Skip to content

SEARCH-3214 : merge origin/main into release/3.x - #406

Merged
sebastientosello merged 12 commits into
finos:release/3.xfrom
sebastientosello:SEARCH-3214
Sep 10, 2026
Merged

sebastientosello merged 12 commits into
finos:release/3.xfrom
sebastientosello:SEARCH-3214

Conversation

@sebastientosello

Copy link
Copy Markdown
Contributor

second attempt at #405

catalinsymphony and others added 11 commits September 3, 2025 16:23
* Fix datahose implementation: use datahose api in datahose loop replacing the datafeed api
* Update packages for snyk

* Allow more types of licenses

* Upgrade packages flagged by safety check

* Add flag to skip checking dev deps

* Version increase
* Add MAINTAINERS.md file

Signed-off-by: Juan Estrella <juan.estrella@finos.org>

* Make maintainer email optional

Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.

Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>

* Update MAINTAINERS.md

* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings

Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.

* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings

Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.

* Add BSD-3-Clause to authorized licenses for liccheck

idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.

---------

Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
* Add AI agent example wiring LangGraph + Vertex AI Gemini into a Symphony bot

Mirrors the Java BDK's bdk-ai-agent-example: any message addressed to the bot
is forwarded to a LangGraph ReAct agent backed by Gemini, with BDK-backed
tools for user lookup, room member listing, and sending messages.

* Add opsx commands and openspec skills used to author the AI agent example

* Pin GitHub Actions to commit SHAs and address CVE/license findings

Harden workflows against supply-chain tag mutation by pinning actions to
SHAs, bump cryptography to >=48.0.1 for a CVE fix, allow BSD-3-Clause
license, and add a documented safety-policy exception for CVE 96886
(fix requires urllib3 2.7.0 which drops Python 3.9 support).

* Pin upload-artifact SHA, fix aiohttp CVE coverage for PR checks

Semgrep flagged mutable actions/upload-artifact@v4 tag; safety flagged
aiohttp 3.13.5 CVEs because cve-scanning-python.yml was missing the -i
ignore flags already present in security.yml for py3.9-only findings.
… a patch release. (finos#397)

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via finos#390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Raise cryptography ceiling to allow the patched 50.x

The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:

  48.0.1  CVE-2026-69247 and CVE-2026-69249
  49.0.0  CVE-2026-69247
  50.0.x  clean

Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.

This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.

Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.

  cryptography 48.0.1  560 passed, 3 skipped
  cryptography 50.0.0  560 passed, 3 skipped
  cryptography 50.0.1  560 passed, 3 skipped   (the locked version)

poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.

* Bump version to 2.11.4 to prepare a patch release

Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.

The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.

Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
# Conflicts:
#	.github/workflows/cve-scanning-python.yml
#	.github/workflows/security.yml
#	.safety-policy.yml
#	poetry.lock
#	pyproject.toml
@sebastientosello
sebastientosello changed the base branch from main to release/3.x September 10, 2026 13:11
- Reformat examples/services/messages.py (ruff format) and drop an
  unused import (ruff check), both pre-existing on release/3.x.
- Drop the SFTY-* string vulnerability IDs from .safety-policy.yml:
  the installed safety version (2.3.5) only accepts integer IDs under
  ignore-vulnerabilities and fails to load the whole policy file
  otherwise. They're already ignored via -i flags in the CI workflows.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sebastientosello
sebastientosello merged commit 94efa8b into finos:release/3.x Sep 10, 2026
18 checks passed
@sebastientosello
sebastientosello deleted the SEARCH-3214 branch September 10, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants