Skip to content

chore(security): remediate OSV findings - #967

Draft
peco-engineer-bot[bot] wants to merge 1 commit into
mainfrom
ai/security-scan-remediation
Draft

peco-engineer-bot[bot] wants to merge 1 commit into
mainfrom
ai/security-scan-remediation

Conversation

@peco-engineer-bot

Copy link
Copy Markdown
Contributor

Summary

Automated remediation for findings from the weekly OSS driver security scan.

Updates:

  • pyjwt@2.13.0 -> patched Poetry resolution
  • urllib3@2.7.0 -> patched Poetry resolution

Needs maintainer follow-up:

  • pyjwt (GHSA-gvp8-978c-rx2q, PYSEC-2026-4146): no fixed version or safe automatic action
  • oauthlib@3.3.1: Poetry constraints did not resolve every vulnerable oauthlib version to its fix floor

The repository's Security Scan check is the authoritative validation. This PR is draft until that check and the normal driver CI pass.

Source: https://github.com/databricks/databricks-driver-test/actions/runs/37187456062

Signed-off-by: peco-engineer-bot[bot] <287056288+peco-engineer-bot[bot]@users.noreply.github.com>
@peco-engineer-bot peco-engineer-bot Bot added the skip-coverage Skip the coverage fan-out for this PR (no tracking issue opened in databricks-driver-test) label Oct 4, 2026

This branch was successfully deployed

1 active deployment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-assisted skip-coverage Skip the coverage fan-out for this PR (no tracking issue opened in databricks-driver-test)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants