Skip to content

fix(security): floor litellm/wandb/lxml past known CVEs; relax stale click cap - #1507

Open
nicgupta-nvidia wants to merge 27 commits into
mainfrom
fix/security-dependency-floors
Open

nicgupta-nvidia wants to merge 27 commits into
mainfrom
fix/security-dependency-floors

Conversation

@nicgupta-nvidia

@nicgupta-nvidia nicgupta-nvidia commented Jul 9, 2026 •

Copy link
Copy Markdown
Collaborator

What

Remediates the fixable Critical/High dependency findings observed across the NeMo-Skills repository and container scans, while retaining the earlier LiteLLM, GitPython, datamodel-code-generator, lxml, aiohttp, msgpack, and setuptools fixes already carried by this PR.

The branch head is based on merge base cb54e911. At the September 8 live-base revalidation, main was 0ce744ab; this PR was 26 commits ahead and 1 behind, and GitHub generated the conflict-free merge ref f098f788 from that base and the exact PR head.

September 4 security refresh

A fresh scan of nvcr.io/0953339617667984/nvflow-nemo-skills:v1.1.3-ray found 2 Critical and 14 High instances on amd64. Fifteen were fixable; the remaining High (CVE-2026-81726 in NLTK) has no fixed release.

Component Scanned version Fixed version Fixable findings
NLTK 3.10.2 3.10.3 1 Critical, 2 High
W&B wandb-core Go stdlib Go 1.26.5 Go 1.26.6 8 High
W&B wandb-core x/crypto 0.54.0 0.55.0 1 Critical
W&B wandb-core go-git 5.19.1 5.19.2 1 High
W&B wandb-core x/image 0.44.0 0.45.0 1 High
W&B wandb-core gRPC 1.82.1 1.83.1 1 High
Total 2 Critical, 13 High

The NLTK floor is enforced in [tool.uv].override-dependencies, the stem requirements, the container install, and static/functional regression checks.

W&B 0.28.1 ships a vulnerable release binary, so the Dockerfile rebuilds only wandb-core from the pinned W&B commit. The build rejects the binary unless go version -m reports:

  • Go 1.26.6
  • go-git 5.19.2
  • x/crypto 0.55.0
  • x/image 0.45.0
  • x/text 0.41.0
  • gRPC 1.83.1

Only the verified executable is copied into the runtime image; the Go toolchain and source are not retained.

The runtime image also replaces /usr/local with the fully resolved dependency artifact and removes pip's build-input CycloneDX BOM. This prevents stale pre-resolution metadata and build-only dependencies from being reported as runtime vulnerabilities.

Earlier security scope retained

  • litellm[caching]==1.84.10 for GHSA-4xpc-pv4p-pm3w
  • GitPython>=3.1.58
  • datamodel-code-generator>=0.64.0, including the BFCL runtime pin
  • lxml>=6.1.0
  • aiohttp>=3.14.3, including Ray's private vendored copy
  • msgpack>=1.2.1
  • setuptools>=78.1.1
  • wandb==0.28.1, paired with the patched core
  • click cap removal and typer>=0.16
  • removal of uv's build-only Git cache and build-SBOM false positives

Verified validation

Source:

  • exact pushed head: a20c5bad7266d4947447f3a72507573a2bfecac9
  • September 4 main snapshot and current merge base: cb54e911ad5b2cee87444fc89656fabca021c8cc (the PR was then 26 ahead, 0 behind)
  • Trivy 0.73.0, September 4 vulnerability database (UpdatedAt 2026-09-04T13:08:55.575059601Z)
  • September 4 main-snapshot tracked-source scan: 0 vulnerabilities (report SHA-256 57aaff384ade15f4921fecc01930279105e085b5cba2da0e28314ddb2af1df36)
  • exact-PR-head tracked-source scan: 0 vulnerabilities (report SHA-256 352340141f93c4bed5be69fd93ee764e38464b27728ac97597dfa9be2d8f31fb)
  • static security regression suite: 45 passed
  • NLTK 3.10.3 version/parser smoke: passed

Multi-architecture image:

  • combined tag: nvcr.io/0953339617667984/nvflow-nemo-skills:pr1507-a20c5bad-security-20260904
  • combined index: sha256:6f98043019f5972daf592533d7324644ded4312283e768f28727d1c5470b2c94
  • exactly two runtime manifests: Linux/amd64 sha256:ebca9c4ba99898e20ee21e8cd7662c65d99178a2f0d2ca02d01a8d19d37a6373; Linux/arm64 sha256:3c0aabf388e30a7020c7fa376818b0e06f137f8b00a28c3e52fc71af32cb2007
Platform Critical High Medium Low Unknown Fixable C/H Report SHA-256
Linux/amd64 0 1 597 128 3 0 a0b1ec69429f3a7a01c1b06d834b51ad5be98ff65e49633fe4cac955be4eb8c7
Linux/arm64 0 1 594 126 3 0 319649fecbed007c94fac98c05a759f78ac77e640728cd43ab4fb750115a7532

All final NLTK, W&B module, dependency-metadata, architecture, and cleanup assertions passed. The sole remaining High on each platform is unfixed NLTK CVE-2026-81726; it is intentionally not hidden or ignored.

