diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 7f74fc72..d848d27e 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -22,10 +22,17 @@ jobs: - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 with: python-version: "3.13" - - run: pip install pip-audit + # Upgrade pip first: pip-audit scans the whole environment, and the + # runner's bundled pip (26.1.1) carries advisory PYSEC-2026-196 (fixed in + # 26.1.2). Upgrading removes the vulnerable version outright rather than + # suppressing it — and 26.1.2 also resolves CVE-2026-3219 / CVE-2026-6357, + # which is why those two stale --ignore-vuln entries are no longer needed. + - run: | + python -m pip install --upgrade pip + pip install pip-audit - run: pip install -e . - name: Pip audit - run: pip-audit --skip-editable --ignore-vuln CVE-2026-3219 --ignore-vuln CVE-2026-6357 + run: pip-audit --skip-editable codeql: runs-on: ubuntu-latest diff --git a/CHANGELOG.md b/CHANGELOG.md index b35807f2..27482caf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -182,6 +182,16 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format ### Security +- **`dependency-scan` (pip-audit) green again — upgrade pip, drop stale ignores.** + The `Security Scan` workflow's `dependency-scan` job had gone red: pip-audit + scans the whole environment, and the runner's bundled pip (26.1.1) carries + advisory PYSEC-2026-196 (fixed in 26.1.2). The job now runs + `python -m pip install --upgrade pip` before auditing (it was the only CI job + not upgrading pip), removing the vulnerable version outright rather than + suppressing it. 26.1.2 also resolves CVE-2026-3219 and CVE-2026-6357, so the + two now-stale `--ignore-vuln` entries were removed — verified against a clean + reproduction of the job's environment, which audits to "No known + vulnerabilities found" with nothing ignored. - **Pinned the `requests` floor to a non-vulnerable version** — raised `requests` to `>=2.34.2` in `pyproject.toml` and the API branch's `requirements.project.txt` (which previously listed it unconstrained). This