Skip to content

fix(attack-surface-management): relax pyOpenSSL in the bbot MCP script - #159

Merged
monoxgas merged 1 commit into
mainfrom
nick/asm-bbot-mcp-pyopenssl
Sep 29, 2026
Merged

monoxgas merged 1 commit into
mainfrom
nick/asm-bbot-mcp-pyopenssl

Conversation

@monoxgas

Copy link
Copy Markdown
Contributor

Summary

  • mcp/bbot.py inline dependencies: pyOpenSSL~=25.3.0 → pyOpenSSL>=25.3.0,<27.
  • Version 2.0.2 → 2.0.3 in capability.yaml and pyproject.toml.

Why

The bbot MCP server is launched with uv run ${CAPABILITY_ROOT}/mcp/bbot.py, so it resolves its PEP 723 dependencies in its own environment. #158 relaxed pyOpenSSL in the manifest but missed this script, so the server still got pyOpenSSL 25.3.0 (2 advisories, max 9.8) and cryptography 46.0.7 (4 advisories, max 8.7).

Verification

uv pip compile of the script's dependencies (Python 3.13, x86_64 Linux):

pyopenssl cryptography dnspython
this branch 26.4.0 50.0.1 2.8.0
main 25.3.0 46.0.7 2.8.0

tests/test_bbot_mcp.py passed against pyopenssl 26.4.0 in the #158 test run, and the capability's other tests passed in the same environment. No other pyOpenSSL~= or dnspython<2.8 pins remain in the repo.

🤖 Generated with Claude Code

mcp/bbot.py declares its own PEP 723 dependencies and is launched with
`uv run`, so it resolves in its own environment. #158 relaxed pyOpenSSL
in the manifest but missed this script, which still pinned
pyOpenSSL~=25.3.0 and therefore cryptography<47. Allow pyOpenSSL 26.x
here too. Bump to 2.0.3.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@monoxgas
monoxgas merged commit 76080dd into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant