Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add MAINTAINERS.md file - #390

Merged
thibauult merged 6 commits into
mainfrom
add-maintainers-file
Aug 18, 2026
Merged

Add MAINTAINERS.md file#390
thibauult merged 6 commits into
mainfrom
add-maintainers-file

Conversation

@TheJuanAndOnly99

@TheJuanAndOnly99TheJuanAndOnly99 commented May 25, 2026

Copy link
Copy Markdown
Member

This PR adds a MAINTAINERS.md file to the root of this repository as part of a FINOS-wide effort to standardize maintainer signaling across all FINOS projects. An announcement was sent to community@finos.org with the full context, see announcement email here.

How this list was generated

The maintainers were determined from this repository's GitHub settings:

  • Users with maintain or admin role on the repository
  • Members of teams with maintain or admin permission

Each entry includes the GitHub username, name, and organization pulled from the user's public GitHub profile. Where name or organization is missing, a *please add ...* placeholder marks where to fill in the value. Email is optional: it is included when the user has a public GitHub email, otherwise the cell is left blank.

If no maintainers were detected automatically (e.g. your repo has no users or teams with maintain/admin role), the table is intentionally empty. Please populate it manually on this branch before merging and email help@finos.org.

What we need from this project's maintainers

  1. Review the list for completeness and accuracy.
  2. Update any incorrect or placeholder values (names, organization) directly on this branch. Email is optional.
  3. Add anyone missing, edit the file in this PR if a maintainer was not automatically detected.
  4. Merge when the list is accurate.

If your project does not need a MAINTAINERS.md for any reason, just close this PR and let us know at help@finos.org.

If this repository should instead be archived (e.g. it is no longer actively maintained or has been superseded), please email help@finos.org instead so we can coordinate the archival with you.

If you already have a MAINTAINERS.md file, you can close this PR. Please update your existing file if needed and place it in the root of the repository.

Multi-repo projects: share one MAINTAINERS.md

If this repository is part of a project with multiple repositories that share (and will continue to share) the same maintainers, you don't need a separate list per repo. Pick one repository (typically the project's main/umbrella repo) to host the canonical MAINTAINERS.md, and on every other repo replace the table in this PR with a short note pointing readers there, for example:

The maintainers of this repository are listed in the main project repository. See list here.

That way maintainer changes only need to be made in one place going forward.

Going forward: keeping the list current

To keep maintainer changes transparent and aligned with open governance:

  • Any change to the maintainer list must be made via a PR to this file.
  • If your project's governance requires a vote, document or link to the vote outcome in the PR description or comments.
  • This gives the community a public audit trail of project leadership over time.

If you have any questions about the format or process, please email help@finos.org.

Thank you for your review!

TheJuanAndOnly99and others added 2 commits May 25, 2026 23:48
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Comment threadMAINTAINERS.md Outdated
thibauultand others added 4 commits August 18, 2026 15:28
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
@thibauult
thibauult merged commit 5480de1 into mainAug 18, 2026
21 checks passed
@thibauult
thibauult deleted the add-maintainers-file branch August 18, 2026 14:11
@matthewcummingsmatthewcummings mentioned this pull request Aug 23, 2026
4 tasks
thibauult pushed a commit that referenced this pull request Aug 26, 2026
… a patch release. (#397)
Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
matthewcummings added a commit to matthewcummings/symphony-bdk-python that referenced this pull request Aug 30, 2026
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
matthewcummings added a commit that referenced this pull request Aug 31, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Add MAINTAINERS.md file
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Make maintainer email optional
Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
* Update MAINTAINERS.md
* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings
Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.
* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings
Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.
* Add BSD-3-Clause to authorized licenses for liccheck
idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.
---------
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
(cherry picked from commit 5480de1)
broHeryk pushed a commit to broHeryk/symphony-bdk-python that referenced this pull request Sep 1, 2026
* Raise cryptography ceiling to allow the patched 50.x
The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:
48.0.1 CVE-2026-69247 and CVE-2026-69249
49.0.0 CVE-2026-69247
50.0.x clean
Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.
This is the second time in eight days the ceiling has blocked a security
fix. finos#397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.
Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.
cryptography 48.0.1 560 passed, 3 skipped
cryptography 50.0.0 560 passed, 3 skipped
cryptography 50.0.1 560 passed, 3 skipped (the locked version)
poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.
* Bump version to 2.11.4 to prepare a patch release
Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.
The constraint fix in finos#390 sat unreleased for five days because the
version bump was a separate change (finos#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.
Follows the same convention as finos#397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
(cherry picked from commit 487ac1c)
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@TheJuanAndOnly99@thibauult