3"]
|
||||
matrix = ["mautrix[encryption]==0.21.0", "aiosqlite==0.22.1", "asyncpg==0.31.0", "aiohttp-socks==0.11.0", "aiohttp==3.14.3"] # aiohttp 3.14.3: prior CVEs + GHSA-cq5v-8q36-5273/GHSA-mfx4-hv73-q22v/GHSA-mq44-7p77-q5h7 (mautrix/aiohttp-socks only cap aiohttp<4 / >=3.10, so pin the patched floor directly)
|
||||
# WeCom callback-mode adapter — parses untrusted XML POST bodies from
|
||||
# WeCom-controlled callback endpoints, so we use defusedxml (drop-in
|
||||
# replacement for stdlib xml.etree.ElementTree) to block billion-laughs
|
||||
@@ -241,9 +241,9 @@ mcp = ["mcp==1.28.1", "starlette==1.3.1"] # starlette: CVE-2026-48710
|
||||
# Backwards-compatible no-op alias. Relay is a core dependency on supported
|
||||
# wheel targets and intentionally unavailable on other platforms.
|
||||
nemo-relay = []
|
||||
homeassistant = ["aiohttp==3.14.1"]
|
||||
sms = ["aiohttp==3.14.1"]
|
||||
teams = ["microsoft-teams-apps==2.0.13.4", "aiohttp==3.14.1"] # aiohttp 3.14.1: CVE-2026-34993(RCE)/47265 + 34513/34518/34519/34520/34525
|
||||
homeassistant = ["aiohttp==3.14.3"]
|
||||
sms = ["aiohttp==3.14.3"]
|
||||
teams = ["microsoft-teams-apps==2.0.13.4", "aiohttp==3.14.3"] # aiohttp 3.14.3: prior CVEs + GHSA-cq5v-8q36-5273/GHSA-mfx4-hv73-q22v/GHSA-mq44-7p77-q5h7
|
||||
# Computer use — macOS background desktop control via cua-driver (MCP stdio).
|
||||
# The cua-driver binary itself is installed via `hermes tools` post-setup
|
||||
# (curl install script); this extra just pins the MCP client used to talk
|
||||
@@ -369,7 +369,9 @@ override-dependencies = [
|
||||
"pynacl>=1.6,<1.7",
|
||||
]
|
||||
exclude-newer = "14 days"
|
||||
exclude-newer-package = { vercel = false, nemo-relay = false, huggingface_hub = false }
|
||||
# h2: temporary exclude-newer exception for the CVE-2026-71554 (GHSA-6hr6-w5qg-qmwg,
|
||||
# request-smuggling) fix in 4.4.1, published 2026-08-03. Remove after 2026-08-17.
|
||||
exclude-newer-package = { vercel = false, nemo-relay = false, huggingface_hub = false, h2 = false }
|
||||
|
||||
[tool.setuptools]
|
||||
# Top-level single-file modules (not packages). Without this, uv2nix's
|
||||
|
||||
Reference in New Issue
Block a user