- backend/requirements.txt : plancher urllib3>=2.8.0 (3 CVE corrigées) - .gitea/workflows/ci.yml : documentation des nouveaux planchers - tests/test_ci_workflow.py : garde-fou urllib3 ajouté dans TestDependencySecurityFloors Corrige l'échec du job security (pip-audit bloquant sur urllib3 2.7.0)
42 lines
1.2 KiB
Plaintext
42 lines
1.2 KiB
Plaintext
fastapi==0.141.1
|
|
uvicorn==0.54.0
|
|
websockets>=12.0
|
|
python-frontmatter==1.1.0
|
|
mistune==3.3.3
|
|
python-multipart==0.0.31
|
|
aiofiles==23.2.1
|
|
aiohttp>=3.9.0
|
|
watchdog>=4.0.0
|
|
argon2-cffi>=23.1.0
|
|
python-jose>=3.3.0
|
|
sortedcontainers>=2.4.0
|
|
snowballstemmer>=2.2.0
|
|
weasyprint>=70.0
|
|
httpx>=0.27.0
|
|
# Plancher de sécurité (BUG-093) : 6.16.0 est vulnérable à deux DoS de
|
|
# ressources (PYSEC-2026-3910 outlines, PYSEC-2026-3911 XForm, fix 6.16.1),
|
|
# atteignables via backend/pdf_reader.py (PDF fournis par l'utilisateur).
|
|
# Le plancher doit être >= 6.16.1 : l'image Act du runner embarque 6.16.0
|
|
# dans sa toolcache Python, donc un plancher trop bas est « already satisfied »
|
|
# et n'est jamais mis à niveau.
|
|
pypdf>=6.16.1
|
|
pyotp>=2.10.0
|
|
segno>=1.5.0
|
|
webauthn==2.6.0
|
|
psutil>=5.9
|
|
pywebpush>=2.3.0
|
|
mcp==1.28.1
|
|
# Plancher de sécurité (BUG-091, BUG-095) : pyjwt est une dépendance transitive
|
|
# (mcp). 2.12.x → PYSEC-2026-178 (fix 2.13.0) ; 2.13.0 → CVE-2026-102274
|
|
# (fix 2.14.0). pip-audit étant bloquant, on reste au-dessus du dernier correctif.
|
|
pyjwt[crypto]>=2.14.0
|
|
sse-starlette==2.1.3
|
|
openpyxl>=3.1
|
|
xlrd==2.0.2
|
|
odfpy==1.4.1
|
|
python-docx>=1.1
|
|
reportlab>=4.0
|
|
pillow>=10.0
|
|
# Plancher urllib3 >= 2.8.0 (CVE-2026-97687, CVE-2026-97688, CVE-2026-97689)
|
|
urllib3>=2.8.0
|