CI status

DCO, pre-commit, and copyright checks pass. Both manually built image architectures and their security/runtime gates pass. The only failing hosted check is CPU tests / unit-tests: 754 passed, 1 skipped, 37 deselected, and 7 failed. Its log confirms the external endpoint returns HTTP 410 Gone because nvidia/nemotron-3-nano-30b-a3b reached end of life at 2026-09-01T09:00:00Z; the seven failures are downstream missing-output or summarization failures from that response. The affected test files are unchanged by this PR, and an unrelated current PR has the same seven failures. This is not a dependency or container regression from this PR.

September 8 fresh-database revalidation

Trivy 0.73.0 was rerun with vulnerability DB UpdatedAt 2026-09-08T07:08:01.235696926Z against the exact source revisions and immutable amd64/arm64 manifests. Severity columns are Critical / High / Medium / Low / Unknown.

Artifact Result Fixable C/H Report SHA-256
merge base cb54e911 source 0 / 0 / 0 / 0 / 0 0 c683a89c8bfc51c682ef15e16953065d41b8378dc766a30d2c4286b959962c48
live main 0ce744ab source 0 / 0 / 0 / 0 / 0 0 a289fb31978dd8c605a3b7c44844e67ff504e4749d01c8db4199967baee3bde4
PR head a20c5bad source 0 / 0 / 0 / 0 / 0 0 655ef24082cd43241a13722b5c8f101498ef4b231e0fb22db1004ece6cbdedf2
conflict-free merge ref f098f788 source 0 / 0 / 0 / 0 / 0 0 2f1ec91eed350824c93c51ff2fc6f0ce346a029618204c6a96b1a19d53e07624
PR worker amd64 0 / 1 / 647 / 128 / 3 0 75398905f9072cbd2579ccc14f12c41f661b8f5aee0d815b15d46fb245a7464f
PR worker arm64 0 / 1 / 644 / 126 / 3 0 4225e2829a2acf028ca170e24b5ebb4a64df82037231a0300186fce1007dc9b5

Every remaining image High is CVE-2026-81726 in NLTK 3.10.3, for which Trivy reports no fixed version. No additional Critical/High code change was required by the September 8 refresh.

@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Dependency requirements now include security floors and compatibility pins, BFCL uses the updated code generator version, Nemo Skills builds and installs a pinned W&B core binary, and regression plus functional tests validate the updated dependency behavior.

Changes

Dependency security and compatibility updates

Layer / File(s) Summary
Dependency constraints and BFCL pin
core/requirements.txt, requirements/stem.txt, requirements/common-tests.txt, nemo_skills/inference/eval/bfcl.py
Adds security minimums for GitPython, datamodel-code-generator, and lxml; constrains MCP and W&B versions; adds Python 3.10 TOML support; and updates the BFCL code generator pin.
Patched W&B core image integration
dockerfiles/Dockerfile.nemo-skills
Builds wandb-core from a pinned commit, verifies Go dependency versions, installs dependencies through the project configuration, and replaces the bundled binary.
Requirement and Docker regression coverage
tests/test_requirements_versions.py
Validates dependency floors and pins, BFCL compatibility, W&B core build metadata, pipeline compatibility assertions, stem requirements, and PEP 508 parsing.
Functional dependency compatibility tests
tests/test_dependency_functional.py
Adds GitPython and datamodel-code-generator checks while retaining functional coverage for litellm, CLI behavior, W&B offline operation, and lxml parsing.

Estimated code review effort: 4 (Complex) | ~45 minutes

Possibly related PRs

Suggested reviewers: gwarmstrong

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 42.86% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary security-related dependency changes, including litellm, wandb, lxml, and the stale click cap.
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🛠️ Fix failing CI checks 💡
  • Fix failing CI checks
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/security-dependency-floors

Comment @coderabbitai help to get the list of available commands.

@nicgupta-nvidia nicgupta-nvidia self-assigned this Jul 9, 2026
@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Note

Unit test generation is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it.


Generating unit tests... This may take up to 20 minutes.

2 similar comments
@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Note

Unit test generation is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it.


Generating unit tests... This may take up to 20 minutes.

@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Note

Unit test generation is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it.


Generating unit tests... This may take up to 20 minutes.

@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

✅ Unit tests committed locally. Commit: 07acd2ccc5aed23517851655d7112cfb704e9b7b

@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

✅ Unit tests committed locally. Commit: e441a66eb09f718a0d49194cedc6abf56d9763e7

@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

✅ Created PR with unit tests: #1508

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
tests/test_requirements_versions.py (1)

95-96: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Extract a shared helper for specifier-floor extraction.

The {spec.operator: spec.version for spec in req.specifier} pattern is repeated across four test methods. A small helper reduces duplication and keeps the assertions consistent if the extraction logic ever needs to change (e.g., handling multiple specifiers of the same operator).

♻️ Proposed helper
+def _get_specifier(req: Requirement, operator: str) -> Version:
+    """Return the parsed Version for the given specifier operator, asserting it's present."""
+    specs = {spec.operator: spec.version for spec in req.specifier}
+    assert operator in specs, f"expected a '{operator}' specifier for {req.name}, got {req.specifier}"
+    return Version(specs[operator])
+
+
 class TestCoreRequirements:
     ...
     def test_litellm_pin_fixes_ghsa_4xpc_pv4p_pm3w(self):
         req, comment = _find_requirement(CORE_REQUIREMENTS, "litellm")
         assert "caching" in req.extras, "litellm[caching] extra must be preserved"
-
-        # Must be pinned to an exact version (== specifier) so the resolver is deterministic.
-        specs = {spec.operator: spec.version for spec in req.specifier}
-        assert "==" in specs, f"expected an exact pin for litellm, got specifier {req.specifier}"
-
-        pinned_version = Version(specs["=="])
+        pinned_version = _get_specifier(req, "==")

Also applies to: 113-114, 156-157, 178-179

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/test_requirements_versions.py` around lines 95 - 96, The specifier
extraction logic is duplicated across multiple test methods in the requirements
version tests, so add a shared helper for turning a requirement’s specifiers
into a usable mapping or floor value. Update the affected assertions in the test
class that currently build specs from req.specifier so they call this helper
instead, keeping the exact-pin checks unchanged while centralizing the
extraction behavior in one place.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@tests/test_requirements_versions.py`:
- Around line 95-96: The specifier extraction logic is duplicated across
multiple test methods in the requirements version tests, so add a shared helper
for turning a requirement’s specifiers into a usable mapping or floor value.
Update the affected assertions in the test class that currently build specs from
req.specifier so they call this helper instead, keeping the exact-pin checks
unchanged while centralizing the extraction behavior in one place.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 0ea160ee-449e-4976-b41b-78cdb3607f1a

📥 Commits

Reviewing files that changed from the base of the PR and between 49cd94e and 01bd214.

📒 Files selected for processing (2)
  • requirements/common-tests.txt
  • tests/test_requirements_versions.py

gwarmstrong added a commit that referenced this pull request Jul 28, 2026
Cherry-picked from #1507 (fix/security-dependency-floors), which is the
last configuration in which the full CPU suite passed (725 passed, 0
failed on 2026-07-14).

With click pinned below 8.2 the ns CLI stops accepting underscore-style
option names, so every test that shells out to `ns eval --output_dir=...`
or `ns summarize_results --max_seq_len=...` fails with "Missing option
'--output-dir'" / "No such option: --max_seq_len". The typer floor moves
to 0.16 alongside it because that is the first release compatible with
click 8.2 (fixes the make_metavar break that motivated the original pin).

Only the CLI-relevant pair is taken here. #1507's litellm, wandb and stem
security floors are left to that PR.

Signed-off-by: gwarmstrong <gwarmstrong@users.noreply.github.com>
gwarmstrong added a commit that referenced this pull request Jul 28, 2026
Dropping the click<8.2 cap alone was not enough: wandb 0.26.1 only
requires click>=8.0.1, so uv still settled on click 8.1.8 and the CPU
suite failed identically (10 failed, 685 passed).

wandb 0.27.1 is the first release requiring click>=8.2.0, which is what
actually moves the resolver. Taken from #1507, the last configuration in
which the full suite passed.

Signed-off-by: gwarmstrong <gwarmstrong@users.noreply.github.com>
gwarmstrong added a commit that referenced this pull request Jul 28, 2026
This is the actual root cause of the CPU suite failures, and the reason
removing the repo's own `click < 8.2.0` cap changed nothing: litellm
1.83.14 declares an exact `click==8.1.8` dependency, capping the entire
tree below click 8.2 regardless of what this repo asks for.

uv spelled it out when wandb>=0.27.1 was added:

    Because wandb>=0.27.1 depends on click>=8.2.0 and litellm==1.83.14
    depends on click==8.1.8, we can conclude that litellm==1.83.14 and
    wandb>=0.27.1 are incompatible.

litellm 1.84.10 relaxes that to click>=8.0.0,<9.0 (and clears
GHSA-4xpc-pv4p-pm3w). With it, `uv pip install -e .[dev]` resolves to
click 8.4.2 / typer 0.27.0 / wandb 0.28.1.

Taken from #1507 together with the wandb floor and the click cap removal;
the three only work as a set.

Signed-off-by: gwarmstrong <gwarmstrong@users.noreply.github.com>
@nicgupta-nvidia
nicgupta-nvidia enabled auto-merge (squash) July 30, 2026 16:34
@nicgupta-nvidia

Copy link
Copy Markdown
Collaborator Author

August 6 High-severity follow-up (commit 75d0c6a):

  • Floors aiohttp>=3.14.3 for CVE-2026-69244.
  • Replaces Ray runtime-env agent’s private aiohttp 3.14.1 copy with the fixed package from the same architecture. Ray 2.56.1 still bundles 3.14.1, so a Ray-only bump is insufficient.
  • Removes uv’s embedded build SBOM from the runtime image. That SBOM describes uv build dependencies (msgpack 1.1.2, setuptools 70.3.0) even though the image actually installs msgpack 1.2.1 and setuptools 83.0.0, causing two false-positive High findings.
  • Scope is High findings only; no Medium or Low remediation is included.

Focused validation: 35 security tests passed, Ruff lint/format passed (excluding one pre-existing C408 on an untouched line), the Ray private import resolved aiohttp 3.14.3, and the SBOM cleanup was exercised. A rebuilt multi-architecture image and fresh Trivy scan remain the final image-level verification.

@nicgupta-nvidia
nicgupta-nvidia force-pushed the fix/security-dependency-floors branch 2 times, most recently from a20c5ba to 70256e1 Compare September 10, 2026 18:37
nicgupta-nvidia and others added 10 commits September 11, 2026 14:30
…click cap

- litellm[caching] 1.83.14 -> 1.84.10: GHSA-4xpc-pv4p-pm3w (Critical) —
  1.83.x leaks the API key to an arbitrary attacker-controlled Host header;
  fixed in 1.84.0. Minimal exact-pin jump; resolves with the existing
  httpx[http2]>=0.28.1 override (litellm 1.84.10 needs httpx>=0.28.0).
- wandb -> >=0.27.1: the bundled wandb-core Go binary in older wheels ships
  golang.org/x/crypto 0.50.0 + Go 1.26.2 stdlib with 7 Critical / 13 High
  CVEs (incl. GHSA-x527-x647-q7gg et al.); 0.27.1 is the first release
  embedding patched x/crypto 0.52.0 (verified on both arches).
- click < 8.2.0 cap removed + typer >= 0.16: the cap guarded against the
  typer/click-8.2 make_metavar break (ai-dynamo/dynamo#1039, closed
  2025-06-26, fixed in typer >=0.16); wandb>=0.27.1 requires click>=8.2,
  and requires-python >=3.10 satisfies click 8.2's floor.
- lxml -> >=6.1.0 (stem extra): GHSA-vfmq-68hx-4jfw (High).

Validation: uv pip compile of core+pipeline (py3.10, with the pyproject
overrides) resolves cleanly — litellm 1.84.10 / wandb 0.28.0 / click 8.4.2 /
typer 0.26.8 / httpx 0.28.1; stem extra resolves with lxml 6.1.1. Runtime
smoke on the resolved set: litellm/wandb import clean; typer --help
rendering (the exact make_metavar crash path) passes under click 8.4.

Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
CodeRabbit's test generation ran twice and committed two near-duplicate
suites (test_dependency_pins.py + test_requirements_versions.py) covering
the same pins. Keep the more robust one (operator-keyed specifier parsing
instead of next(iter(specifier)), which is order-fragile on multi-spec
requirements) and graft the three tests unique to the deleted file:
pyproject stale-comment guards, pipeline-lines-parseable, and the
wandb/typer click-comment consistency check.

Also:
- fix the copyright year (2026, not 2025)
- add tomli (python_version < 3.11) to common-tests.txt so the pyproject
  override tests actually RUN on the CI's Python 3.10 instead of
  silently skipping (tomllib is stdlib only from 3.11)
- add the missing trailing newline that failed the pre-commit
  end-of-file-fixer hook on the generated files

17 tests pass on Python 3.10 with the CI's -m 'not gpu' selection;
pre-commit (pinned ruff) clean.

Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
…ed deps

test_requirements_versions.py only asserts the pins statically. Add functional
coverage that drives litellm 1.84.10, typer/click, and wandb through NeMo-Skills'
own code paths (CPU-only, hermetic — no sandbox, no live endpoint, no API keys)
so a resolve to a behavior-divergent version fails CI, not a production run:

  * litellm: OpenAIModel.litellm_kwargs binds api_key to the configured
    base_url/api_base only (GHSA-4xpc-pv4p-pm3w regression), generate_async
    calls litellm.acompletion with those credentials and parses the 1.84
    response, and the imported litellm exception/type surface still exists.
  * typer/click: ns CLI --help + per-command help render Parameter.make_metavar
    (the click 8.2 break typer>=0.16 fixes) and unknown commands are usage errors.
  * wandb: log_random_samples matches the wandb 0.28 init/save/summary/finish
    contract, and a real offline init/finish cycle runs with no account.
  * lxml: importorskip-guarded real parse (optional stem extra).

Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
@nicgupta-nvidia
nicgupta-nvidia force-pushed the fix/security-dependency-floors branch from 70256e1 to 94d105c Compare September 11, 2026 18:39
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
@nicgupta-nvidia
nicgupta-nvidia force-pushed the fix/security-dependency-floors branch from 94d105c to da8459a Compare September 11, 2026 18:45
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
@nicgupta-nvidia

Copy link
Copy Markdown
Collaborator Author

Merge-blocker status update (September 14):

  • This branch contains current main (bcf059af55c20a89f797724598f9908d126153e6) and is 0 commits behind, with no merge conflicts.
  • There are no unresolved review threads.
  • Required checks are green: CPU tests (761 passed), pre-commit, copyright, and DCO. The GPU check is intentionally skipped by its workflow rules.
  • GitHub reports the current head (87367bb1cf1e305e22cb8c5d238004bd67da4113) as mergeable.

@gwarmstrong A qualifying review is the only remaining merge blocker. A review is already requested; could you please review the current head when available?

Signed-off-by: Nick Gupta <nicgupta@nvidia.com>
@nicgupta-nvidia

Copy link
Copy Markdown
Collaborator Author

Added the October 2 Trivy refresh in commit b7e957b5b9702949ae7c0a05fea7b09ad0ee83c6.

Fresh scan results

Scanned the fully resolved runtime + dev graph for Linux Python 3.10 with Trivy 0.75.0 and the vulnerability database updated at 2026-10-02T12:48:00Z.

State Platform Critical High Fixable Critical/High
main baseline amd64 1 6 6
PR #1507 + update amd64 0 1 0
PR #1507 + update arm64 0 1 0

Remediated:

  • AnyIO 4.9.0 -> 4.15.1 (CVE-2026-63374; fixed in 4.14.2)
  • HTTPcore2/HTTPX2 2.6.0 -> 2.13.1 (CVE-2026-84381, CVE-2026-84382)
  • Starlette 0.52.1 -> 1.7.0 (CVE-2026-48818, CVE-2026-54283)
  • Prometheus FastAPI Instrumentator 7.0.0 -> 8.1.0 so the resolved instrumentator officially supports Starlette 1.x

The remaining High on both architectures is NLTK CVE-2026-81726; Trivy currently provides no fixed version.

The AnyIO and instrumentator floors are resolver overrides because LeptonAI 0.27.3 pins the affected/incompatible versions. HTTPcore2, HTTPX2, and Starlette use ordinary constraints. uv pip check reports only the three documented LeptonAI metadata overrides (AnyIO, the pre-existing HTTPX override, and instrumentator), with no other incompatibilities.

Validation

  • full runtime + dev resolution: Linux amd64 and arm64, Python 3.10
  • Python 3.10 imports for the security dependency stack and LeptonAI
  • Anthropic sync/async client construction and shutdown
  • instrumented FastAPI /health and /metrics requests: HTTP 200, expected request metric present
  • AnyIO async run and msgpack round trip
  • TOML policy assertion and git diff --check

Scan report SHA-256:

  • baseline amd64: 4bbbd2e8b73c64d97f485710fb0dca0f7a29e6e475d0148ffbc5e820853ddbd6
  • post-fix amd64: 4142d663350983e1535e233f8e79720f09a9dfde76e5b9051e8f22db24c2f17d
  • post-fix arm64: f67c53a5f238a117dcdec2acf25063b89468bb2dbdcf95f259d8b24cf223cf27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant