Skip to content

chore(security): remediate OSV findings - #967

Merged
vuanhphung merged 2 commits into
mainfrom
ai/security-scan-remediation
Oct 6, 2026
Merged

vuanhphung merged 2 commits into
mainfrom
ai/security-scan-remediation

Conversation

@peco-engineer-bot

Copy link
Copy Markdown
Contributor

Summary

Automated remediation for findings from the weekly OSS driver security scan.

Updates:

  • pyjwt@2.13.0 -> patched Poetry resolution
  • urllib3@2.7.0 -> patched Poetry resolution

Needs maintainer follow-up:

  • pyjwt (GHSA-gvp8-978c-rx2q, PYSEC-2026-4146): no fixed version or safe automatic action
  • oauthlib@3.3.1: Poetry constraints did not resolve every vulnerable oauthlib version to its fix floor

The repository's Security Scan check is the authoritative validation. This PR is draft until that check and the normal driver CI pass.

Source: https://github.com/databricks/databricks-driver-test/actions/runs/37187456062

Signed-off-by: peco-engineer-bot[bot] <287056288+peco-engineer-bot[bot]@users.noreply.github.com>
@peco-engineer-bot peco-engineer-bot Bot added the skip-coverage Skip the coverage fan-out for this PR (no tracking issue opened in databricks-driver-test) label Oct 4, 2026
@vuanhphung
vuanhphung marked this pull request as ready for review October 5, 2026 16:10

@peco-review-bot peco-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Review bot failed — see workflow logs.

Reason: model did not call finalize_review and the final text was not parseable JSON: Empty response

@peco-review-bot peco-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No issues identified by the review bot.

@vuanhphung vuanhphung added the kernel-e2e Trigger preview run of the Kernel E2E workflow on this PR label Oct 6, 2026
@vuanhphung
vuanhphung enabled auto-merge October 6, 2026 03:36
Signed-off-by: Vu Anh Phung <vu.phung@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
@github-actions github-actions Bot removed the kernel-e2e Trigger preview run of the Kernel E2E workflow on this PR label Oct 6, 2026

@peco-review-bot peco-review-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No issues identified by the review bot.

@vuanhphung
vuanhphung added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit afff99e Oct 6, 2026
64 checks passed

This branch was successfully deployed

1 active deployment
azure-prod — 4f7d6ee4 Deployed Oct 6, 2026 by vuanhphung via lts-install (13.3.x-scala2.12, kernel) #366
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ai-assisted skip-coverage Skip the coverage fan-out for this PR (no tracking issue opened in databricks-driver-test)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant