Skip to content

[0.9.8-bp] sec alerts aiohttp cryptography - #6838

Merged
masenf merged 4 commits into
r/pre-2026.08.03from
claude/sec-alerts-aiohttp-cryptography-ypb8ve
Aug 4, 2026
Merged

[0.9.8-bp] sec alerts aiohttp cryptography#6838
masenf merged 4 commits into
r/pre-2026.08.03from
claude/sec-alerts-aiohttp-cryptography-ypb8ve

Conversation

@masenf

@masenf masenf commented Aug 4, 2026

Copy link
Copy Markdown
Collaborator

backport for pre-release 0.9.8

Review in cubic

masenf and others added 4 commits August 3, 2026 17:11
Dependabot flagged two transitive dependencies in uv.lock:

  aiohttp       3.14.1 -> 3.14.3  (GHSA-cq5v-8q36-5273 / CVE-2026-69244)
  cryptography  49.0.0 -> 50.0.0  (GHSA-g6cj-pr64-35w5 / CVE-2026-69247)

Both reach the lock only through the docs app: reflex-enterprise pulls
asgiproxy (-> aiohttp) and joserfc (-> cryptography). Neither is a
dependency of the published reflex package, so this is a lockfile-only
fix with no impact on installs of reflex itself.

aiohttp 3.14.3 published outside the 7 day exclude-newer window and
resolves on its own. cryptography 50.0.0 published inside it, so add an
exclude-newer exemption alongside the existing starlette one. Since
cryptography is transitive there is no version floor to pin, and the
exemption keeps future security releases resolvable immediately rather
than aging out of the window first.

Verified the patched versions against their consumers: joserfc 1.7.1
round-trips a JWT on cryptography 50.0.0, and asgiproxy 0.2.0 imports
cleanly on aiohttp 3.14.3.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ULSRWe743saVEBbvBxuL9D
`chore` is not a configured towncrier type in pyproject.toml (the types
are breaking, deprecation, feature, bugfix, performance, docs, misc), so
`_has_pending_fragments()` in scripts/release.py skipped these files and
they would never have reached a CHANGELOG:

  news/6836.chore.md                      -> news/6836.misc.md
  news/+sec-aiohttp-cryptography.chore.md -> news/+sec-aiohttp-cryptography.misc.md

Both now render under the Miscellaneous heading, verified with
`towncrier build --draft`.

Also expand the dependency-bump entry: the aiohttp 3.14.1 -> 3.14.3 jump
clears CVE-2026-59881 and CVE-2026-69243 (both fixed in 3.14.2) in
addition to the reported CVE-2026-69244, and the entry now notes these
are docs-app transitive dependencies rather than shipped ones.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ULSRWe743saVEBbvBxuL9D
Replaces the `+`-prefixed placeholder now that the PR number is known, so
the changelog entry links back to the pull request.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ULSRWe743saVEBbvBxuL9D
@masenf
masenf requested a review from a team as a code owner August 4, 2026 05:18
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@masenf
masenf merged commit c973417 into r/pre-2026.08.03 Aug 4, 2026
110 checks passed
@greptile-apps

greptile-apps Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

The PR updates locked development and documentation dependencies to versions containing security fixes and exempts transitive cryptography releases from the repository’s seven-day resolver delay.

  • Upgrades aiohttp from 3.14.1 to 3.14.3.
  • Upgrades cryptography from 49.0.0 to 50.0.0.
  • Upgrades Pillow from 12.2.0 to 12.3.0.
  • Adds matching miscellaneous release notes.

Confidence Score: 5/5

The PR appears safe to merge, with the dependency updates matching the documented scope and supported environments.

The updated lockfile retains compatible artifacts for supported Python versions, the transitive dependency chains match the release notes, and no concrete installation, runtime, or security regression remains.

Important Files Changed

Filename Overview
pyproject.toml Adds a documented cryptography exception to the existing uv package-age policy, following the established security-update pattern.
uv.lock Regenerates lock metadata and artifacts for the three security-related dependency upgrades without an identified compatibility regression.
news/6836.misc.md Accurately records the locked Pillow development dependency update.
news/6837.misc.md Accurately records the aiohttp and cryptography updates and their docs-only transitive dependency scope.

Reviews (1): Last reviewed commit: "Name the dependency-bump news fragment a..." | Re-trigger Greptile

@codspeed-hq

codspeed-hq Bot commented Aug 4, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 26 untouched benchmarks
⏩ 8 skipped benchmarks1


Comparing claude/sec-alerts-aiohttp-cryptography-ypb8ve (1c95997) with main (a348aea)2

Open in CodSpeed

Footnotes

  1. 8 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

  2. No successful run was found on r/pre-2026.08.03 (8ee317a) during the generation of this report, so main (a348aea) was used instead as the comparison base. There might be some changes unrelated to this pull request in this report.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants