From 819ac7961dae1ac317c015618cc624dcaeddccff Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 02:12:38 +0000 Subject: [PATCH 1/4] Bump pyjwt from 2.13.0 to 2.15.0 in /dynatrace_base Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] --- dynatrace_base/requirements-dev.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dynatrace_base/requirements-dev.txt b/dynatrace_base/requirements-dev.txt index 81b9dbd7..81d2c6c5 100644 --- a/dynatrace_base/requirements-dev.txt +++ b/dynatrace_base/requirements-dev.txt @@ -1,3 +1,3 @@ -e ../stackstate_checks_dev requests-mock==1.9.3 -pyjwt==2.13.0 +pyjwt==2.15.0 From 0d55ce8a75c546511576d39faaee88f8786697c6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 02:18:08 +0000 Subject: [PATCH 2/4] Bump pyjwt from 2.13.0 to 2.15.0 in /dynatrace_health Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] --- dynatrace_health/requirements-dev.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dynatrace_health/requirements-dev.txt b/dynatrace_health/requirements-dev.txt index 214f0b58..e74f3e21 100644 --- a/dynatrace_health/requirements-dev.txt +++ b/dynatrace_health/requirements-dev.txt @@ -1,4 +1,4 @@ -e ../stackstate_checks_dev requests-mock==1.9.3 freezegun -pyjwt==2.13.0 +pyjwt==2.15.0 From 47163840dc2dc4656f4795f70e360c83c271b0fd Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 07:31:52 +0000 Subject: [PATCH 3/4] Bump pyjwt from 2.13.0 to 2.15.0 in /dynatrace_topology Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](https://github.com/jpadilla/pyjwt/compare/2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] --- dynatrace_topology/requirements-dev.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dynatrace_topology/requirements-dev.txt b/dynatrace_topology/requirements-dev.txt index ea4562cf..984b8ff1 100644 --- a/dynatrace_topology/requirements-dev.txt +++ b/dynatrace_topology/requirements-dev.txt @@ -1,4 +1,4 @@ -e ../stackstate_checks_dev requests-mock==1.9.3 deepdiff~=8.6.2 -pyjwt==2.13.0 +pyjwt==2.15.0 From f50c336c6b23beb3f2e651dca558e1dba6a5781a Mon Sep 17 00:00:00 2001 From: "SUSE Observability AI (POC)" Date: Fri, 2 Oct 2026 09:49:03 +0000 Subject: [PATCH 4/4] Pin fixed PyJWT, urllib3 and oauthlib in the agent runtime --- README.md | 4 ++++ splunk_base/requirements.in | 2 +- splunk_metric/requirements.in | 2 +- stackstate_checks_base/requirements.in | 3 ++- .../stackstate_checks/base/data/agent_requirements.in | 5 +++-- 5 files changed, 11 insertions(+), 5 deletions(-) diff --git a/README.md b/README.md index a391f0b4..57c8a878 100644 --- a/README.md +++ b/README.md @@ -36,6 +36,10 @@ After defining the dependencies which the check needs in `/requireme this will update the `agent_requirements.in` file to be used by the stackstate-agent build. +Review the generated diff before committing: `dep freeze` collects the active +checks' requirements only. Preserve additional runtime pins already in +`agent_requirements.in` when they are still required by the packaged agent. + ## Manual testing Use the `checksdev env` command to do manual testing. Testing always happens in an environment, to list all environments run: diff --git a/splunk_base/requirements.in b/splunk_base/requirements.in index 2bff4105..68d2b246 100644 --- a/splunk_base/requirements.in +++ b/splunk_base/requirements.in @@ -1,3 +1,3 @@ pytz==2021.1 iso8601==0.1.14 -PyJWT==2.13.0 +PyJWT==2.15.0 diff --git a/splunk_metric/requirements.in b/splunk_metric/requirements.in index 4a58ed71..8839f583 100644 --- a/splunk_metric/requirements.in +++ b/splunk_metric/requirements.in @@ -1,3 +1,3 @@ pydantic==2.12.5 -PyJWT==2.13.0 +PyJWT==2.15.0 docker==6.1.3 diff --git a/stackstate_checks_base/requirements.in b/stackstate_checks_base/requirements.in index c0ead270..d3fa9dae 100644 --- a/stackstate_checks_base/requirements.in +++ b/stackstate_checks_base/requirements.in @@ -4,7 +4,8 @@ prometheus-client==0.24.1; python_version > '3.0' protobuf==6.33.5; python_version > '3.0' pywin32==306; sys_platform == 'win32' and python_version > '3.0' requests==2.33.0; python_version > '3.0' -urllib3==2.7.0 +urllib3==2.8.0 +oauthlib==4.0.0; python_version > '3.0' simplejson==3.20.1 six==1.16.0 uuid==1.30 diff --git a/stackstate_checks_base/stackstate_checks/base/data/agent_requirements.in b/stackstate_checks_base/stackstate_checks/base/data/agent_requirements.in index 84e17de7..ff1bded4 100644 --- a/stackstate_checks_base/stackstate_checks/base/data/agent_requirements.in +++ b/stackstate_checks_base/stackstate_checks/base/data/agent_requirements.in @@ -8,6 +8,7 @@ enum34==1.1.10; python_version < "3.0" flatten-dict==0.2.0 iso8601==0.1.14 kubernetes==35.0.0; python_version > '3.0' +oauthlib==4.0.0; python_version > '3.0' orionsdk==0.3.0 orjson==3.11.7; python_version > '3.0' pg8000==1.31.5 @@ -17,7 +18,7 @@ psutil==6.0.0 psycopg2-binary==2.9.9; python_version > '3.0' pymysql==1.1.2; python_version > '3.0' pynag==1.1.2 -PyJWT==2.13.0 +PyJWT==2.15.0 pytz==2021.1 pywin32==306; sys_platform == 'win32' and python_version > '3.0' pyyaml==6.0.2; python_version > '3.0' @@ -26,7 +27,7 @@ requests==2.33.0; python_version > '3.0' pydantic==2.12.5 simplejson==3.20.1 six==1.16.0 -urllib3==2.7.0 +urllib3==2.8.0 uuid==1.30 pyvmomi==9.1.0.0 vmware-vapi-common-client==9.1.0.0