Skip to content

Bump soupsieve 2.8.4 → 2.10 in uv.lock (CVE-2026-85999, CVE-2026-86000) - #547

Merged
derek73 merged 1 commit into
masterfrom
claude/quirky-pasteur-ujc4xy
Sep 26, 2026
Merged

derek73 merged 1 commit into
masterfrom
claude/quirky-pasteur-ujc4xy

Conversation

@derek73

@derek73 derek73 commented Sep 26, 2026

Copy link
Copy Markdown
Owner

What

Clears the two Dependabot alerts against soupsieve 2.8.4 by bumping the lockfile to 2.10. This only touches uv.lock: three lines, all in the soupsieve entry.

CVE Issue Fixed in
CVE-2026-85999 Quadratic-time ReDoS when trimming trailing whitespace or comments from a CSS selector 2.9.0
CVE-2026-86000 Quadratic-time ReDoS from backtracking in the IDENTIFIER/VALUE selector regex 2.9.0

Exposure

Low. soupsieve is a docs-only transitive dependency (furo → beautifulsoup4 → soupsieve, in the dev group). nameparser has no runtime dependencies, so people who install it never got soupsieve. Both bugs also need a CSS selector supplied by an attacker, which Sphinx and furo never pass.

Notes

  • The lock was regenerated with uv lock --upgrade-package soupsieve (uv 0.12.19). No other package moved.
  • .github/dependabot.yml limits uv version updates to namedivider-python, which is probably why no Dependabot PR was opened for this. I've left that config unchanged.

Verification

  • pip-audit over uv export --all-groups --all-extras: 2 vulnerabilities before, none after.
  • sphinx-build -b html docs and sphinx-build -b doctest docs both exit 0 with soupsieve 2.10 installed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01AbTbV94Ns5AEacyG1BqRRi


Generated by Claude Code

Both CVEs are quadratic-time ReDoS in soupsieve's CSS selector compiler,
fixed in 2.9.0. soupsieve is a docs-only transitive dependency
(furo -> beautifulsoup4 -> soupsieve, dev group); nameparser has no
runtime dependencies, so installed users were never exposed. Lockfile-only
change; pip-audit over the exported lock is clean afterwards.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AbTbV94Ns5AEacyG1BqRRi
@derek73 derek73 self-assigned this Sep 26, 2026
@codecov

codecov Bot commented Sep 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.78%. Comparing base (e0f1a2f) to head (43b0d4c).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #547   +/-   ##
=======================================
  Coverage   98.78%   98.78%           
=======================================
  Files          45       45           
  Lines        3703     3703           
=======================================
  Hits         3658     3658           
  Misses         45       45           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@derek73
derek73 merged commit f6a79ec into master Sep 26, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants