Skip to content

fix(deps): bump pypdf, python-multipart, authlib, langsmith to fix CVEs#1250

Merged
eti-sre-cicd merged 1 commit intomainfrom
prebuild/fix/pypdf-authlib-langsmith-vulnerabilities
Apr 18, 2026
Merged

fix(deps): bump pypdf, python-multipart, authlib, langsmith to fix CVEs#1250
eti-sre-cicd merged 1 commit intomainfrom
prebuild/fix/pypdf-authlib-langsmith-vulnerabilities

Conversation

@sriaradhyula
Copy link
Copy Markdown
Member

Summary

  • Bump pypdf from 6.10.0 to 6.10.2 in constraint-dependencies across 19 pyproject.toml files (medium CVE)
  • authlib upgraded to 1.6.11 via transitive lock update (medium CVE)
  • langsmith upgraded to 0.7.31 via transitive lock update (medium CVE)
  • python-multipart upgraded to 0.0.26 via transitive lock update (medium CVE)
  • Final langchain-text-splitters lock file updated (jira agent)
  • Regenerated 38 uv.lock files including all mcp/ subworkspaces

Dependabot alerts addressed

Resolves ~149 of the 151 remaining open Dependabot alerts. The 2 remaining (scrapy DoS) have no upstream fix available.

Notes

Test plan

  • CI passes for all affected agents and RAG packages

Addresses remaining Dependabot security alerts (151 open):
- pypdf 6.10.0 → 6.10.2 (medium CVE)
- python-multipart, authlib (1.6.11), langsmith (0.7.31): transitive bumps via uv lock upgrade
- langchain-text-splitters: final remaining lock file updated

Changes:
- pypdf==6.10.2 in constraint-dependencies across 19 pyproject.toml files
- Regenerated 38 uv.lock files (incl. mcp/ subworkspaces) upgrading:
  pypdf, python-multipart, authlib, langsmith, langchain-text-splitters
- scrapy: no fix available upstream, left as-is

Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Sri Aradhyula <sraradhy@cisco.com>
@github-actions
Copy link
Copy Markdown
Contributor

✅ No proprietary content detected. This PR is clear for review!

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Dynamic Agents Docker Image Published

Repository: ghcr.io/cnoe-io/prebuild/caipe-dynamic-agents
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/caipe-dynamic-agents:fix-pypdf-authlib-langsmith-vulnerabilities-2

Test in Helm values

dynamic-agents:
  image:
    repository: ghcr.io/cnoe-io/prebuild/caipe-dynamic-agents
    tag: "fix-pypdf-authlib-langsmith-vulnerabilities-2"

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: jira
Repository: ghcr.io/cnoe-io/prebuild/mcp-jira
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-jira:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: confluence
Repository: ghcr.io/cnoe-io/prebuild/mcp-confluence
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-confluence:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Repository: ghcr.io/cnoe-io/prebuild/ai-platform-engineering
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/ai-platform-engineering:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: pagerduty
Repository: ghcr.io/cnoe-io/prebuild/mcp-pagerduty
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-pagerduty:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: victorops
Repository: ghcr.io/cnoe-io/prebuild/mcp-victorops
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-victorops:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: netutils
Repository: ghcr.io/cnoe-io/prebuild/mcp-netutils
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-netutils:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: splunk
Repository: ghcr.io/cnoe-io/prebuild/mcp-splunk
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-splunk:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Component: ingestors
Repository: ghcr.io/cnoe-io/prebuild/caipe-rag-ingestors
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/caipe-rag-ingestors:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: webex
Repository: ghcr.io/cnoe-io/prebuild/mcp-webex
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-webex:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: komodor
Repository: ghcr.io/cnoe-io/prebuild/mcp-komodor
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-komodor:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: argocd
Repository: ghcr.io/cnoe-io/prebuild/mcp-argocd
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-argocd:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@eti-sre-cicd eti-sre-cicd merged commit 8057ab1 into main Apr 18, 2026
89 checks passed
@eti-sre-cicd eti-sre-cicd deleted the prebuild/fix/pypdf-authlib-langsmith-vulnerabilities branch April 18, 2026 00:33
@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: backstage
Repository: ghcr.io/cnoe-io/prebuild/mcp-backstage
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/mcp-backstage:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Component: server
Repository: ghcr.io/cnoe-io/prebuild/caipe-rag-server
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/caipe-rag-server:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: github
Repository: ghcr.io/cnoe-io/prebuild/agent-github
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-2

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-github:fix-pypdf-authlib-langsmith-vulnerabilities-2

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: argocd
Repository: ghcr.io/cnoe-io/prebuild/agent-argocd
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-argocd:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Component: agent-ontology
Repository: ghcr.io/cnoe-io/prebuild/caipe-rag-agent-ontology
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/caipe-rag-agent-ontology:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: netutils
Repository: ghcr.io/cnoe-io/prebuild/agent-netutils
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-netutils:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: jira
Repository: ghcr.io/cnoe-io/prebuild/agent-jira
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-jira:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: aws
Repository: ghcr.io/cnoe-io/prebuild/agent-aws
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-aws:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: confluence
Repository: ghcr.io/cnoe-io/prebuild/agent-confluence
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-confluence:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: webex
Repository: ghcr.io/cnoe-io/prebuild/agent-webex
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-webex:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: slack
Repository: ghcr.io/cnoe-io/prebuild/agent-slack
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-slack:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: gitlab
Repository: ghcr.io/cnoe-io/prebuild/agent-gitlab
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-gitlab:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: splunk
Repository: ghcr.io/cnoe-io/prebuild/agent-splunk
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-splunk:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: weather
Repository: ghcr.io/cnoe-io/prebuild/agent-weather
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-weather:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: victorops
Repository: ghcr.io/cnoe-io/prebuild/agent-victorops
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-victorops:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: pagerduty
Repository: ghcr.io/cnoe-io/prebuild/agent-pagerduty
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-pagerduty:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: backstage
Repository: ghcr.io/cnoe-io/prebuild/agent-backstage
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-backstage:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: template
Repository: ghcr.io/cnoe-io/prebuild/agent-template
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-template:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

@github-actions
Copy link
Copy Markdown
Contributor

🐳 Prebuild Docker Image Published

Agent: komodor
Repository: ghcr.io/cnoe-io/prebuild/agent-komodor
Tag: fix-pypdf-authlib-langsmith-vulnerabilities-1

Usage

docker pull ghcr.io/cnoe-io/prebuild/agent-komodor:fix-pypdf-authlib-langsmith-vulnerabilities-1

Note: This prebuild image will be automatically cleaned up when the PR is closed or merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants