WIP: Refresh vulnerable development and release lock #24

Closed
clawlter wants to merge 1 commit from audit/dependency-refresh into main
Owner

Remediates HUI-013 from audited baseline 36a6494b01538328d906dfc8b3d9393ec0690a33.

Dependency remediation

  • Updates direct development constraints to Black >=26.3.1,<27 and pytest >=9.0.3,<10.
  • Regenerates the frozen lock with fixed compatible releases: Black 26.5.1, pytest 9.1.1, pymdown-extensions 10.21.3, cryptography 49.0.0, idna 3.18, and urllib3 2.7.0.
  • Pins Black’s target version to the project’s supported Python 3.13 and applies its required formatting-only changes to three existing files.

Reachability and advisory evidence

  • Runtime-only OSV audit: 11 packages, zero findings (baseline and final).
  • All default groups include CI formatting/type/test/docs and release build/Twine tooling; baseline contained 11 OSV records across the six packages above. Final OSV audit: 70 packages, zero findings.
  • No ignore, suppression, frozen-install weakening, or tool removal.

Verification

  • uv lock --check and uv sync --frozen
  • Black and isort checks; strict Pyright (0 errors)
  • Full pytest: 14 passed
  • Strict MkDocs build and docs tests: 3 passed
  • sdist/wheel build and Twine metadata checks
  • clean Python 3.13 wheel install: hui --help and hui --db <temp> init

No publishing, merge, or changes to main. Draft pending independent review.

Remediates HUI-013 from audited baseline `36a6494b01538328d906dfc8b3d9393ec0690a33`. ## Dependency remediation - Updates direct development constraints to Black `>=26.3.1,<27` and pytest `>=9.0.3,<10`. - Regenerates the frozen lock with fixed compatible releases: Black 26.5.1, pytest 9.1.1, pymdown-extensions 10.21.3, cryptography 49.0.0, idna 3.18, and urllib3 2.7.0. - Pins Black’s target version to the project’s supported Python 3.13 and applies its required formatting-only changes to three existing files. ## Reachability and advisory evidence - Runtime-only OSV audit: 11 packages, zero findings (baseline and final). - All default groups include CI formatting/type/test/docs and release build/Twine tooling; baseline contained 11 OSV records across the six packages above. Final OSV audit: 70 packages, zero findings. - No ignore, suppression, frozen-install weakening, or tool removal. ## Verification - `uv lock --check` and `uv sync --frozen` - Black and isort checks; strict Pyright (0 errors) - Full pytest: 14 passed - Strict MkDocs build and docs tests: 3 passed - sdist/wheel build and Twine metadata checks - clean Python 3.13 wheel install: `hui --help` and `hui --db <temp> init` No publishing, merge, or changes to main. Draft pending independent review.
chore(deps): refresh vulnerable development lock
All checks were successful
Docs site / Validate docs build (pull_request) Successful in 1m45s
Python CI / Validate formatting, typing, and tests (pull_request) Successful in 7m50s
Docs site / Publish docs to mehalter.page (pull_request) Has been skipped
Python CI / Build source and wheel distributions (pull_request) Successful in 6m10s
3b63396f70
clawlter changed title from Draft: Refresh vulnerable development and release lock to WIP: Refresh vulnerable development and release lock 2026-07-11 18:40:41 -04:00
Author
Owner

Closing without merge because the owner cancelled the code-security-audit-2026-07 campaign. This does not revert previously merged work.

Closing without merge because the owner cancelled the `code-security-audit-2026-07` campaign. This does not revert previously merged work.
clawlter closed this pull request 2026-07-14 08:15:48 -04:00
All checks were successful
Docs site / Validate docs build (pull_request) Successful in 1m45s
Python CI / Validate formatting, typing, and tests (pull_request) Successful in 7m50s
Required
Details
Docs site / Publish docs to mehalter.page (pull_request) Has been skipped
Python CI / Build source and wheel distributions (pull_request) Successful in 6m10s
Required
Details

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
clawlter/hermes-usage-insights!24
No description provided.