Skip to content

fix(deps): remediate FOSSA CVEs in click, pyjwt, python-dotenv, python-socketio - #1897

Merged
robert-ursu merged 3 commits into
mainfrom
fix/cve-remediation-2026-09
Sep 15, 2026
Merged

robert-ursu merged 3 commits into
mainfrom
fix/cve-remediation-2026-09

Conversation

@robert-ursu

@robert-ursu robert-ursu commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Remediates the FOSSA security findings for the uipath package and the sample lockfiles FOSSA scans.

CVEs Package Was Fixed in Change
CVE-2026-7246 click 8.3.1 8.3.3 floor >=8.3.3, <9.0.0, SDK lock 8.4.2, sample locks 8.5.0
CVE-2026-32597, CVE-2026-48522..48526 PyJWT 2.10.1 / 2.11.0 / 2.12.1 2.13.0 floor >=2.13.0, <3.0.0, locked 2.14.0
CVE-2026-28684 python-dotenv 1.0.1 / 1.2.1 1.2.2 floor >=1.2.2, <2.0.0, locked 1.2.3
CVE-2026-48804 python-socketio 5.15.0 / 5.16.1 5.16.2 floor >=5.16.2, <6.0.0, locked 5.16.4
CVE-2025-53365, CVE-2025-53366, CVE-2025-66416, CVE-2026-52869, CVE-2026-59950 mcp (samples only) 1.0.0 / 1.26.0 1.28.1 list-mcp-agent floor >=1.28.1; greeter lock 2.2.0

uipath is bumped to 2.14.16. The three samples that point at the local SDK (attachment_evaluation_test, csv_employee_generator, line_by_line_test) pick up the local 2.14.16 in their lockfiles as a side effect of the re-lock.

The SDK lock stays at click 8.4.2 rather than 8.5.0: 8.5.0 deprecates CliRunner.isolated_filesystem, which the CLI tests use ~280 times, and the warnings summary overflows the CI runner's non-blocking stdout (BlockingIOError). The floor still admits 8.5.0 for downstream installs.

The raised floors are a hard constraint tightening for downstream installs pinned to older click / PyJWT / python-dotenv / python-socketio releases.

Verification

  • ruff check and the httpx-client lint pass
  • pytest: 2452 passed
  • all seven uv.lock files in the repo verified at or above the fixed versions

🤖 Generated with Claude Code

…n-socketio (PRODEV-1544)

Raise the SDK floors to the first fixed releases (click 8.3.3, PyJWT 2.13.0,
python-dotenv 1.2.2, python-socketio 5.16.2), re-lock the SDK and the four
sample lockfiles FOSSA scans, and lift the list-mcp-agent sample's mcp floor
to 1.28.1.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 15, 2026 08:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues were identified.

Pull request overview

Remediates dependency CVEs by raising package floors, updating uipath to 2.14.16, and refreshing sample lockfiles.

Changes:

  • Updates Click, PyJWT, python-dotenv, python-socketio, and MCP minimum versions.
  • Regenerates affected lockfiles with remediated versions.
File summaries
File Description
packages/uipath/uv.lock Locks remediated dependency versions.
packages/uipath/samples/list-mcp-agent/pyproject.toml Raises the MCP minimum version.
packages/uipath/samples/line_by_line_test/uv.lock Refreshes local SDK and dependency locks.
packages/uipath/samples/greeter/uv.lock Updates MCP and transitive dependency locks.
packages/uipath/pyproject.toml Updates the SDK version and dependency floors.
Review details
  • Files reviewed: 2/7 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

click 8.5.0 deprecates CliRunner.isolated_filesystem, which the CLI tests
use ~280 times; the resulting warnings summary overflows the CI runner's
non-blocking stdout and fails the job with BlockingIOError.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Comment thread packages/uipath/pyproject.toml Outdated
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@robert-ursu
robert-ursu enabled auto-merge (squash) September 15, 2026 10:44
@sonarqubecloud

Copy link
Copy Markdown

@robert-ursu
robert-ursu merged commit 6c1e604 into main Sep 15, 2026
103 checks passed
@robert-ursu
robert-ursu deleted the fix/cve-remediation-2026-09 branch September 15, 2026 10:48
robert-ursu added a commit to UiPath/uipath-mcp-python that referenced this pull request Sep 15, 2026
uipath moves from >=2.10.40, <2.14.0 to >=2.14.16, <2.15.0 so installs pick
up the click, PyJWT, python-dotenv and python-socketio fixes shipped in
UiPath/uipath-python#1897. uipath 2.14 requires uipath-runtime 0.13, so that
range follows to >=0.13.1, <0.14.0.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
robert-ursu added a commit to UiPath/uipath-langchain-python that referenced this pull request Sep 15, 2026
Raises the uipath floor from 2.14.13 so installs pick up the click, PyJWT,
python-dotenv and python-socketio fixes shipped in UiPath/uipath-python#1897;
the template lock follows.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@robert-ursu robert-ursu changed the title fix(deps): remediate FOSSA CVEs in click, pyjwt, python-dotenv, python-socketio (PRODEV-1544) fix(deps): remediate FOSSA CVEs in click, pyjwt, python-dotenv, python-socketio Sep 15, 2026
robert-ursu added a commit to UiPath/uipath-mcp-python that referenced this pull request Sep 15, 2026
uipath moves from >=2.10.40, <2.14.0 to >=2.14.16, <2.15.0 so installs pick
up the click, PyJWT, python-dotenv and python-socketio fixes shipped in
UiPath/uipath-python#1897. uipath 2.14 requires uipath-runtime 0.13, so that
range follows to >=0.13.1, <0.14.0.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
robert-ursu added a commit to UiPath/uipath-langchain-python that referenced this pull request Sep 15, 2026
Raises the uipath floor from 2.14.13 so installs pick up the click, PyJWT,
python-dotenv and python-socketio fixes shipped in UiPath/uipath-python#1897;
the template lock follows.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants