Repository navigation
build(deps): bump soupsieve from 2.8.4 to 2.9.2 - #41679
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [soupsieve](https://github.com/facelessuser/soupsieve) from 2.8.4 to 2.9. - [Release notes](https://github.com/facelessuser/soupsieve/releases) - [Commits](facelessuser/soupsieve@2.8.4...2.9) --- updated-dependencies: - dependency-name: soupsieve dependency-version: '2.9' dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
GHSA-gjv8-xp57-g29c and GHSA-j934-xhv5-fg8f affect soupsieve 2.8.4 (fixed in 2.9.0), so osv-scan fails on every PR whose lock still pins it. Generated with 'uv lock --upgrade-package soupsieve'; only the soupsieve stanza changes. Same intent as BerriAI#41679; drop this commit if that lands first. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011qUBY2P8qTTuJCUeMzTCD4
…raise the CVE floor
|
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 66cdc8e. Configure here.
|
Closing as superseded: #41703 landed the same soupsieve 2.9.2 bump on main first, so this PR now conflicts on uv.lock |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
TLDR
Problem this solves:
How it solves it:
[tool.uv]CVE floor tosoupsieve>=2.9so no relock returns to 2.8.4User Flow
Before: a contributor opens any PR into main and osv-scan turns red for a dependency they never touched
osv-scancheck fails within two minutes: "Total 1 package affected by 2 known vulnerabilities", soupsieve 2.8.4 in uv.lock, fixed version 2.9.0After: the same PR gets a green osv-scan
osv-scancheck passes with "No issues found"Relevant issues
Affected release
Linear ticket
Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
uv run pytest tests/test_litellm/<your_test_file>.py -v. Leave the suites (make test-unit-*,make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more (not applicable: no test file covers a lock bump, the import smoke below runs the only in-repo consumer against the new version)@greptileaito re-request a review after pushing changes) (5/5 at 66cdc8e)Delays in PR merge?
If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).
Screenshots / Proof of Fix
Shared setup: osv-scanner v2.3.8, the version
.github/workflows/osv-scan.ymlpins, checksum-verified against its SHA256SUMS, run from the repo root with CI's exact commandBefore (bc9f4fe)
osv-scanner on uv.lock, same command as CI
git checkout bc9f4fec5b, then the command aboveosv-scan check on a PR into main
##[error]Process completed with exit code 1., and the check is red on the PRsoupsieve through beautifulsoup4, the only in-repo consumer
uv sync --frozen --group ci --inexact, thenuv run --frozen --no-sync python -c 'import soupsieve, bs4; print("soupsieve", soupsieve.__version__, "bs4", bs4.__version__); print(bs4.BeautifulSoup("<ul><li class=a>one</li><li>two</li></ul>", "html.parser").select_one("li.a").text)'soupsieve 2.8.4 bs4 4.14.3andoneAfter (66cdc8e)
osv-scanner on uv.lock, same command as CI
git checkout 66cdc8e4d0, then the command aboveosv-scanner.tomlalready ignores on main, unchanged here):osv-scan check on a PR into main
Scanned .../uv.lock file and found 458 packages,Filtered 4 vulnerabilities from output,No issues found, and the check is green on the PRsoupsieve through beautifulsoup4, the only in-repo consumer
soupsieve 2.9.2 bs4 4.14.3andoneType
🚄 Infrastructure
Caveats (if any)
Low
soupsieve>=2.9in[tool.uv] constraint-dependencies, the same way the 2.8.4 floor was addeduv lockcould resolve back below the fixed versionexclude-newerin uv.lock moved from 2026-09-14T20:32Z to 2026-09-14T23:48Z: uv 0.10.9 refreshes its rolling window on every relock, and no other package moved>=0.10.9) flips those 388 lines back on the next relock, so they never landcigroup only, the proxy runtime never imports it, so no user-facing behavior changesFinal Attestation
Note
Low Risk
Lockfile and uv constraint bump only; no runtime or auth code changes, and soupsieve is used only transitively in CI test dependencies.
Overview
Fixes osv-scan failures on every PR into main by resolving two medium ReDoS advisories (GHSA-gjv8-xp57-g29c, GHSA-j934-xhv5-fg8f) that affect soupsieve 2.8.4 and are patched in 2.9.0+.
The lockfile pins soupsieve 2.9.2 (was 2.8.4), and
[tool.uv] constraint-dependenciesraises the floor fromsoupsieve>=2.8.4tosoupsieve>=2.9so futureuv lockruns cannot drift back below the fixed version. Theexclude-newertimestamp inuv.lockshifts slightly as part of the same relock; no other packages change.soupsieve remains a transitive dependency of beautifulsoup4 in the
cidependency group only—not the proxy runtime—so this is a supply-chain / CI hygiene change with no application code edits.Reviewed by Cursor Bugbot for commit 66cdc8e. Bugbot is set up for automated code reviews on this repo. Configure here.