diff --git a/CHANGELOG.md b/CHANGELOG.md index ac57e303b..33027145b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Upgrade gzip, PCRE2, SQLite, and Perl in Docker runtime images to pick up Debian security fixes. - Upgrade locked GitPython to 3.1.59 to address four dependency audit advisories. +- Upgrade locked GitPython to 3.1.60 to address newly disclosed dependency audit advisories. - Inspect hidden ZIP archives and malicious pickle payloads in legacy GGML model variants. - Stop reporting a ZIP polyglot for GGUF/GGML files whose tensor data merely contains an end-of-central-directory signature. - Upgrade Debian util-linux packages in all Docker runtime images to remediate CVE-2026-53615. diff --git a/tests/test_dependency_lock.py b/tests/test_dependency_lock.py index a06feb7b7..cfb76589e 100644 --- a/tests/test_dependency_lock.py +++ b/tests/test_dependency_lock.py @@ -16,7 +16,7 @@ ROOT_PYPROJECT = ROOT_DIR / "pyproject.toml" RENOVATE_CONFIG = ROOT_DIR / "renovate.json" PICKLESCAN_PYPROJECT = ROOT_DIR / "packages" / "modelaudit-picklescan" / "pyproject.toml" -PATCHED_GITPYTHON_FLOOR = (3, 1, 59) +PATCHED_GITPYTHON_FLOOR = (3, 1, 60) PINNED_MATURIN_BACKEND = "maturin===1.13.3" REQUIRED_PICKLESCAN_RELEASE = "modelaudit-picklescan>=0.1.10,<0.2.0" PATCHED_PY7ZR_REQUIREMENT = "py7zr>=1.1.3" diff --git a/uv.lock b/uv.lock index 7d5651c10..b2563abea 100644 --- a/uv.lock +++ b/uv.lock @@ -3,10 +3,10 @@ revision = 3 requires-python = ">=3.10, <3.14" resolution-markers = [ "python_full_version >= '3.13' and platform_machine != 's390x'", - "python_full_version == '3.12.*' and platform_machine != 's390x'", - "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version >= '3.13' and platform_machine == 's390x'", + "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version == '3.12.*' and platform_machine == 's390x'", + "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version == '3.11.*' and platform_machine == 's390x'", "python_full_version < '3.11' and platform_machine != 's390x'", "python_full_version < '3.11' and platform_machine == 's390x'", @@ -202,16 +202,16 @@ wheels = [ [[package]] name = "anyio" -version = "4.13.0" +version = "4.14.2" source = { registry = "https://pypi.org/simple" } dependencies = [ { name = "exceptiongroup", marker = "python_full_version < '3.11'" }, { name = "idna" }, { name = "typing-extensions", marker = "python_full_version < '3.13'" }, ] -sdist = { url = "https://files.pythonhosted.org/packages/19/14/2c5dd9f512b66549ae92767a9c7b330ae88e1932ca57876909410251fe13/anyio-4.13.0.tar.gz", hash = "sha256:334b70e641fd2221c1505b3890c69882fe4a2df910cba14d97019b90b24439dc", size = 231622, upload-time = "2026-03-24T12:59:09.671Z" } +sdist = { url = "https://files.pythonhosted.org/packages/61/cc/a381afa6efea9f496eff839d4a6a1aed3bfafc7b3ab4b0d1b243a12573dd/anyio-4.14.2.tar.gz", hash = "sha256:cfa139f3ed1a23ee8f88a145ddb5ac7605b8bbfd8592baacd7ce3d8bb4313c7f", size = 260176, upload-time = "2026-07-12T20:29:07.082Z" } wheels = [ - { url = "https://files.pythonhosted.org/packages/da/42/e921fccf5015463e32a3cf6ee7f980a6ed0f395ceeaa45060b61d86486c2/anyio-4.13.0-py3-none-any.whl", hash = "sha256:08b310f9e24a9594186fd75b4f73f4a4152069e3853f1ed8bfbf58369f4ad708", size = 114353, upload-time = "2026-03-24T12:59:08.246Z" }, + { url = "https://files.pythonhosted.org/packages/da/35/f2287558c17e29fafc8ef3daf819bb9834061cfa43bff8014f7df7f63bdc/anyio-4.14.2-py3-none-any.whl", hash = "sha256:9f505dda5ac9f0c8309b5e8bd445a8c2bf7246f3ce950121e45ea15bc41d1494", size = 125813, upload-time = "2026-07-12T20:29:05.763Z" }, ] [[package]] @@ -1107,14 +1107,14 @@ wheels = [ [[package]] name = "gitpython" -version = "3.1.59" +version = "3.1.60" source = { registry = "https://pypi.org/simple" } dependencies = [ { name = "gitdb" }, ] -sdist = { url = "https://files.pythonhosted.org/packages/ca/dc/126b28e76b24a9268ba931ad3e012f71ebdadf62fd9f17758f7074bb0b20/gitpython-3.1.59.tar.gz", hash = "sha256:0a1475cfdc38a5bfba1a3e9a4a9da52a39749ecec322b772915c019f94e5b7e4", size = 230445, upload-time = "2026-08-10T12:03:20.271Z" } +sdist = { url = "https://files.pythonhosted.org/packages/84/14/e6b1a48d831755a53c2029351fcef82e70db4a08f338daefe29d8d0cf31c/gitpython-3.1.60.tar.gz", hash = "sha256:e936431879fa85581b4311fa63492ea52251909e2d655b6529c704c904ddcc24", size = 230793, upload-time = "2026-08-25T18:33:46.102Z" } wheels = [ - { url = "https://files.pythonhosted.org/packages/ef/ed/ae57eb7d344f43f87b74b3a281ead6ec7d6394eef72a7b1dcb28dd089550/gitpython-3.1.59-py3-none-any.whl", hash = "sha256:67a82f537384578643624c8b2c531938a9b82be431663e575dcf638526631d4c", size = 220996, upload-time = "2026-08-10T12:03:18.804Z" }, + { url = "https://files.pythonhosted.org/packages/71/63/ba28697918b7c190af9f3f21940d03e8814e25dd4ddd39d6929f3a553995/gitpython-3.1.60-py3-none-any.whl", hash = "sha256:39548bffb8fa0f3a548133348868bb4838e79d73283052207dc97781a569b6b4", size = 221893, upload-time = "2026-08-25T18:33:44.75Z" }, ] [[package]] @@ -2141,11 +2141,11 @@ requires-dist = [ { name = "sqlparse", marker = "extra == 'mlflow'", specifier = ">=0.6.0" }, { name = "tensorflow", marker = "python_full_version >= '3.11' and python_full_version < '3.13' and extra == 'tensorflow'", specifier = ">=2.21,<2.22" }, { name = "tensorrt", marker = "(sys_platform == 'linux' and extra == 'tensorrt') or (sys_platform == 'win32' and extra == 'tensorrt')", specifier = ">=8.6.0" }, - { name = "tomli", marker = "python_full_version < '3.11'", specifier = ">=2.0.0" }, { name = "tflite", marker = "extra == 'all'", specifier = ">=2.18.0" }, { name = "tflite", marker = "extra == 'all-ci'", specifier = ">=2.18.0" }, { name = "tflite", marker = "extra == 'numpy1'", specifier = ">=2.18.0" }, { name = "tflite", marker = "extra == 'tflite'", specifier = ">=2.18.0" }, + { name = "tomli", marker = "python_full_version < '3.11'", specifier = ">=2.0.0" }, { name = "torch", marker = "extra == 'all'", specifier = ">=2.13.0,<3.0" }, { name = "torch", marker = "extra == 'all-ci'", specifier = ">=2.13.0,<3.0" }, { name = "torch", marker = "extra == 'numpy1'", specifier = ">=2.13.0,<3.0" }, @@ -2435,10 +2435,10 @@ version = "3.6.1" source = { registry = "https://pypi.org/simple" } resolution-markers = [ "python_full_version >= '3.13' and platform_machine != 's390x'", - "python_full_version == '3.12.*' and platform_machine != 's390x'", - "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version >= '3.13' and platform_machine == 's390x'", + "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version == '3.12.*' and platform_machine == 's390x'", + "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version == '3.11.*' and platform_machine == 's390x'", ] sdist = { url = "https://files.pythonhosted.org/packages/6a/51/63fe664f3908c97be9d2e4f1158eb633317598cfa6e1fc14af5383f17512/networkx-3.6.1.tar.gz", hash = "sha256:26b7c357accc0c8cde558ad486283728b65b6a95d85ee1cd66bafab4c8168509", size = 2517025, upload-time = "2025-12-08T17:02:39.908Z" } @@ -2550,8 +2550,8 @@ version = "2.5.0" source = { registry = "https://pypi.org/simple" } resolution-markers = [ "python_full_version >= '3.13' and platform_machine != 's390x'", - "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version >= '3.13' and platform_machine == 's390x'", + "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version == '3.12.*' and platform_machine == 's390x'", ] sdist = { url = "https://files.pythonhosted.org/packages/e7/05/3d27272d30698dc0ecb7fdfaa41ad70303b444f81722bb99bce1d818638a/numpy-2.5.0.tar.gz", hash = "sha256:5a129578019311b6e56bdd714250f19b518f7dceeeb8d1af5490f4942d3f891c", size = 20652461, upload-time = "2026-06-21T20:57:51.95Z" } @@ -3734,10 +3734,10 @@ version = "1.8.0" source = { registry = "https://pypi.org/simple" } resolution-markers = [ "python_full_version >= '3.13' and platform_machine != 's390x'", - "python_full_version == '3.12.*' and platform_machine != 's390x'", - "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version >= '3.13' and platform_machine == 's390x'", + "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version == '3.12.*' and platform_machine == 's390x'", + "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version == '3.11.*' and platform_machine == 's390x'", ] dependencies = [ @@ -3841,10 +3841,10 @@ version = "1.17.1" source = { registry = "https://pypi.org/simple" } resolution-markers = [ "python_full_version >= '3.13' and platform_machine != 's390x'", - "python_full_version == '3.12.*' and platform_machine != 's390x'", - "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version >= '3.13' and platform_machine == 's390x'", + "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version == '3.12.*' and platform_machine == 's390x'", + "python_full_version == '3.11.*' and platform_machine != 's390x'", "python_full_version == '3.11.*' and platform_machine == 's390x'", ] dependencies = [ @@ -4511,8 +4511,8 @@ version = "3.4.1" source = { registry = "https://pypi.org/simple" } resolution-markers = [ "python_full_version >= '3.13' and platform_machine != 's390x'", - "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version >= '3.13' and platform_machine == 's390x'", + "python_full_version == '3.12.*' and platform_machine != 's390x'", "python_full_version == '3.12.*' and platform_machine == 's390x'", ] dependencies = [