fix(deps): remediate FOSSA CVEs in click, pyjwt, python-dotenv, python-socketio - #1897
Merged
Merged
Conversation
…n-socketio (PRODEV-1544) Raise the SDK floors to the first fixed releases (click 8.3.3, PyJWT 2.13.0, python-dotenv 1.2.2, python-socketio 5.16.2), re-lock the SDK and the four sample lockfiles FOSSA scans, and lift the list-mcp-agent sample's mcp floor to 1.28.1. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
No unresolved review issues were identified.
Pull request overview
Remediates dependency CVEs by raising package floors, updating uipath to 2.14.16, and refreshing sample lockfiles.
Changes:
- Updates Click, PyJWT, python-dotenv, python-socketio, and MCP minimum versions.
- Regenerates affected lockfiles with remediated versions.
File summaries
| File | Description |
|---|---|
packages/uipath/uv.lock |
Locks remediated dependency versions. |
packages/uipath/samples/list-mcp-agent/pyproject.toml |
Raises the MCP minimum version. |
packages/uipath/samples/line_by_line_test/uv.lock |
Refreshes local SDK and dependency locks. |
packages/uipath/samples/greeter/uv.lock |
Updates MCP and transitive dependency locks. |
packages/uipath/pyproject.toml |
Updates the SDK version and dependency floors. |
Review details
- Files reviewed: 2/7 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
click 8.5.0 deprecates CliRunner.isolated_filesystem, which the CLI tests use ~280 times; the resulting warnings summary overflows the CI runner's non-blocking stdout and fails the job with BlockingIOError. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
radu-mocanu
reviewed
Sep 15, 2026
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
radu-mocanu
approved these changes
Sep 15, 2026
robert-ursu
enabled auto-merge (squash)
September 15, 2026 10:44
|
robert-ursu
added a commit
to UiPath/uipath-mcp-python
that referenced
this pull request
Sep 15, 2026
uipath moves from >=2.10.40, <2.14.0 to >=2.14.16, <2.15.0 so installs pick up the click, PyJWT, python-dotenv and python-socketio fixes shipped in UiPath/uipath-python#1897. uipath 2.14 requires uipath-runtime 0.13, so that range follows to >=0.13.1, <0.14.0. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
robert-ursu
added a commit
to UiPath/uipath-langchain-python
that referenced
this pull request
Sep 15, 2026
Raises the uipath floor from 2.14.13 so installs pick up the click, PyJWT, python-dotenv and python-socketio fixes shipped in UiPath/uipath-python#1897; the template lock follows. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
robert-ursu
added a commit
to UiPath/uipath-mcp-python
that referenced
this pull request
Sep 15, 2026
uipath moves from >=2.10.40, <2.14.0 to >=2.14.16, <2.15.0 so installs pick up the click, PyJWT, python-dotenv and python-socketio fixes shipped in UiPath/uipath-python#1897. uipath 2.14 requires uipath-runtime 0.13, so that range follows to >=0.13.1, <0.14.0. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
robert-ursu
added a commit
to UiPath/uipath-langchain-python
that referenced
this pull request
Sep 15, 2026
Raises the uipath floor from 2.14.13 so installs pick up the click, PyJWT, python-dotenv and python-socketio fixes shipped in UiPath/uipath-python#1897; the template lock follows. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Remediates the FOSSA security findings for the
uipathpackage and the sample lockfiles FOSSA scans.>=8.3.3, <9.0.0, SDK lock 8.4.2, sample locks 8.5.0>=2.13.0, <3.0.0, locked 2.14.0>=1.2.2, <2.0.0, locked 1.2.3>=5.16.2, <6.0.0, locked 5.16.4>=1.28.1; greeter lock 2.2.0uipathis bumped to 2.14.16. The three samples that point at the local SDK (attachment_evaluation_test,csv_employee_generator,line_by_line_test) pick up the local 2.14.16 in their lockfiles as a side effect of the re-lock.The SDK lock stays at click 8.4.2 rather than 8.5.0: 8.5.0 deprecates
CliRunner.isolated_filesystem, which the CLI tests use ~280 times, and the warnings summary overflows the CI runner's non-blocking stdout (BlockingIOError). The floor still admits 8.5.0 for downstream installs.The raised floors are a hard constraint tightening for downstream installs pinned to older click / PyJWT / python-dotenv / python-socketio releases.
Verification
ruff checkand the httpx-client lint passpytest: 2452 passeduv.lockfiles in the repo verified at or above the fixed versions🤖 Generated with Claude Code