Skip to content

chore(deps): bump gitpython and tornado, extend diskcache osv ignore to Nov 1 - #43961

Merged
yuneng-berri merged 1 commit into
mainfrom
litellm_/lockout-exception-handling-7e0b37
Oct 1, 2026
Merged

yuneng-berri merged 1 commit into
mainfrom
litellm_/lockout-exception-handling-7e0b37

Conversation

@yuneng-berri

Copy link
Copy Markdown
Contributor

TLDR

Problem this solves:

  • The osv-scan lockfile check is red on every PR to main
  • gitpython and tornado have fixed releases we haven't picked up
  • The diskcache ignore expired on 2026-10-01 with still no fixed release

How it solves it:

  • Bump gitpython 3.1.61 to 3.1.62 (released 2026-09-07)
  • Bump tornado 6.5.8 to 6.5.10 (released 2026-09-15)
  • Move the diskcache ignore to 2026-11-01

Both bumps are past the 3-day uv cooldown. uv.lock only touches those two package blocks, since a full relock rewrote unrelated markers. uv lock --check passes

Screenshots / Proof of Fix

Before (6997223)

  1. Failing CI run on a PR to main: https://github.com/BerriAI/litellm/actions/runs/36799075151/job/110169119114
  2. Output: Total 3 packages affected by 5 known vulnerabilities (diskcache 5.6.3, gitpython 3.1.61, tornado 6.5.8), and osv-scanner.toml has unused ignores: GHSA-w8v5-vhqr-4h9v because its ignoreUntil had passed

After (1f0e543)

  1. osv-scanner scan source --config osv-scanner.toml -L uv.lock -L ui/litellm-dashboard/package-lock.json -L vscode-extension/package-lock.json
  2. Output: GHSA-w8v5-vhqr-4h9v and 2 aliases have been filtered out, then No issues found

Type

🚄 Infrastructure

Caveats (if any)

Medium

  • The two oauthlib ignores expire 2026-10-02, so this check goes red again then
    • oauthlib 4.0.0 clears the cooldown around 2026-10-01 06:00 UTC, but it is a major bump

…to Nov 1

gitpython 3.1.62 (2026-09-07) and tornado 6.5.10 (2026-09-15) are past the
3-day uv cooldown. diskcache still has no fixed release, so its ignore moves
from 2026-10-01 to 2026-11-01
@yuneng-berri
yuneng-berri requested a review from a team October 1, 2026 01:08
@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Bumps gitpython and tornado dependencies.

The PR appears safe to merge based on the reviewed changes.

Summary

Updates the locked GitPython and Tornado releases and extends the existing diskcache advisory ignore through November 1.

  • The dependency changes remain within the repository’s declared constraints.
  • The diskcache suppression remains explicitly time-limited.

Reviews (1) · Last reviewed commit: "chore(deps): bump gitpython and tornado,..."

@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@codspeed

codspeed Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 31 untouched benchmarks


Comparing litellm_/lockout-exception-handling-7e0b37 (1f0e543) with main (6997223)

Open in CodSpeed

@yuneng-berri
yuneng-berri merged commit 431ecd8 into main Oct 1, 2026
108 of 116 checks passed
@yuneng-berri
yuneng-berri deleted the litellm_/lockout-exception-handling-7e0b37 branch October 1, 2026 01:27
jan-sauer-reef added a commit to jan-sauer-reef/litellm that referenced this pull request Oct 1, 2026
…ject_key_prefix

* upstream/main: (62 commits)
  fix(guardrails): scan Responses API input in Azure Prompt Shield (BerriAI#43786)
  feat(lens): investigate sampled traces and retain batch results (BerriAI#43942)
  fix(proxy): restore pre-config-wins handling of pass-through endpoints (BerriAI#43962)
  fix(cost-map): raise baseten DeepSeek-V4.1-Flash max output to 262144 (BerriAI#43916)
  chore(cost-map): add deprecation date for anthropic claude-sonnet-4-5 (BerriAI#43898)
  chore(cost-map): add fireworks inkling priority prices from the prices api (BerriAI#43949)
  feat(guardrails): honor litellm_params.timeout in every HTTP guardrail (BerriAI#43134)
  test(e2e): typed per-test metadata for the e2e suite (BerriAI#42044)
  fix(caching): write the response-cache SET to Redis at once instead of on the post-call batch (BerriAI#43973)
  feat(ui): filter tags by name and description on the Tag Management page (BerriAI#42949)
  feat(providers): add Cortecs as an OpenAI-compatible provider (BerriAI#43872)
  feat(e2e): record each e2e test's steps, starting with ProxyClient (BerriAI#42393)
  test(ci): repair stale tests and move retired OpenAI text-completion fixtures (BerriAI#43958)
  feat(proxy): record in spend logs whether a request used a client-forwarded Anthropic OAuth token (BerriAI#43063)
  fix(azure_storage): keep the DataLakeServiceClient alive until its TTL elapses (BerriAI#43082)
  chore(deps): bump gitpython and tornado, extend diskcache osv ignore to Nov 1 (BerriAI#43961)
  fix(guardrails): treat an unknown straiker api_version as unset instead of skipping the guardrail (BerriAI#43956)
  fix(azure_storage): name Data Lake objects without base64 padding or slashes (BerriAI#43914)
  fix(grayswan): send request conversation and tool calls to post-call monitor (BerriAI#43770)
  chore(cost-map): sync openrouter prices from the models API (BerriAI#43950)
  ...

This branch is waiting to be deployed

1 waiting deployment
e2e-changed — 1f0e543e Waiting Oct 1, 2026 by yuneng-berri via oauth #2192
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants