Skip to content

fix(deps): require patched pytest in Python dev groups - #56

Merged
locez merged 1 commit into
mainfrom
fix/pytest-tmpdir-advisory
Sep 15, 2026
Merged

locez merged 1 commit into
mainfrom
fix/pytest-tmpdir-advisory

Conversation

@locez

@locez locez commented Sep 15, 2026

Copy link
Copy Markdown
Owner

Resolves Dependabot alerts #4 and #5 (GHSA-6w46-j5rx-g56g, medium, CVSS 6.8).

pytest < 9.0.3 builds its tmp directory as /tmp/pytest-of-{user} on UNIX, which lets a local user cause a denial of service or possibly gain privileges. The pytest>=8,<9 dev constraint in sdks/python and benchmark made the patched release unreachable, so the floor is raised to the first fixed version and both lockfiles are regenerated: pytest 8.4.2 -> 9.1.1. No other locked package changed.

Verification, with pytest reporting 9.1.1:

  • sdks/python: uv sync --locked, maturin develop --features test-utils, ruff format --check, ruff check, ty check clean; pytest 53 passed; uv build produced wheel and sdist
  • benchmark: uv sync --locked, ruff check, ty check clean; pytest 16 passed

Both Dependabot alerts should close once this lands on main.

Dependabot alerts GHSA-6w46-j5rx-g56g report pytest < 9.0.3 in sdks/python/uv.lock and benchmark/uv.lock. On UNIX pytest relies on /tmp/pytest-of-{user} directories, so a local user can cause a denial of service or possibly gain privileges. The pytest>=8,<9 dev constraint made the patched release unreachable, so raise the floor to the first fixed version and regenerate both lockfiles (pytest 8.4.2 -> 9.1.1).

Verification: uv sync --locked succeeded for both projects; ruff and ty are clean; the suites pass under pytest 9.1.1 (53 passed in sdks/python, 16 passed in benchmark); uv build produced the wheel and sdist.
@locez
locez merged commit 34d894f into main Sep 15, 2026
8 checks passed
@locez
locez deleted the fix/pytest-tmpdir-advisory branch September 15, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant