Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 19 additions & 10 deletions backend/pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -146,21 +146,30 @@ ignore = ["B008", "UP045"]
# accepted by fastapi's starlette range (uv resolves cleanly). Remove once
# fastapi's own pin moves past 1.3.1.
#
# pip: PYSEC-2026-196 (fixed in 26.1.2). Present only because pip-audit
# (our dev-time scanner) pulls pip in to resolve deps, then --strict audits
# pip itself. Advisory landed ~2026-06 and turned the scan red even though
# no code changed. Dev/CI surface only — pip isn't shipped in the app
# image. Remove once pip-audit's own pin clears 26.1.2.
# pip: PYSEC-2026-196 (fixed in 26.1.2), then PYSEC-2026-3721 (fixed in
# 26.2, landed ~2026-08). Present only because pip-audit (our dev-time
# scanner) pulls pip in to resolve deps, then --strict audits pip itself.
# Dev/CI surface only — pip isn't shipped in the app image. Remove once
# pip-audit's own pin clears 26.2.
constraint-dependencies = [
"authlib>=1.7.1",
"urllib3>=2.7.0",
"idna>=3.15",
"starlette>=1.3.1",
"pip>=26.1.2",
# cryptography: GHSA-537c-gmf6-5ccf (fixed in 48.0.1). Transitive via
# clerk-backend-api / authlib. Remove once a direct dep's own pin
# clears cryptography 48.0.1.
"cryptography>=48.0.1",
"pip>=26.2",
# cryptography: GHSA-537c-gmf6-5ccf (fixed in 48.0.1), then three more
# advisories — PYSEC-2026-3552 (fixed in 50.0.0), PYSEC-2026-3553 +
# PYSEC-2026-3554 (both fixed in 49.0.0). 50.0.0 satisfies all of
# them. Transitive via clerk-backend-api / authlib. clerk-backend-api
# 6.0.1 caps cryptography <49.0.0, so this floor forces clerk to 7.0.0
# (released 2026-08-11 to raise the cap to <51.0.0). Remove once a
# direct dep's own pin clears cryptography 50.0.0.
"cryptography>=50.0.0",
# click: PYSEC-2026-2132 (fixed in 8.3.3, landed ~2026-08). Transitive
# via uvicorn (which depends on click). Not a direct dep — surfaced
# purely because pip-audit --strict audits the whole resolved tree.
# Remove once uvicorn's own pin clears click 8.3.3.
"click>=8.3.3",
# joserfc: CVE-2026-48990 (fixed in 1.6.7). Transitive via
# clerk-backend-api. Remove once clerk's own pin clears 1.6.7.
"joserfc>=1.6.7",
Expand Down
Loading