Fix embedded agent PyJWT, urllib3 and oauthlib vulnerabilities - #382
Merged
rb3ckers merged 7 commits intoOct 2, 2026
Merged
Conversation
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
rb3ckers
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The embedded agent currently installs PyJWT 2.13.0, urllib3 2.7.0 and oauthlib 3.3.1. Upgrade the source requirements and packaged agent input to PyJWT 2.15.0, urllib3 2.8.0 and oauthlib 4.0.0. Pin oauthlib explicitly for the Kubernetes/requests-oauthlib dependency path and preserve all other packaged runtime inputs.
Adopts the existing commits from #379, #380 and #381. Those PRs update development requirements only; this PR supplies the missing production pins. Agent #542 consumes this exact signed commit,
f50c336c6b23beb3f2e651dca558e1dba6a5781a, and exercises a maintained PyJWT options-reuse regression in the packaged images on both architectures. The producer candidate starts at the existing7.78.2-6release tree.Validation: full existing CI matrix 36991969024 is green, including dependency/metadata validation, every integration suite and workflow lint. The combined candidate passes 93 local Dynatrace tests and their lint checks; #379/#380/#381's individual successful PyJWT 2.15.0 CI remains reusable. The complete preserved agent requirements resolve with hashes, install successfully on BCI Python 3.13, and pass
pip check, the PyJWT regression and OAuth2Session/Kubernetes client smoke checks. Local Trivy rootfs scanning of that full installed environment identifies all three fixed package versions with zero of the 18 assigned Python CVEs; the same database detects all 18/18 against the original-version control. The companion agent's complete native Omnibus/image CI is green. Actual AMD64 and ARM64 DEBs contain PyJWT 2.15.0, urllib3 2.8.0 and oauthlib 4.0.0; their extracted rootfs scans have zero of the 18 assigned Python CVEs without VEX filtering. Both native image startup/security suites pass all three maintained tests, and both image Trivy reports contain none of these findings. Artifact digests and existing job links are recorded in agent #542.Scope is the Trivy-only Python findings in cve-reporter run 36983036771/1, verified aggregate digest
sha256:600d791947fc21560ab206d820e80af13dab87d0de836377c73cda6046e96345. PyJWT CVE-2026-103001 has no fixed-version field but bounds affected versions through 2.13.0; its options-reuse regression passes on 2.15.0 and fails on 2.13.0. Grype scanning and all existing CI gates remain unchanged. This PR adds no VEX statements, ignore rules, suppressions or exceptions. Only the assigned Trivy findings are remediated; Grype findings remain visible in scans. Any gate failure caused solely by Grype findings must be reported rather than bypassed. Merge and production release/adoption require human approval; this is source/candidate remediation rather than delivery closure.