Skip to content

fix(deps): raise Mako and requests floors past known advisories - #152

Open
adamsrnmsu wants to merge 1 commit into
sandialabs:mainfrom
adamsrnmsu:fix-deps-mako-requests
Open

adamsrnmsu wants to merge 1 commit into
sandialabs:mainfrom
adamsrnmsu:fix-deps-mako-requests

Conversation

@adamsrnmsu

@adamsrnmsu adamsrnmsu commented Oct 1, 2026 •

Copy link
Copy Markdown

Description

Raise two dependency floors that sit below releases fixing published security advisories:

  • Mako~=1.1.3 → Mako>=1.3.10
  • requests==2.31.0 → requests>=2.32.4

One of four independent PRs splitting up a hardening patch: #153 (pathlib refactor), #154 (path validation), #155 (command execution). Each is a single commit on main and they can merge in any order.

Related Issues/PRs

#153, #154, #155. No dependencies between them.

Type of Change

  • Chore (CI, build, dependencies, etc.) (chore)

Checklist

  • This PR conforms to the process detailed in the Contributing Guide.
  • I have included no proprietary/sensitive information in my code or the PR.
  • I have commented my code, particularly in hard-to-understand areas.
  • I have made corresponding changes to the documentation.
  • I have tested my code (describe below).

Testing

make check and make test in src/python on Python 3.12, with Mako 1.4.3 and requests 2.34.2 installed: 697 passed.

Additional Notes

The CHANGELOG entry goes at the top of ### Changed, so it doesn't conflict with the entries in the other PRs.

🤖 Generated with Claude Code

https://claude.ai/code/session_016KAfcDUSerQCCWwBM9BxAo

@adamsrnmsu

Copy link
Copy Markdown
Author

@GhostofGoes i can't mark you as a reviewer for some reason

@GhostofGoes

Copy link
Copy Markdown
Contributor

@GhostofGoes i can't mark you as a reviewer for some reason

Welcome to the club of Phenix Contributors With No Real Power, we're a cool club.

@GhostofGoes GhostofGoes left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LTGM, assuming you've tested these with an actual deployment.

@adamsrnmsu

Copy link
Copy Markdown
Author

@GhostofGoes Thanks! Since we haven't cut a release yet, these are all technically just pre-release updates that can be verified in a real deployment before the release :)

@GhostofGoes

Copy link
Copy Markdown
Contributor

Oh, there are releases for apps?
Anyway, please test these changes, it takes 5 minutes. Mako touches everything.

Mako was held at ~=1.1.3 and requests pinned to 2.31.0, both below releases
that fix published security advisories. Raise the floors to Mako>=1.3.10 and
requests>=2.32.4. The full test suite passes against the new versions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016KAfcDUSerQCCWwBM9BxAo
@adamsrnmsu
adamsrnmsu force-pushed the fix-deps-mako-requests branch from cdec59d to 6c2d72f Compare October 4, 2026 23:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants