pip-audit bloquait sur PYSEC-2026-3910 (outlines) et PYSEC-2026-3911 (XForm), toutes deux atteignables via backend/pdf_reader.py. Le plancher pypdf>=4.0 ne protégeait rien : l'image Act du runner embarque 6.16.0 dans sa toolcache Python, donc pip répondait « already satisfied » sans jamais aligner. Au passage, le garde-fou TestSemgrepStep était en régression depuis la désactivation de semgrep (v2.39.9) et aurait rougi le job `test` : il vérifie désormais que l'étape n'exécute que son avertissement et que bandit et pip-audit restent bloquants. Nouveau TestDependencySecurityFloors pour verrouiller les planchers de sécurité (contre-preuve : pypdf remis à >=4.0). 🤖 Generated with Codebuff Co-Authored-By: Codebuff <[email protected]>
39 lines
1.1 KiB
Plaintext
39 lines
1.1 KiB
Plaintext
fastapi==0.141.1
|
|
uvicorn==0.54.0
|
|
websockets>=12.0
|
|
python-frontmatter==1.1.0
|
|
mistune==3.3.3
|
|
python-multipart==0.0.31
|
|
aiofiles==23.2.1
|
|
aiohttp>=3.9.0
|
|
watchdog>=4.0.0
|
|
argon2-cffi>=23.1.0
|
|
python-jose>=3.3.0
|
|
sortedcontainers>=2.4.0
|
|
snowballstemmer>=2.2.0
|
|
weasyprint>=70.0
|
|
httpx>=0.27.0
|
|
# Plancher de sécurité (BUG-093) : 6.16.0 est vulnérable à deux DoS de
|
|
# ressources (PYSEC-2026-3910 outlines, PYSEC-2026-3911 XForm, fix 6.16.1),
|
|
# atteignables via backend/pdf_reader.py (PDF fournis par l'utilisateur).
|
|
# Le plancher doit être >= 6.16.1 : l'image Act du runner embarque 6.16.0
|
|
# dans sa toolcache Python, donc un plancher trop bas est « already satisfied »
|
|
# et n'est jamais mis à niveau.
|
|
pypdf>=6.16.1
|
|
pyotp>=2.10.0
|
|
segno>=1.5.0
|
|
webauthn==2.6.0
|
|
psutil>=5.9
|
|
pywebpush>=2.3.0
|
|
mcp==1.28.1
|
|
# Plancher de sécurité (BUG-091) : pyjwt est une dépendance transitive (mcp) ;
|
|
# 2.12.x est vulnérable (PYSEC-2026-178, fix 2.13.0) et pip-audit bloque sinon.
|
|
pyjwt[crypto]>=2.13.0
|
|
sse-starlette==2.1.3
|
|
openpyxl>=3.1
|
|
xlrd==2.0.2
|
|
odfpy==1.4.1
|
|
python-docx>=1.1
|
|
reportlab>=4.0
|
|
pillow>=10.0
|