Fix reported urllib3 and Tornado vulnerabilities - #91
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The attached scan reports urllib3 2.7.0 and Tornado 6.5.8 in Reachy's locked dependency graph. Raise the minimum versions and regenerate
uv.lockso installs use urllib3 2.8.0 and stable Tornado 6.5.10. Only these two package versions change.Tornado's 6.5.9 release fixes the three advisories affecting 6.5.8; 6.5.10 also fixes Jupyter compatibility. This avoids the CSV's suggested 6.6a1 prerelease. urllib3 2.8.0 fixes proxy TLS configuration, deflate streaming, and chunk-size buffering. OSV queries return no advisories for either selected version.
The third CSV finding,
golang.org/x/crypto v0.57.0, is GO-2026-5932: unmaintained OpenPGP packages, all versions affected, no fixed release. The exporter's existing README records this assessment. Recheckedgo list -deps -test ./...: no affected OpenPGP packages in build or test imports.govulncheck ./...reports zero vulnerable imported packages or called symbols; the advisory appears only at module level. No Go change is warranted.Validation:
uv lock --check,ruff check .,python -m compileall -q src tests, andgit diff --checkpass.PYTHONPATHpointing tosrc.go mod verifypasses;govulncheck ./...reports no reachable vulnerabilities.Independent panel review: clean, one round, both reviewers complete; no findings, rejected findings, or follow-ups.
Frozen review target:
main fcb7a2d78aff8852b08a8f6c3693a3baf8321834tojohnny/fix-reported-dependency-vulnerabilities d8c25ea09ed7b024f6117b12341efb060fe35614. Reproduce with:This two-reviewer panel covers the relevant risks of a minimal dependency maintenance change. Documentation assessment covers the manifest comments, PR triage and existing exporter README. UI/user experience, public API, data/migrations, and performance/concurrency reviews are skipped because those surfaces do not change. No platform redesign or unrelated dependency updates are included. Complete macOS installation/tests/type checking and robot runtime remain unverified as described above.
All GitHub checks passed for the reviewed head.