Skip to content

fix(deps): bump soupsieve from 2.8.3 to 2.8.4 in /docs in the pip-security group across 1 directory - #361

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/docs/pip-security-0462f47e4d
Closed

fix(deps): bump soupsieve from 2.8.3 to 2.8.4 in /docs in the pip-security group across 1 directory#361
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/docs/pip-security-0462f47e4d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the pip-security group with 1 update in the /docs directory: soupsieve.

Updates soupsieve from 2.8.3 to 2.8.4

Release notes

Sourced from soupsieve's releases.

2.8.4

  • FIX: Fix another inefficient attribute pattern (@​mauriceng98).
  • FIX: Limit total number of selectors processed in a pattern to prevent massive selector requests (@​mauriceng98).
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the pip-security group with 1 update in the /docs directory: [soupsieve](https://github.com/facelessuser/soupsieve).


Updates `soupsieve` from 2.8.3 to 2.8.4
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.8.3...2.8.4)

---
updated-dependencies:
- dependency-name: soupsieve
  dependency-version: 2.8.4
  dependency-type: indirect
  dependency-group: pip-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file priority: high High priority security Security-advisory dependency fix — merge-first labels Jul 10, 2026
@dependabot
dependabot Bot requested a review from Cre-eD as a code owner July 10, 2026 23:21
@dependabot dependabot Bot added the security Security-advisory dependency fix — merge-first label Jul 10, 2026
@dependabot
dependabot Bot requested a review from smecsia as a code owner July 10, 2026 23:21
@dependabot dependabot Bot added the priority: high High priority label Jul 10, 2026
@github-actions

Copy link
Copy Markdown

Semgrep Scan Results

Repository: api | Commit: 2c224ef

Check Status Details
⚠️ Semgrep Warning 1 warning(s), 5 total

Scanned at 2026-07-10 23:21 UTC

@github-actions

Copy link
Copy Markdown

Security Scan Results

Repository: api | Commit: 2c224ef

Check Status Details
✅ Secret Scan Pass No secrets detected
✅ Dependencies (Trivy) Pass 1 total (no critical/high)
✅ Dependencies (Grype) Pass 1 total (no critical/high)
📦 SBOM Generated 523 components (CycloneDX)

Scanned at 2026-07-10 23:22 UTC

@github-actions

Copy link
Copy Markdown

📊 Statement coverage

Measured on the documented included set (see docs/TESTING.md → Coverage scope). Observe-only — no regression gate is enforced yet.

Scope This PR main baseline Δ
Included set (Gold-tier denominator) 90.3% 90.3% +0.0 pp
Full set (whole repo, transparency) 28.0% 28.0% +0.0 pp

Baseline: main @ d64c472

Cre-eD added a commit that referenced this pull request Aug 3, 2026
…lities 8 → 10) (#372)

## Summary

OpenSSF Scorecard's **Vulnerabilities** check is at **8/10** with 8 open
advisories. This PR takes it to **10/10**.

- **7 fixed by version bump** — 3 Go, 4 Python (all severities, nothing
deferred).
- **1 unfixable by design** — `GO-2026-5932` has `introduced: 0` and no
fix event in OSV. Declared `not_affected` with reachability evidence.
- **2 stale suppressions retired** — `GO-2022-0635` / `GO-2022-0646` no
longer apply; removed rather than carried forward.

`osv-scanner scan source -r .` → **No issues found** (was 8). Scorecard
runs the same scanner (`osvscanner.DoScan` via `clients/osv.go`) against
the repo root, so the check flips on merge to `main`.

## Fixed

| Package | Old → New | Advisory | Sev | Where |
|---|---|---|---|---|
| `github.com/klauspost/compress` | 1.18.4 → 1.18.7 | GO-2026-5841 /
GHSA-259r-337f-4rfw — OOB read in `s2` | HIGH | `go.mod` (indirect) |
| `google.golang.org/grpc` | 1.81.1 → 1.82.1 | GO-2026-6061 /
GHSA-hrxh-6v49-42gf — xDS RBAC + HTTP/2 server | HIGH | `go.mod`
(indirect) |
| `click` | 8.1.8 → 8.4.2 | PYSEC-2026-2132 / CVE-2026-7246 | MEDIUM |
`docs/requirements.txt` |
| `pymdown-extensions` | 10.21.3 → 11.0.1 | GHSA-9xwg-3r6f-jcx2 /
CVE-2026-61632 — `b64` path traversal | MEDIUM | `docs/requirements.txt`
|
| `setuptools` | 82.0.1 → 83.0.0 | PYSEC-2026-3447 / CVE-2026-59890 |
MEDIUM | `docs/requirements.txt` |
| `soupsieve` | 2.8.3 → 2.9.1 | PYSEC-2026-3071 / CVE-2026-49476 —
memory exhaustion | HIGH | `docs/requirements.txt` |
| `soupsieve` | 2.8.3 → 2.9.1 | PYSEC-2026-3072 / CVE-2026-49477 — ReDoS
in selector parser | HIGH | `docs/requirements.txt` |

Side-effect bumps pulled in by the above: `x/crypto` 0.53.0 → 0.54.0,
`x/sys` 0.46.0 → 0.47.0, `x/term` 0.44.0 → 0.45.0,
`opentelemetry-operations-go/detectors/gcp` 1.31.0 → 1.32.0,
`contrib/detectors/gcp` 1.42.0 → 1.43.0, plus the `tools.go` chain (see
*CI ordering* below).

### How the Python side was done

`docs/requirements.in` gains explicit patched floors for the four
packages, following the pattern already established for `requests` /
`urllib3` after #264 — pinning the floor in the `.in` file is what stops
a future `pip-compile` from silently resolving back to a vulnerable
version. `docs/requirements.txt` was then regenerated with `pip-compile
--allow-unsafe --generate-hashes --upgrade`.

`mkdocs-material` 9.7.7 declares `pymdown-extensions>=10.2` with no
upper bound, so the 11.x major is in range for the theme — no theme pin
change needed, and the docs site builds clean (evidence below). The
`b64` extension that carries CVE-2026-61632 is not enabled in
`docs/mkdocs.yml` at all; the bump closes the advisory rather than a
live exposure.

## Not fixable — `GO-2026-5932` (`golang.org/x/crypto/openpgp`)

> The `golang.org/x/crypto/openpgp` package is unmaintained, unsafe by
design, and has known security issues.

This is a permanent "this package should not be used" notice, not a
patchable defect. In OSV it is `introduced: 0` with **no fix event**, so
no version of `x/crypto` clears it — bumping to 0.54.0 (done here
anyway, for hygiene) changes nothing.

**Reachability:**

1. **Where in the tree** — `x/crypto` is a direct dependency, required
for `chacha20poly1305` in `pkg/api/secrets/ciphers`. The advisory covers
only `openpgp` and its six subpackages.
2. **Is it in the artifact** — no. `go list -deps ./... | grep
x/crypto/openpgp` returns nothing, and Go's linker does not emit
packages no import path reaches. The vulnerable code is not present in
any binary this repo produces.
3. **Is the vulnerable code called** — no. `govulncheck -mode=source
./...` reports **0 reachable vulnerabilities**; this advisory lands in
its "modules you require, but your code doesn't appear to call" bucket.
4. **What OpenPGP work actually runs** —
`github.com/ProtonMail/go-crypto/openpgp`, which is the maintained fork
the advisory text itself recommends as the replacement.
5. **What would change the answer** — any new import of
`x/crypto/openpgp/*`. That would flip the VEX statement to `affected`
and block the gate.

Recorded as `status: not_affected`, `justification:
vulnerable_code_not_present` in [`vex/openvex.json`](vex/openvex.json),
mirrored into [`osv-scanner.toml`](osv-scanner.toml) — Scorecard's check
has no VEX input, so the mirror is the only channel that reaches it. No
`.trivyignore`, no `# nosec`, nothing hidden.

## Re-triage of existing suppressions

Both entries that predate this PR were re-checked rather than carried
forward:

| Advisory | Was | Now | Why |
|---|---|---|---|
| GO-2022-0635 (aws-sdk-go v1 s3crypto) | `not_affected` + ignore |
`fixed`, ignore removed | `github.com/aws/aws-sdk-go` (v1) is no longer
in `go.mod` — the Pulumi upgrades dropped the last build-graph edge and
Go module pruning removed it. `osv-scanner` reported the entry as an
**unused ignore**. |
| GO-2022-0646 (same subpackage) | `not_affected` + ignore | `fixed`,
ignore removed | Same. |

VEX statements are kept one release as an audit trail; the
`osv-scanner.toml` entries are gone.

## Governance changes

- **CODEOWNERS** — `/vex/` and `/osv-scanner.toml` are now named
explicitly. A `not_affected` statement hides a real advisory from both
the scanners and the Scorecard badge; that is the same class of change
as touching a workflow, and it should not merge on a generic `*` match.
- **`docs/DEPENDENCIES.md`** — documents (a) that `osv-scanner.toml` is
a *derivative* mirror which may only carry an ID that already exists in
VEX, and (b) that every SCA pass re-triages both files, with `unused
ignores` as the removal signal. Previously the policy said suppressions
live "never in a scanner-suppression file" while `osv-scanner.toml`
existed; policy and practice now agree.
- **`osv-scanner.toml`** — added a note that `reason` must stay a
single-line TOML basic string. A newline in it makes osv-scanner discard
the **entire** config (`strings cannot contain newlines`) and silently
re-report every ignored advisory. Hit while writing this PR.

## CI ordering (`tools.go` pre-bake)

`build-setup` runs `go get $(tools.go imports)` → `go mod download` →
`go generate -tags tools` → `go mod tidy`. Because `go get` resolves
tools to *latest* and `tidy` only runs afterwards, a tool minor landing
between runs breaks `go generate` with `missing go.sum entry`. The
post-`go get` state is pre-baked into this commit so CI's `go get` is a
no-op: `go-jsonschema` 0.23.1 → 0.24.1, `go-internal` 1.14.1 → 1.15.0,
`gofumpt` 0.10.0 → 0.11.0, `x/mod` 0.37.0 → 0.38.0, `x/net` 0.56.0 →
0.57.0, `x/tools` 0.47.0 → 0.48.0, `x/telemetry` bumped.

## Dependabot reconciliation

Open alerts before this PR: 5 — `pymdown-extensions`, `setuptools`,
`soupsieve` ×2, `grpc`. All 5 are closed by the bumps above; they
auto-resolve once this lands on `main`. `click` (PYSEC-2026-2132) and
`klauspost/compress` (GO-2026-5841) were **not** alerted by Dependabot
but are flagged by OSV — fixed here too.

Open Dependabot PRs:

| PR | Disposition |
|---|---|
| #361 `soupsieve 2.8.3 → 2.8.4` | Superseded — this PR goes to 2.9.1.
Dependabot closes it automatically when the manifest lands. |
| #371, #352, #351, #334, #333, #326 | Untouched — `github-actions` /
`docker` streams, unrelated to this PR. |

No config change needed: `.github/dependabot.yml` already covers `gomod`
(/), `pip` (/docs), `docker`, and `github-actions`.

## Evidence

<details>
<summary><code>osv-scanner scan source -r .</code> — before</summary>

```
click              8.1.8    [PyPI] -> PYSEC-2026-2132
pymdown-extensions 10.21.3  [PyPI] -> GHSA-9xwg-3r6f-jcx2
setuptools         82.0.1   [PyPI] -> PYSEC-2026-3447, GHSA-h35f-9h28-mq5c
soupsieve          2.8.3    [PyPI] -> PYSEC-2026-3071, PYSEC-2026-3072,
                                      GHSA-2wc2-fm75-p42x, GHSA-836r-79rf-4m37
klauspost/compress 1.18.4   [Go]   -> GO-2026-5841
golang.org/x/crypto 0.53.0  [Go]   -> GO-2026-5932
google.golang.org/grpc 1.81.1 [Go] -> GO-2026-6061, GHSA-hrxh-6v49-42gf

osv-scanner.toml has unused ignores:
 - GO-2022-0635
 - GO-2022-0646
```
</details>

<details>
<summary><code>osv-scanner scan source -r .</code> — after</summary>

```
Scanned docs/requirements.txt file and found 36 packages
Scanned go.mod file and found 486 packages
Loaded filter from: osv-scanner.toml
GO-2026-5932 has been filtered out because: VEX not_affected
  (vulnerable_code_not_present) ...
Filtered 1 vulnerability from output

No issues found
```
</details>

<details>
<summary><code>govulncheck -mode=source ./...</code> — after</summary>

```
=== Symbol Results ===

No vulnerabilities found.

Your code is affected by 0 vulnerabilities.
This scan also found 0 vulnerabilities in packages you import and 1
vulnerability in modules you require, but your code doesn't appear to call
these vulnerabilities.
```

The 1 module-level finding is GO-2026-5932, covered above.
</details>

## Test plan

- [x] `go build ./...`
- [x] `go generate -tags tools` (post-pre-bake, matches CI's build-setup
order)
- [x] `go test ./pkg/api/secrets/... ./pkg/security/... -count=1` — all
pass
- [x] Docs built exactly as CI does it: `docker run --rm -v
$PWD/docs:/docs -w /docs python@sha256:401f6e1a... sh -c "pip install
--require-hashes -r requirements.txt && mkdocs build"` → `Documentation
built in 3.39 seconds`, hash check clean, no new warnings
- [x] `jq empty vex/openvex.json`
- [ ] CI: govulncheck, CodeQL, Semgrep, build matrix

Signed-off-by: Dmitrii Creed <creeed22@gmail.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Looks like soupsieve is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 3, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/docs/pip-security-0462f47e4d branch August 3, 2026 06:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file priority: high High priority security Security-advisory dependency fix — merge-first

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants