Raise the second wave of vulnerable dependencies to their fixed versions - #292
Conversation
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
| Duplication | 0 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
There was a problem hiding this comment.
Pull Request Overview
This PR successfully upgrades 15 vulnerable dependencies and adapts the codebase to accommodate breaking changes in NiceGUI and Starlette. The analysis shows the changes are up to standards. However, the implementation of the new fluent dialog API in render_dialog_actions lacks a corresponding unit test to verify it handles objects returned by callbacks. No major security flaws or logic bugs were found in the current changes.
Test suggestions
- Verify render_dialog_actions accepts a callback returning a Dialog object without type errors or runtime failures.
- Verify test_web_app_factory can isolate page imports without blocking NiceGUI's internal lazy-loaded imports.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify render_dialog_actions accepts a callback returning a Dialog object without type errors or runtime failures.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Co-authored-by: codacy-production[bot] <61871480+codacy-production[bot]@users.noreply.github.com>
|



Trivy's advisory database picked up 41 further findings against the lockfile, 20 of them high, on packages already pinned here rather than anything the last bump moved. The serious ones are two PyJWT bypasses, one accepting forged tokens and one on verifier-side algorithm selection, Starlette SSRF and NTLM credential theft through UNC paths, and the MCP SDK serving session requests without verifying them. This raises the fifteen packages that have a published fix. WeasyPrint's CSS injection and the ecdsa Minerva timing attack have none and stay.
Starlette needs 1.3.1 and resolution landed on 1.6.0, which carries FastAPI from 0.128.1 to 0.141.1, and NiceGUI needs 3.12.0 and landed on 3.16.0. Those two are the reason this touches code at all, in a second commit kept apart from the lockfile.
NiceGUI now imports the members of its ui module lazily, which broke two tests that neutralised the dynamic page import by replacing importlib.import_module process-wide with a single-argument stub, since NiceGUI's own lazy lookups then hit that stub. The replacement is scoped to the one module name that is actually imported and delegates everything else to the real function, so it no longer depends on patch ordering. Separately, Dialog.close() became fluent and returns the dialog, so render_dialog_actions stopped accepting a plain close callback as on_cancel. It hands that callback straight to a button and discards the result, so the parameter was always typed more narrowly than its use and is now widened rather than wrapped at five call sites.