Skip to content

chore: fold strict dependency-floor lock metadata into security baseline - #520

Closed
seonghobae wants to merge 2 commits into
claude/contextualwisdomlab-audit-governance-qyxe67from
fix/trivy-fs-uv-lock-cves
Closed

chore: fold strict dependency-floor lock metadata into security baseline#520
seonghobae wants to merge 2 commits into
claude/contextualwisdomlab-audit-governance-qyxe67from
fix/trivy-fs-uv-lock-cves

Conversation

@seonghobae

Copy link
Copy Markdown
Collaborator

Temporary integration PR into #467's feature branch. It imports only the stricter Pillow/pypdf project-floor metadata already reviewed in closed #517. The merge preview must retain Click 8.4.2 and the httpx2/httpcore2/truststore removals before this is merged.

seonghobae and others added 2 commits August 4, 2026 16:35
…1, setuptools 83.0.0

Clears all 19 trivy-fs findings in uv.lock:
- pillow 12.2.0 -> 12.3.0 (13 CVEs incl. CVE-2026-54058, CVE-2026-59197)
- pypdf 6.13.3 -> 6.14.2 (CVE-2026-59935..59938)
- pymdown-extensions 10.21.3 -> 11.0.1 (CVE-2026-61632)
- setuptools 81.0.0 -> 83.0.0 (CVE-2026-59890)
- mkdocs-material 9.6.23 -> 9.7.7 (drops the pymdown-extensions~=10.2 cap)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The <9.7 hold blocked pymdown-extensions 11 (needed for
CVE-2026-61632). Validated per the CONTRIBUTING exit clause:
'uv run mkdocs build --strict' passes on material 9.7.7 with
mkdocs still 1.6.1. Guard tests and CONTRIBUTING now document
the validated >=9.7,<9.8 line; the mkdocs<2.0 hold stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 597e18e3-b066-479f-b276-795783c7ea42

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Collaborator Author

Closing this temporary integration PR because GitHub cannot produce a merge preview for the diverged lock histories. The canonical #467 branch already contains the reviewed strict pyproject.toml floors and regression contracts; its bounded one-shot workflow remains the safe path to regenerate uv.lock from that exact combined tree without reintroducing Click or the removed httpx2 closure.

@seonghobae seonghobae closed this Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant