Skip to content

bump executor aiohttp and urllib3 to clear snyk findings - #144

Merged
edandylytics merged 1 commit into
developmentfrom
snyk/early-oct-updates
Oct 5, 2026
Merged

edandylytics merged 1 commit into
developmentfrom
snyk/early-oct-updates

Conversation

@edandylytics

Copy link
Copy Markdown
Collaborator

This PR bumps a couple Executor dependencies flagged by Snyk. Ruwnay wasn't affected by these specific vulns. I've tested locally and job processing works as expected.

  • urllib3 2.7.0 -> 2.8.0
  • aiohttp 3.14.1 -> 3.14.3

- urllib3 2.7.0 -> 2.8.0: improper certificate validation (high),
  unbounded chunk-size buffering (high), deflate infinite loop (medium)
- aiohttp 3.14.1 -> 3.14.3: use after free (high), resource
  exhaustion and request smuggling (medium)

urllib3 backs the executor's requests session to the app and boto3's
S3 calls; aiohttp backs lightbeam's ODS fetch/send. 2.8.0's breaking
change is limited to HTTPS proxy TLS config, and the executor uses no
proxy. The aiohttp releases are bug fixes only. Both versions are past
the CI safe-chain age gate.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@amazon-inspector-ohio

Copy link
Copy Markdown

⏳ I'm reviewing this pull request for security vulnerabilities and code quality issues. I'll provide an update when I'm done

@snyk-io-us

snyk-io-us Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@amazon-inspector-ohio

Copy link
Copy Markdown

✅ I finished the code review, and didn't find any security or code quality issues.

@edandylytics
edandylytics merged commit bef654d into development Oct 5, 2026
4 checks passed
@edandylytics
edandylytics deleted the snyk/early-oct-updates branch October 5, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants