Skip to content

fix: bump mako 1.4.2, fsspec 2026.6.0, pymongo 4.18.2 (CVE-2026-102991) - #468

Open
scale-prodsec[bot] wants to merge 1 commit into
mainfrom
vulnmanagementagent/gfdvr-163617-trivy-remediate-mako1312-vulnerabilities
Open

scale-prodsec[bot] wants to merge 1 commit into
mainfrom
vulnmanagementagent/gfdvr-163617-trivy-remediate-mako1312-vulnerabilities

Conversation

@scale-prodsec

@scale-prodsec scale-prodsec Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

  • uv.lock only: mako 1.3.12 -> 1.4.2, fsspec 2025.9.0 -> 2026.6.0, pymongo 4.15.1 -> 4.18.2 (lowest OSV-clean releases at/above the fixed floors; 4.18.2 covers 4.18.1 and 4.18.2).
  • Lock revision (3) preserved by using uv 0.9.5 (0.7.x rewrote it to revision 2).

Coverage

Tickets: GFDVR-163617, GFDVR-163618, GFDVR-163619
CVEs: CVE-2026-102991, CVE-2026-104851, CVE-2026-88029, CVE-2026-96748, CVE-2026-96747, CVE-2026-96749

Validation

  • uvx uv@0.9.5 lock --upgrade-package ... moved exactly 3 packages; uv lock --check passes
  • bot.version_gate (OSV): zero known advisories for all three targets
  • Fresh venv with the three versions: imports of mako.template, fsspec, pymongo AsyncMongoClient/AsyncCollection/OperationFailure (the agentex consumers) succeed
  • fsspec/mako have no direct first-party imports in agentex/src; pymongo usage is the async API only
  • git diff --check clean; only uv.lock changed

@scale-prodsec
scale-prodsec Bot requested a review from a team as a code owner October 6, 2026 07:48
@greptile-apps

greptile-apps Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

No reviewable files after applying ignore patterns.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​pymongo@​4.15.1 ⏵ 4.18.291100 +24100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant