Skip to content

Clear pip-audit: raise anyio and audit uv.lock - #57

Merged
crossjam merged 2 commits into
mainfrom
fix/anyio-audit
Sep 23, 2026
Merged

crossjam merged 2 commits into
mainfrom
fix/anyio-audit

Conversation

@crossjam

@crossjam crossjam commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

The blocking pip-audit step in QA has been failing on main since #56 (and on feat/datasette-readonly-enforcement). Lint, type checks and tests all passed; the audit flagged anyio 4.13.0:

Both are fixed in 4.14.2. anyio is transitive (via httpx, starlette and mcp, pulled in by pylast, datasette and datasette-mcp).

While in here, the audit itself was also fixed. It checked the installed environment, and pip-audit identifies installed packages by name and version only, so our loguru-config fork (a git source) was being matched against the unrelated loguru-config project on PyPI (erezinman/loguru-config).

Changes

  • uv.lock: anyio 4.13.0 → 4.14.2; no other packages moved.
  • pyproject.toml [tool.uv]: add anyio>=4.14.2 to constraint-dependencies, alongside the existing pip and msgpack floors, so a re-resolution can't drop back below the fix.
  • pyproject.toml audit poe task: audit uv.lock instead of the environment:
    set -o pipefail
    uv export --frozen --all-extras --all-groups --no-emit-project --no-hashes --quiet \
      | pip-audit --requirement /dev/stdin --disable-pip --no-deps
    • The fork now reaches pip-audit as a URL requirement and is skipped rather than checked against the wrong project.
    • --no-emit-project drops the "scrobbledb not on PyPI" skip notice.
    • Covers every extra and dependency group, slightly more than CI's uv sync installs.
    • pipefail makes a failed export fail the task instead of auditing an empty list as clean.

Trade-offs

  • pip-audit prints two warnings recommending hashed requirements; hashes can't be used because the git dependency has none.
  • The fork isn't checked for vulnerabilities at all. No advisory database covers it, so that's more accurate than checking the wrong project.

Verification

  • uv run poe audit: no known vulnerabilities found; loguru-config is the only skip.
  • Same export with anyio pinned back to 4.13.0: both CVEs reported, exit 1.
  • Corrupted uv.lock: the task exits 2.
  • uv run poe test:quick: 883 passed, 2 skipped.

feat/datasette-readonly-enforcement will need a rebase onto main once this lands.

🤖 Generated with Claude Code

anyio 4.13.0 carries CVE-2026-63374 and CVE-2026-64847, failing the
blocking audit step in QA. Upgrade the lock to the fixed release and add
a constraint floor so a future re-resolution cannot drop back below it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@crossjam crossjam self-assigned this Sep 23, 2026
@crossjam

Copy link
Copy Markdown
Owner Author

LGTM! Fire in the disco!

pip-audit identifies installed packages by name and version only, so it
matched our loguru-config fork (a git source) against the unrelated
loguru-config project on PyPI. Exporting the lockfile hands the fork to
pip-audit as a URL requirement, which it skips rather than misattributes,
and drops the scrobbledb self-audit notice. The export covers every extra
and group; pipefail keeps a failed export from passing as a clean audit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@crossjam crossjam changed the title Raise anyio to 4.14.2 to clear pip-audit Clear pip-audit: raise anyio and audit uv.lock Sep 23, 2026
@crossjam
crossjam merged commit 1a7344c into main Sep 23, 2026
4 checks passed
@crossjam
crossjam deleted the fix/anyio-audit branch September 23, 2026 00:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant