From ee78c39e801cc0de459d5356078def8a2ce651af Mon Sep 17 00:00:00 2001 From: AIOSAI Date: Wed, 3 Jun 2026 11:34:02 -0700 Subject: [PATCH] security(deps): pin requests>=2.34.2 to clear 6 OSV advisories (DPLAN-0193 step 1) --- CHANGELOG.md | 11 +++++++++++ pyproject.toml | 2 +- src/aipass/api/requirements.project.txt | 2 +- 3 files changed, 13 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 5ea59846..424b3927 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -84,6 +84,17 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format reports each branch's real count (e.g. devpulse now shows its 12 open plans instead of 0). +### Security + +- **Pinned the `requests` floor to a non-vulnerable version** — raised + `requests` to `>=2.34.2` in `pyproject.toml` and the API branch's + `requirements.project.txt` (which previously listed it unconstrained). This + clears six OSV advisories the OpenSSF Scorecard flagged against the dependency + (PYSEC-2014-13, PYSEC-2014-14, PYSEC-2018-28, GHSA-9wx4-h78v-vm56, + GHSA-9hjg-9r4m-mvj7, GHSA-gc5v-m9x4-r6x2) — the oldest surfaced only because the + dependency was declared without a version bound. No runtime change (the AIPass + venv already ran a fixed release). (DPLAN-0193) + --- ## [2026.W22] - 2026-05-30 diff --git a/pyproject.toml b/pyproject.toml index c708d42d..cebd9fe6 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -28,7 +28,7 @@ classifiers = [ dependencies = [ "rich>=13.0", "watchdog>=3.0", - "requests>=2.28", + "requests>=2.34.2", "psutil>=5.9", "questionary>=2.0", ] diff --git a/src/aipass/api/requirements.project.txt b/src/aipass/api/requirements.project.txt index 2cf77723..03fbdbcd 100644 --- a/src/aipass/api/requirements.project.txt +++ b/src/aipass/api/requirements.project.txt @@ -2,7 +2,7 @@ # These are beyond the base AIPass requirements # Install with: pip install -r requirements.project.txt -requests +requests>=2.34.2 rich google-auth google-auth-oauthlib