Skip to content

deps(semgrep): PyJWT 2.15.1 (override) + urllib3 2.8.0 (2/2, merge after 1/2) - #401

Open
Chris-Wolfgang wants to merge 4 commits into
mainfrom
deps/semgrep-pyjwt-override
Open

Chris-Wolfgang wants to merge 4 commits into
mainfrom
deps/semgrep-pyjwt-override

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

2 of 2. Merge after #400 (semgrep.yaml installs with --no-deps). If this lands first, pip re-applies semgrep's pyjwt~=2.13.0 pin and refuses the new tree, and the Semgrep job fails on main until 1/2 merges.

What it fixes

Package Was Now Advisories
PyJWT 2.13.0 2.15.1 12, including GHSA-ffc3-869f-jxw9 (critical), five high, and GHSA-42vr-xj54-vc7v (≤ 2.14.0)
urllib3 2.7.0 (where older) 2.8.0 GHSA-8988-9cw3-xx77, -vxq7-64xx-v4gw (high); -gh4c-6fx4-qh6g

Changes

  • semgrep-overrides.txt (new): pyjwt[crypto]~=2.15.0, passed to uv pip compile --override. semgrep.txt's header records the command. Semgrep imports jwt only in its MCP server, never in semgrep scan. Delete the override once a semgrep release allows PyJWT 2.15.
  • semgrep.txt recompiled with uv 0.12.21: PyJWT 2.15.1 and urllib3 2.8.0, with every other pin kept. The newer uv also adds environment markers (cffi, pycparser, uvicorn) and a Windows-only pywin32 entry. None apply on the Linux runner.

Verified locally

This exact lockfile was installed with pip install --no-deps --require-hashes in a fresh venv: it gives PyJWT 2.15.1 and urllib3 2.8.0 on this repo's semgrep version. As a smoke test of the install, the workflow's scan (p/csharp, p/security-audit, p/secrets) then ran against DbContextBuilder's source and completed: 167 rules on 662 files, 0 findings. This repo's own scan runs on main after merge. The identical change is running green on Chris-Wolfgang/DbContextBuilder main.

⚠️ This PR's Semgrep job fails until 1/2 merges. That's expected. This repo's semgrep.yaml installs the PR's own lockfile, and without 1/2's --no-deps pip refuses the override (semgrep 1.177.0 depends on pyjwt~=2.13.0). After merging 1/2, re-run this PR's Semgrep job. It then installs this lockfile with --no-deps and should pass: a real CI test of it. Semgrep is not a required check.

🤖 Generated with Claude Code

Copilot AI balanced review requested due to automatic review settings October 11, 2026 02:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Companion PR #400 remains unmerged, so the current Semgrep workflow rejects this dependency tree.

1 open finding
What changed in this PR

Updates Semgrep’s hash-pinned dependencies to address PyJWT and urllib3 vulnerabilities.

Changes:

  • Overrides PyJWT to 2.15.x.
  • Regenerates the lockfile with PyJWT 2.15.1 and urllib3 2.8.0.
File Description
.github/​requirements/​semgrep.txt Updates the compiled dependency tree and platform markers.
.github/​requirements/​semgrep-overrides.txt Defines and documents the PyJWT override.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

# in its MCP server, never in `semgrep scan`, which is all semgrep.yaml runs.
# semgrep.yaml installs with --no-deps so pip does not re-apply semgrep's pin. Delete
# this line once a semgrep release allows pyjwt 2.15.
pyjwt[crypto]~=2.15.0

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants