fix(deps): bump high/critical transitive deps to resolve Dependabot alerts - #1070
Conversation
…uf, pyasn1, python-multipart, urllib3) Co-Authored-By: AJ Steers <aj@airbyte.io>
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
👋 Greetings, Airbyte Team Member!Here are some helpful tips and reminders for your convenience. 💡 Show Tips and TricksTesting This PyAirbyte VersionYou can test this version of PyAirbyte using the following: # Run PyAirbyte CLI from this branch:
uvx --from 'git+https://github.com/airbytehq/PyAirbyte.git@devin/1783461851-security-high-critical-transitive' pyairbyte --help
# Install PyAirbyte from this branch for development:
pip install 'git+https://github.com/airbytehq/PyAirbyte.git@devin/1783461851-security-high-critical-transitive'PR Slash CommandsAirbyte Maintainers can execute the following slash commands on your PR:
📚 Show Repo GuidanceHelpful ResourcesCommunity SupportQuestions? Join the #pyairbyte channel in our Slack workspace. |
Code Coverage OverviewLanguages: Python Python / code-coverage/pytest-fastThe overall coverage in the Show a code coverage summary of the most impacted files.
Python / code-coverage/pytest-no-credsThe overall coverage in the Show a code coverage summary of the most impacted files.
Python / code-coverage/pytestThe overall coverage in the Show a code coverage summary of the most impacted files.
Updated |
Summary
Regenerates
uv.lockto bump six HIGH/CRITICAL transitive dependencies flagged by Dependabot, grouped into a single PR (per AJ Steers' request). Nopyproject.tomlchange — all are transitive, resolved byuv lock --upgrade-package.segment-analytics-python2.3.5 → 2.3.6 came along incidentally as a compatible transitive resolution.Resolves 13 HIGH/CRITICAL transitive alerts (1 critical, 12 high). All bumps stay within the same major version (no breaking changes). Verified locally:
uv sync --group devresolves and the package + upgraded deps import cleanly.Not included (blocked / separate)
airbyte-cdk==7.21.1(nltk==3.9.1); needs anairbyte-python-cdkchange first (some nltk advisories also have no upstream fix yet).cryptography>=46; will go with the directcryptographybump.pydantic-ai; reaching a patched slim requires a breakingpydantic-ai1.x→2.x bump.Tracking issue: https://github.com/airbytehq/airbyte-internal-issues/issues/16721
Requested by AJ Steers (Aaron ("AJ") Steers (@aaronsteers)).
Link to Devin session: https://app.devin.ai/sessions/02a00648c5114ea2b824fad2d57bc5cd