Repository navigation
deps(semgrep): PyJWT 2.15.1 (override) + urllib3 2.8.0 (2/2, merge after 1/2) - #401
Open
Chris-Wolfgang wants to merge 4 commits into
Open
Chris-Wolfgang wants to merge 4 commits into
Chris-Wolfgang wants to merge 4 commits into
Conversation
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Companion PR #400 remains unmerged, so the current Semgrep workflow rejects this dependency tree.
1 open finding
What changed in this PR
Updates Semgrep’s hash-pinned dependencies to address PyJWT and urllib3 vulnerabilities.
Changes:
- Overrides PyJWT to 2.15.x.
- Regenerates the lockfile with PyJWT 2.15.1 and urllib3 2.8.0.
| File | Description |
|---|---|
.github/requirements/semgrep.txt |
Updates the compiled dependency tree and platform markers. |
.github/requirements/semgrep-overrides.txt |
Defines and documents the PyJWT override. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| # in its MCP server, never in `semgrep scan`, which is all semgrep.yaml runs. | ||
| # semgrep.yaml installs with --no-deps so pip does not re-apply semgrep's pin. Delete | ||
| # this line once a semgrep release allows pyjwt 2.15. | ||
| pyjwt[crypto]~=2.15.0 |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

2 of 2. Merge after #400 (
semgrep.yamlinstalls with--no-deps). If this lands first, pip re-applies semgrep'spyjwt~=2.13.0pin and refuses the new tree, and the Semgrep job fails onmainuntil 1/2 merges.What it fixes
Changes
semgrep-overrides.txt(new):pyjwt[crypto]~=2.15.0, passed touv pip compile --override.semgrep.txt's header records the command. Semgrep importsjwtonly in its MCP server, never insemgrep scan. Delete the override once a semgrep release allows PyJWT 2.15.semgrep.txtrecompiled with uv 0.12.21: PyJWT 2.15.1 and urllib3 2.8.0, with every other pin kept. The newer uv also adds environment markers (cffi, pycparser, uvicorn) and a Windows-onlypywin32entry. None apply on the Linux runner.Verified locally
This exact lockfile was installed with
pip install --no-deps --require-hashesin a fresh venv: it gives PyJWT 2.15.1 and urllib3 2.8.0 on this repo's semgrep version. As a smoke test of the install, the workflow's scan (p/csharp,p/security-audit,p/secrets) then ran against DbContextBuilder's source and completed: 167 rules on 662 files, 0 findings. This repo's own scan runs onmainafter merge. The identical change is running green on Chris-Wolfgang/DbContextBuildermain.Semgrepjob fails until 1/2 merges. That's expected. This repo'ssemgrep.yamlinstalls the PR's own lockfile, and without 1/2's--no-depspip refuses the override (semgrep 1.177.0 depends on pyjwt~=2.13.0). After merging 1/2, re-run this PR's Semgrep job. It then installs this lockfile with--no-depsand should pass: a real CI test of it.Semgrepis not a required check.🤖 Generated with Claude Code