Skip to content

Raise the second wave of vulnerable dependencies to their fixed versions - #292

Merged
LucaCappelletti94 merged 3 commits into
mainfrom
fix/second-wave-dependencies
Sep 8, 2026
Merged

LucaCappelletti94 merged 3 commits into
mainfrom
fix/second-wave-dependencies

Conversation

@LucaCappelletti94

Copy link
Copy Markdown
Collaborator

Trivy's advisory database picked up 41 further findings against the lockfile, 20 of them high, on packages already pinned here rather than anything the last bump moved. The serious ones are two PyJWT bypasses, one accepting forged tokens and one on verifier-side algorithm selection, Starlette SSRF and NTLM credential theft through UNC paths, and the MCP SDK serving session requests without verifying them. This raises the fifteen packages that have a published fix. WeasyPrint's CSS injection and the ecdsa Minerva timing attack have none and stay.

Starlette needs 1.3.1 and resolution landed on 1.6.0, which carries FastAPI from 0.128.1 to 0.141.1, and NiceGUI needs 3.12.0 and landed on 3.16.0. Those two are the reason this touches code at all, in a second commit kept apart from the lockfile.

NiceGUI now imports the members of its ui module lazily, which broke two tests that neutralised the dynamic page import by replacing importlib.import_module process-wide with a single-argument stub, since NiceGUI's own lazy lookups then hit that stub. The replacement is scoped to the one module name that is actually imported and delegates everything else to the real function, so it no longer depends on patch ordering. Separately, Dialog.close() became fluent and returns the dialog, so render_dialog_actions stopped accepting a plain close callback as on_cancel. It hands that callback straight to a button and discards the result, so the parameter was always typed more narrowly than its use and is now widened rather than wrapped at five call sites.

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR successfully upgrades 15 vulnerable dependencies and adapts the codebase to accommodate breaking changes in NiceGUI and Starlette. The analysis shows the changes are up to standards. However, the implementation of the new fluent dialog API in render_dialog_actions lacks a corresponding unit test to verify it handles objects returned by callbacks. No major security flaws or logic bugs were found in the current changes.

Test suggestions

  • Verify render_dialog_actions accepts a callback returning a Dialog object without type errors or runtime failures.
  • Verify test_web_app_factory can isolate page imports without blocking NiceGUI's internal lazy-loaded imports.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify render_dialog_actions accepts a callback returning a Dialog object without type errors or runtime failures.

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread src/openscientist/webapp_components/ui_components.py Outdated
@codecov

codecov Bot commented Sep 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Co-authored-by: codacy-production[bot] <61871480+codacy-production[bot]@users.noreply.github.com>
@sonarqubecloud

sonarqubecloud Bot commented Sep 8, 2026

Copy link
Copy Markdown

@LucaCappelletti94
LucaCappelletti94 merged commit bf596a6 into main Sep 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant