fix(deps): lock tornado 6.5.10 for GHSA-chx6-46f5-w4vp, GHSA-c2m8-h5v5-343r and GHSA-3hv7-mjh2-fv65 - #30
Merged
Conversation
…5-343r and GHSA-3hv7-mjh2-fv65 tornado 6.5.8 is affected by three advisories, all fixed in 6.5.9: - GHSA-chx6-46f5-w4vp: CurlAsyncHTTPClient accumulates a decompressed response body without any size limit (memory exhaustion). - GHSA-c2m8-h5v5-343r: StaticFileHandler follows a symlink inside the static root to a file outside it (arbitrary file read). - GHSA-3hv7-mjh2-fv65: HTTPServerRequest parses the URL query string with no field-count limit (CPU exhaustion). The lock moves tornado 6.5.8 -> 6.5.10, the latest release, with `uv lock --upgrade-package tornado`. No other package changes version and the resolution markers are unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Locks tornado 6.5.10 (from 6.5.8) to close three advisories fixed in 6.5.9:
CurlAsyncHTTPClientStaticFileHandlersymlink escape from the static rootProduced by
uv lock --upgrade-package tornado(uv 0.12.21). Onlyuv.lockchanges; no other package moves and the resolution markers are unchanged.Verification
Audit run as the Security workflow runs it, with a fresh pip-audit cache:
pre-commit run --all-files: exit 0The Security workflow does not see these advisories
The workflow's own command,
uv run --with pip-audit pip-audit --local --desc, reports"No known vulnerabilities found" on the lock on main, with tornado 6.5.8 installed. pip-audit
is not in the
devextra, so--withruns it from an ephemeral environment layered over theproject venv, and
--localrestricts the audit to that ephemeral environment: it auditspip-audit's own dependencies and none of the project's. The audit above therefore exports the
devextra from the lock instead. The workflow itself is unchanged here.