Skip to content

fix(deps): bump sse-starlette to 3.5.0 and resolve dependency audits - #535

Merged
liujuanjuan1984 merged 7 commits into
mainfrom
dependabot/uv/uv-all-updates-a7757bd5ea
Oct 2, 2026
Merged

liujuanjuan1984 merged 7 commits into
mainfrom
dependabot/uv/uv-all-updates-a7757bd5ea

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

概述

在 Dependabot 分组更新(uv-all-updates)的基础上,升级 sse-starlette,清除仓库当前全部依赖审计失败(运行时 + 开发依赖),并把依赖信息收敛为“单一来源”:依赖版本与依赖管理策略只存在于依赖/CI 文件(pyproject.toml、uv.lock、workflow 配置),不再重复出现在文档或测试中。

变更内容

  1. 运行时依赖升级:sse-starlette 3.4.11 → 3.5.0(Dependabot 原始改动)。
    • 上游修复:进程内已停止的 uvicorn 服务器不会再取消后续服务器的 SSE 流(回归自 3.1.1)。
    • 行为变更:AppStatus.should_exit 不再由 uvicorn 状态驱动。本仓库未使用该接口(全仓 rg 无引用),无需迁移。
  2. 运行时安全下限:新增 urllib3>=2.8.0(PYSEC-2026-4175/4176/4177;经 requests <- google-api-core <- a2a-sdk 进入 runtime)。下限写入 wheel/sdist 元数据,uv tool install 等独立安装同样受保护。
  3. 开发工具链刷新:virtualenv 21.7.4 → 21.14.3(PYSEC-2026-4011/4012/4013/4014),同步 python-discovery 1.5.2 → 1.6.1。
  4. 消除文档/测试中的依赖信息冗余
    • tests/package/test_dependency_contract.py:删除重复书写依赖版本字面量的断言。
    • docs/compatibility.md:删除“Protobuf”与“Security floors”行、uv.lock 说明句、SDK 固定/升级指引,并把小节标题改为 SDK and Adapter Review。
    • docs/guide.md:删除 sqlalchemy[asyncio] 声明说明与安全下限句,去掉 pinned a2a-sdk release 表述。
    • 保留内容:兼容性承诺(Python/A2A 协议/OpenCode/SDK 线)与适配层评审结论。

提交

  • 5d2640d deps: bump sse-starlette
  • 63b9c94 fix(deps): clear runtime and dev dependency audits
  • cb5fab2 revert(deps): keep dependency floors in dependency files only
  • e068f45 refactor(deps): drop duplicated dependency versions from docs and tests
  • b33e342 docs(deps): drop remaining SQLAlchemy version literal from guide
  • 949379d docs: drop dependency-management details from compatibility and guide

关联 issue

Closes #536

该 issue 记录的 pip-audit 失败(urllib3、virtualenv)由本 PR 全部解决;publish.yml 与定时任务 dependency-review.yml 中的同类审计入口也一并恢复通过。

验证

  • ./scripts/doctor.sh 通过(pre-commit、mypy、904 项 pytest、覆盖率门禁、构建与 wheel 冒烟)
  • 运行时审计 uv run pip-audit --requirement <runtime requirements> → No known vulnerabilities found
  • 开发依赖审计 ./scripts/dependency_health.sh → No known vulnerabilities found
  • ./scripts/conformance.sh:本次未改动 A2A 传输或契约行为,未运行
  • CI:推送后触发 Validate PRs and Main(5 个 job)

兼容性与风险

  • 无协议、SDK 版本或部署边界变化;sse-starlette 3.5.0 的行为变更在本仓库代码中未被使用。
  • 新增 urllib3 直接依赖仅施加版本下限,不改变运行时行为。
  • 文档清理只删除重复的依赖管理描述与版本字面量,兼容性承诺与适配层结论保持不变;测试仅删除重复版本断言,打包行为仍由构建与 wheel 冒烟覆盖。
  • 流程说明:已直接推送到 Dependabot 分支,因此 Dependabot 不再自动 rebase/维护该 PR。

Bumps the uv-all-updates group with 1 update: [sse-starlette](https://github.com/sysid/sse-starlette).


Updates `sse-starlette` from 3.4.11 to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.11...v3.5.0)

---
updated-dependencies:
- dependency-name: sse-starlette
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-all-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
- urllib3: add runtime floor >=2.8.0 for PYSEC-2026-4175/4176/4177 (via requests <- google-api-core <- a2a-sdk) and lock to 2.8.0
- virtualenv: refresh to 21.14.3 for PYSEC-2026-4011/4012/4013/4014

Refs #536
@liujuanjuan1984

Copy link
Copy Markdown
Collaborator

在本 PR 分支上追加提交 fix(deps): clear runtime and dev dependency audits,修复原 Validate Default Toolchain 的 pip-audit 失败:

  • 新增运行期安全下限 urllib3>=2.8.0,并 uv lock 至 2.8.0(PYSEC-2026-4175/4176/4177)。
  • 刷新 dev 工具链 virtualenv 至 21.14.3(PYSEC-2026-4011/4012/4013/4014)。

本地验证:./scripts/doctor.sh 通过;runtime 与 dev 的 pip-audit 均报告 No known vulnerabilities found。

追踪 issue:#536

- parametrize the installed-metadata floor test with urllib3 2.7.0 -> 2.8.0
- list urllib3>=2.8.0 alongside the existing floors in compatibility and guide docs

Refs #536
@liujuanjuan1984 liujuanjuan1984 changed the title deps: bump sse-starlette from 3.4.11 to 3.5.0 in the uv-all-updates group fix(deps): bump sse-starlette to 3.5.0 and resolve dependency audits Oct 2, 2026
The urllib3 security floor is declared in pyproject.toml and locked in uv.lock, which stay the single source of truth for dependency management. Revert the duplicated mention added in 2f706e3 so docs and dependency-contract tests remain identical to main.

Refs #536
Remove the security-floor and version-range literals that restated what pyproject.toml and uv.lock already declare, in docs/compatibility.md, docs/guide.md, and tests/package/test_dependency_contract.py. Keep the installed-metadata assertion for the sqlalchemy asyncio extra, which expresses a packaging contract rather than a version restatement. Dependency files remain the single source of truth.

Refs #536
The guide keeps the rationale for the sqlalchemy[asyncio] extra without restating an upstream release number.

Refs #536
Remove descriptions that restated dependency policy handled by pyproject.toml, uv.lock, and CI config: the protobuf range/CI matrix and security-floor rows, the uv.lock lint-source note, the SDK pin/upgrade guidance, the sqlalchemy[asyncio] declaration note, and the pinned-SDK wording. Compatibility promises and adapter review decisions stay intact.

Refs #536
@liujuanjuan1984
liujuanjuan1984 merged commit dc8e629 into main Oct 2, 2026
5 checks passed
@liujuanjuan1984
liujuanjuan1984 deleted the dependabot/uv/uv-all-updates-a7757bd5ea branch October 2, 2026 03:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[chore] 修复依赖审计失败:urllib3 2.7.0 与 virtualenv 21.7.4 存在已知漏洞

1 participant