fix(deps): enforce GitPython and AnyIO security floors - #1857
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Performance BenchmarksCompared
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 46986e664f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Reuse the AnyIO 4.14.2 and GitPython 3.1.60 lock updates and regression guards from PR #1857 so this branch passes the dependency audit independently.
Reuse the dependency remediation and security floor regression guards from PR promptfoo#1857 (46986e6 and ac1483f) so the safetensors CI audit can pass independently.
* fix(deps): bump anyio from 4.13.0 to 4.14.2 Bumps [anyio](https://github.com/agronholm/anyio) from 4.13.0 to 4.14.2. - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.13.0...4.14.2) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> * fix(deps): carry GitPython audit remediation Reuse the GitPython 3.1.60 lock update, regression floor, and changelog from PR #1857 (46986e6). AnyIO 4.14.2 is already present on this PR. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Michael D'Angelo <mdangelo@openai.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b7bcc102c0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
* fix(safetensors): preserve native FDICT-shaped headers * fix(deps): carry audited AnyIO and GitPython updates Reuse the dependency remediation and security floor regression guards from PR #1857 (46986e6 and ac1483f) so the safetensors CI audit can pass independently. * docs(changelog): record AnyIO security update * test(cache): stabilize retained interrupt monitor fixture --------- Co-authored-by: Arunim Shukla <54760103+arunimshukla@users.noreply.github.com>
* fix(ci): bound compatible lint and type checker versions * fix(ci): align standalone mypy validation dependencies * fix(deps): carry independent audit remediation Reuse the AnyIO 4.14.2 and GitPython 3.1.60 lock updates and regression guards from PR #1857 so this branch passes the dependency audit independently. * docs(changelog): include AnyIO audit remediation * test(cache): make interrupt cleanup fixture portable
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 79a84d4ecd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Require AnyIO >=4.14.2 in base package metadata and GitPython >=3.2.0 in the
mlflow,all-ci, andallextras. Keep the lockfile and regression guards consistent so these floors also protect published-wheel consumers. GitPython 3.2.0 addresses GHSA-f9j4-qggq-h239.Refreshed against main
17c9efa0without changing the dependency patch. Validation at9e322f92: 159 dependency and MLflow integration tests passed, repository-wide Ruff passed, lock consistency passed against the public index, and built-wheel metadata contains all four required declarations. Two independent native reviews and an independent verification found no actionable issues. Hosted CI is running on the refreshed head.Local mypy reports the pre-existing optional-TensorFlow unreachable-import error at
tests/scanners/test_weight_distribution_scanner.py:2122; no new type errors were reported. The devbox package mirror lacks GitPython 3.2.0, while upstream PyPI lists its released non-yanked wheel and sdist.