Repository navigation
Bump urllib3 from 1.26.4 to 2.7.0 in /blueprints/gap-wave2-20260923/grype-known-cve-fixture - #105
Conversation
Bumps [urllib3](https://github.com/urllib3/urllib3) from 1.26.4 to 2.7.0. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@1.26.4...2.7.0) --- updated-dependencies: - dependency-name: urllib3 dependency-version: 2.7.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Closing: this manifest is a deliberately vulnerable positive-control fixture for the grype known-CVE detection test (gap ci-supply-chain[13], #101). Bumping urllib3 would break the control. The alerts are dismissed as not_used. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…immutable releases, target ruleset (#108) * Close the catalog's GitHub automation: OSV/zizmor-online scans, gates, immutable releases, target ruleset Add security-scan.yml: an osv-scanner job (OSV-Scanner 2.6.0, checksum-verified) over every tracked lockfile in .github/osv-scanner-lockfiles.json with --no-resolve, failing on unignored vulnerabilities and uploading SARIF off PRs, plus a zizmor-online SARIF job. A unittest fails when a tracked lockfile is missing from the inventory or an ignore lacks a <=90-day expiry. Gate dependency review at high (warn-only removed) and grype at --fail-on high with a reviewed, empty .grype.yaml; upload Scorecard SARIF with a job-scoped security-events write; add a 7-day Dependabot cooldown. publish-catalog.yml gains a tag-only release job (contents: write only) that re-checks the attested digests and creates the immutable release with both files attached at creation. .github/main-ruleset.json becomes the target (dependency-review and osv-scanner required, strict checks, signatures, CodeQL code_scanning, squash only); the tag rulesets match live 23829417 and 23859358. Record the evidence, the CodeQL-vs-zizmor comparison on 168a3a8 and the superseded decisions in docs/decisions/2026-09-22-github-automation-closure.md; update SECURITY.md, automation.json, the docs, the regenerated verdicts/explorer and evidence hashes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop required_signatures from the target ruleset; gate .grype.yaml changes; fix stale gate docs A measured agent-lab run (2026-09-23) blocked PRs with unsigned branch commits under required_signatures even though GitHub signs the squash merge, so the target main ruleset leaves the rule out as keep-but-compare until every writer signs. supply-chain.yml now runs its grype gate when .grype.yaml changes, with a test. Scorecard, dependency-review and grype docs no longer call the new gates report-only, and the CodeQL default-setup row cites the re-read settings GET. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Resolve the catalog-automation review findings after rebasing on main - Rebase onto origin/main 8faca90 (#96, #99-#104, #106): take main's removal of docs/ecosystem/index.html, merge main's explorer build/attest/upload steps with the release job's digest outputs, and re-register manifest hashes with host_receipts.register_file. - OSV inventory: add a reasoned "excluded" list for the #101 grype positive-control fixture; the coverage test accepts only listed, fixture-scoped exclusions with an evidence path and still fails on any unlisted tracked lockfile. osv-scanner 2.6.0 exits 0 on the 37 listed files. - Target main ruleset: strict_required_status_checks_policy false (auto-merge without a merge queue would stall every open PR when main moves); required_signatures stays out; regression tests assert both. - automation.json: gating lanes move to security_gate_lanes with boolean required_check/target_required_check; fresh CodeQL default-setup GET cited. - foundation.json: restore ci-supply-chain lane gap text, replace stale automation.json line citations with JSON-path anchors at 92bb279; regenerate verdicts and the handbook section with build_verdicts. - Handbook automation summary and closure record updated (mlx branch dropped after #99, fixture alerts 7-15 dismissed and #105 closed, security updates kept on, strict decision, gap-ledger mapping). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Align merge-queue and osv-scanner catalog text with the strict-off target; record #104 CodeQL triage - automation.json merge-queue non-adoption no longer cites strict checks; it points at the strict-off decision (closure record section 10) with its overturn condition. - osv-scanner selection says "required in the target ruleset once applied" and names the 37 listed lockfiles, 2 covered manifests and 1 fixture exclusion. - Closure record section 2: the 10 first-analysis CodeQL alerts were resolved in #104, not left for owners. - Hashes re-registered in manifests/evidence.json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Keep Dependabot security PRs off the grype positive-control fixture ignore: urllib3 on a pip entry scoped to the fixture directory (ignore applies to security updates; exclude-paths does not). Clarify that osv-scanner becomes a required check only after the target ruleset is applied. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Refresh evidence hashes after rebasing onto #95 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Fix the OSV SARIF path under bash -e; keep the zizmor write token away from the analyzer shell: bash implies -e, so a findings exit ended the OSV step before the SARIF run (reproduced; found by an independent-implementation comparison and the Codex cross-family review). zizmor now runs read-only and a tool-free upload job holds security-events: write. Tests cover both, plus OSV PackageOverrides and grype review-by dates. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Bumps urllib3 from 1.26.4 to 2.7.0.
Release notes
Sourced from urllib3's releases.
... (truncated)
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
9a950b9Release 2.7.05ec0de4Merge commit from fork2bdcc44Merge commit from forkf45b0dfFix a misleading example forProxyManager(#4970)577193cSwitch to nightly PyPy3.11 in CI for now (#4984)e90af45Avoid infinite loop inHTTPResponse.read_chunkedwhenamt=0(#4974)67ed74fBump dev dependencies (#4972)3abd481Upgrade mypy to version 1.20.2 (#4978)2b8725dDrop support for EOL PyPy3.10 (#4979)2944b2aUpgradesetup-chromeandsetup-firefoxto fix warnings (#4973)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.