Skip to content

Fix reported urllib3 and Tornado vulnerabilities - #91

Merged
johnnygreco merged 1 commit into
mainfrom
johnny/fix-reported-dependency-vulnerabilities
Oct 6, 2026
Merged

johnnygreco merged 1 commit into
mainfrom
johnny/fix-reported-dependency-vulnerabilities

Conversation

@johnnygreco

@johnnygreco johnnygreco commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

The attached scan reports urllib3 2.7.0 and Tornado 6.5.8 in Reachy's locked dependency graph. Raise the minimum versions and regenerate uv.lock so installs use urllib3 2.8.0 and stable Tornado 6.5.10. Only these two package versions change.

Tornado's 6.5.9 release fixes the three advisories affecting 6.5.8; 6.5.10 also fixes Jupyter compatibility. This avoids the CSV's suggested 6.6a1 prerelease. urllib3 2.8.0 fixes proxy TLS configuration, deflate streaming, and chunk-size buffering. OSV queries return no advisories for either selected version.

The third CSV finding, golang.org/x/crypto v0.57.0, is GO-2026-5932: unmaintained OpenPGP packages, all versions affected, no fixed release. The exporter's existing README records this assessment. Rechecked go list -deps -test ./...: no affected OpenPGP packages in build or test imports. govulncheck ./... reports zero vulnerable imported packages or called symbols; the advisory appears only at module level. No Go change is warranted.

Validation:

  • uv lock --check, ruff check ., python -m compileall -q src tests, and git diff --check pass.
  • Reachy REST transport, camera policy, configuration, package, and sandbox-control suites: 42 passed, using an isolated Python 3.12 uv environment with the patched packages and PYTHONPATH pointing to src.
  • Dependency license audit passes for both upgraded packages (Apache-2.0 and MIT; no unresolved changed dependencies).
  • go mod verify passes; govulncheck ./... reports no reachable vulnerabilities.
  • Full Reachy sync/test/type validation cannot complete on this Linux host: the committed lockfile supports Darwin only. Isolated full-suite collection and type checking encounter missing macOS runtime dependencies. No platform configuration changes are included.

Independent panel review: clean, one round, both reviewers complete; no findings, rejected findings, or follow-ups.

Frozen review target: main fcb7a2d78aff8852b08a8f6c3693a3baf8321834 to johnny/fix-reported-dependency-vulnerabilities d8c25ea09ed7b024f6117b12341efb060fe35614. Reproduce with:

git diff fcb7a2d78aff8852b08a8f6c3693a3baf8321834 d8c25ea09ed7b024f6117b12341efb060fe35614
  • Security/dependency supply-chain reviewer: clean. Independently verified upstream advisory fixes, zero OSV findings for selected versions, and all five locked artifacts against non-yanked PyPI URLs/hashes/sizes. Confirmed no affected OpenPGP packages in Linux AMD64, Linux ARM64, or Darwin ARM64 build/test dependency graphs; fresh govulncheck found no vulnerable imports or calls.
  • Correctness/integration/tests/maintainability reviewer: clean. Independently checked manifest/lock consistency, only two changed package versions, Python compatibility and installation paths, offline lock validation, and reran the 42 selected tests successfully.

This two-reviewer panel covers the relevant risks of a minimal dependency maintenance change. Documentation assessment covers the manifest comments, PR triage and existing exporter README. UI/user experience, public API, data/migrations, and performance/concurrency reviews are skipped because those surfaces do not change. No platform redesign or unrelated dependency updates are included. Complete macOS installation/tests/type checking and robot runtime remain unverified as described above.

All GitHub checks passed for the reviewed head.

@johnnygreco
johnnygreco merged commit cb153d6 into main Oct 6, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant