Skip to content

fix(deps): enforce GitPython and AnyIO security floors - #1857

Merged
mldangelo-oai merged 12 commits into
mainfrom
fix/gitpython-security-floor
Oct 4, 2026
Merged

mldangelo-oai merged 12 commits into
mainfrom
fix/gitpython-security-floor

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Require AnyIO >=4.14.2 in base package metadata and GitPython >=3.2.0 in the mlflow, all-ci, and all extras. Keep the lockfile and regression guards consistent so these floors also protect published-wheel consumers. GitPython 3.2.0 addresses GHSA-f9j4-qggq-h239.

Refreshed against main 17c9efa0 without changing the dependency patch. Validation at 9e322f92: 159 dependency and MLflow integration tests passed, repository-wide Ruff passed, lock consistency passed against the public index, and built-wheel metadata contains all four required declarations. Two independent native reviews and an independent verification found no actionable issues. Hosted CI is running on the refreshed head.

Local mypy reports the pre-existing optional-TensorFlow unreachable-import error at tests/scanners/test_weight_distribution_scanner.py:2122; no new type errors were reported. The devbox package mirror lacks GitPython 3.2.0, while upstream PyPI lists its released non-yanked wheel and sdist.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T17:42:04.096269Z 9e322f9 New commits
🔒 Security Review ✅ Completed 2026-10-04T17:42:25.835690Z 9e322f9 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 13 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 13 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 4.306s -> 4.330s (+0.5%).

Workload Benchmark Target Size Files Baseline Current Change Status
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 151.82ms 157.64ms +3.8% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 222.8us 216.8us -2.7% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 585.73ms 574.15ms -2.0% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 126.01ms 124.41ms -1.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 273.5us 276.8us +1.2% stable
rejected-basic-auth-candidates tests/benchmarks/test_scan_benchmarks.py::test_rejected_basic_auth_candidates_scan_linearly - 371.1 KiB 1 2.457s 2.484s +1.1% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 105.44ms 104.49ms -0.9% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 110.11ms 109.14ms -0.9% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 656.24ms 661.88ms +0.9% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 297.2us 295.0us -0.7% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 112.51ms 112.87ms +0.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 309.3us 309.8us +0.2% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 341.4us 341.4us +0.0% stable

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 46986e664f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/test_dependency_lock.py Outdated
@mldangelo-oai mldangelo-oai changed the title fix(deps): upgrade GitPython security floor fix(deps): remediate GitPython and AnyIO vulnerabilities Sep 20, 2026
mldangelo-oai added a commit that referenced this pull request Sep 29, 2026
Reuse the GitPython 3.1.60 lock update, regression floor, and changelog from PR #1857 (46986e6). AnyIO 4.14.2 is already present on this PR.
mldangelo-oai added a commit that referenced this pull request Sep 29, 2026
Reuse the AnyIO 4.14.2 and GitPython 3.1.60 lock updates and regression guards from PR #1857 so this branch passes the dependency audit independently.
mldangelo-oai added a commit to arunimshukla/modelaudit that referenced this pull request Sep 29, 2026
Reuse the dependency remediation and security floor regression guards from PR promptfoo#1857 (46986e6 and ac1483f) so the safetensors CI audit can pass independently.
mldangelo-oai added a commit that referenced this pull request Sep 29, 2026
* fix(deps): bump anyio from 4.13.0 to 4.14.2

Bumps [anyio](https://github.com/agronholm/anyio) from 4.13.0 to 4.14.2.
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.13.0...4.14.2)

---
updated-dependencies:
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix(deps): carry GitPython audit remediation

Reuse the GitPython 3.1.60 lock update, regression floor, and changelog from PR #1857 (46986e6). AnyIO 4.14.2 is already present on this PR.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Michael D'Angelo <mdangelo@openai.com>
@mldangelo-oai mldangelo-oai changed the title fix(deps): remediate GitPython and AnyIO vulnerabilities fix(deps): enforce GitPython and AnyIO security floors Sep 30, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b7bcc102c0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread CHANGELOG.md Outdated
mldangelo-oai added a commit that referenced this pull request Oct 3, 2026
* fix(safetensors): preserve native FDICT-shaped headers

* fix(deps): carry audited AnyIO and GitPython updates

Reuse the dependency remediation and security floor regression guards from PR #1857 (46986e6 and ac1483f) so the safetensors CI audit can pass independently.

* docs(changelog): record AnyIO security update

* test(cache): stabilize retained interrupt monitor fixture

---------

Co-authored-by: Arunim Shukla <54760103+arunimshukla@users.noreply.github.com>
mldangelo pushed a commit that referenced this pull request Oct 3, 2026
* fix(ci): bound compatible lint and type checker versions

* fix(ci): align standalone mypy validation dependencies

* fix(deps): carry independent audit remediation

Reuse the AnyIO 4.14.2 and GitPython 3.1.60 lock updates and regression guards from PR #1857 so this branch passes the dependency audit independently.

* docs(changelog): include AnyIO audit remediation

* test(cache): make interrupt cleanup fixture portable
@mldangelo
mldangelo enabled auto-merge (squash) October 3, 2026 22:04

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 79a84d4ecd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pyproject.toml Outdated
@mldangelo
mldangelo disabled auto-merge October 4, 2026 09:11
@mldangelo
mldangelo enabled auto-merge (squash) October 4, 2026 10:32
@mldangelo-oai
mldangelo-oai merged commit b80c705 into main Oct 4, 2026
42 checks passed
@mldangelo-oai
mldangelo-oai deleted the fix/gitpython-security-floor branch October 4, 2026 19:15
@github-actions github-actions Bot mentioned this pull request Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants