Repository navigation
fix(deps): bump sse-starlette to 3.5.0 and resolve dependency audits - #535
Merged
Merged
Conversation
Bumps the uv-all-updates group with 1 update: [sse-starlette](https://github.com/sysid/sse-starlette). Updates `sse-starlette` from 3.4.11 to 3.5.0 - [Release notes](https://github.com/sysid/sse-starlette/releases) - [Commits](sysid/sse-starlette@v3.4.11...v3.5.0) --- updated-dependencies: - dependency-name: sse-starlette dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: uv-all-updates ... Signed-off-by: dependabot[bot] <support@github.com>
- urllib3: add runtime floor >=2.8.0 for PYSEC-2026-4175/4176/4177 (via requests <- google-api-core <- a2a-sdk) and lock to 2.8.0 - virtualenv: refresh to 21.14.3 for PYSEC-2026-4011/4012/4013/4014 Refs #536
Collaborator
|
在本 PR 分支上追加提交
本地验证: 追踪 issue:#536 |
- parametrize the installed-metadata floor test with urllib3 2.7.0 -> 2.8.0 - list urllib3>=2.8.0 alongside the existing floors in compatibility and guide docs Refs #536
Remove the security-floor and version-range literals that restated what pyproject.toml and uv.lock already declare, in docs/compatibility.md, docs/guide.md, and tests/package/test_dependency_contract.py. Keep the installed-metadata assertion for the sqlalchemy asyncio extra, which expresses a packaging contract rather than a version restatement. Dependency files remain the single source of truth. Refs #536
The guide keeps the rationale for the sqlalchemy[asyncio] extra without restating an upstream release number. Refs #536
Remove descriptions that restated dependency policy handled by pyproject.toml, uv.lock, and CI config: the protobuf range/CI matrix and security-floor rows, the uv.lock lint-source note, the SDK pin/upgrade guidance, the sqlalchemy[asyncio] declaration note, and the pinned-SDK wording. Compatibility promises and adapter review decisions stay intact. Refs #536
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
概述
在 Dependabot 分组更新(
uv-all-updates)的基础上,升级sse-starlette,清除仓库当前全部依赖审计失败(运行时 + 开发依赖),并把依赖信息收敛为“单一来源”:依赖版本与依赖管理策略只存在于依赖/CI 文件(pyproject.toml、uv.lock、workflow 配置),不再重复出现在文档或测试中。变更内容
sse-starlette3.4.11 → 3.5.0(Dependabot 原始改动)。AppStatus.should_exit不再由 uvicorn 状态驱动。本仓库未使用该接口(全仓rg无引用),无需迁移。urllib3>=2.8.0(PYSEC-2026-4175/4176/4177;经requests <- google-api-core <- a2a-sdk进入 runtime)。下限写入 wheel/sdist 元数据,uv tool install等独立安装同样受保护。virtualenv21.7.4 → 21.14.3(PYSEC-2026-4011/4012/4013/4014),同步python-discovery1.5.2 → 1.6.1。tests/package/test_dependency_contract.py:删除重复书写依赖版本字面量的断言。docs/compatibility.md:删除“Protobuf”与“Security floors”行、uv.lock说明句、SDK 固定/升级指引,并把小节标题改为SDK and Adapter Review。docs/guide.md:删除sqlalchemy[asyncio]声明说明与安全下限句,去掉pinned a2a-sdk release表述。提交
5d2640ddeps: bump sse-starlette63b9c94fix(deps): clear runtime and dev dependency auditscb5fab2revert(deps): keep dependency floors in dependency files onlye068f45refactor(deps): drop duplicated dependency versions from docs and testsb33e342docs(deps): drop remaining SQLAlchemy version literal from guide949379ddocs: drop dependency-management details from compatibility and guide关联 issue
Closes #536
该 issue 记录的 pip-audit 失败(urllib3、virtualenv)由本 PR 全部解决;
publish.yml与定时任务dependency-review.yml中的同类审计入口也一并恢复通过。验证
./scripts/doctor.sh通过(pre-commit、mypy、904 项 pytest、覆盖率门禁、构建与 wheel 冒烟)uv run pip-audit --requirement <runtime requirements>→No known vulnerabilities found./scripts/dependency_health.sh→No known vulnerabilities found./scripts/conformance.sh:本次未改动 A2A 传输或契约行为,未运行Validate PRs and Main(5 个 job)兼容性与风险
sse-starlette3.5.0 的行为变更在本仓库代码中未被使用。urllib3直接依赖仅施加版本下限,不改变运行时行为。