fix(deps): bump bedrock-agentcore to patch CVE-2026-16796 (#6654)

bedrock-agentcore 1.7.0 has GHSA-j6g5-3hh3-pgw8 (CVE-2026-16796, high):
argument-delimiter injection in CodeInterpreter.install_packages(). It fails
the pip-audit vulnerability scan on every PR in the repo.

The patch is 1.18.1, which requires boto3>=1.43.31. The old <1.8.0 cap plus
aiobotocore~=3.5.0 (botocore<1.42.92) made that unsatisfiable, so the AWS
stack moves together:

- bedrock-agentcore >=1.7.0,<1.8.0 -> >=1.18.1,<2.0.0
- boto3 ~=1.42.90 -> ~=1.43.46  (aws + bedrock extras)
- aiobotocore ~=3.5.0 -> ~=3.8.0 (aws + bedrock extras)

aiobotocore 3.8.0 allows botocore <1.43.47 and boto3 1.43.46 pins botocore
1.43.46, so the ranges overlap.

Verified: uv lock resolves, pip-audit reports no vulnerabilities (3 existing
ignores, none new), 48 bedrock tests pass, and both bedrock toolkits import
cleanly. BrowserClient.{start,stop,generate_ws_headers} and
CodeInterpreter.{start,stop,invoke} are unchanged in 1.18.1.
This commit is contained in:
alex-clawd
2026-07-26 00:55:05 -07:00
committed by GitHub
parent b3aaaab023
commit 728183e420
3 changed files with 26 additions and 26 deletions

View File

@@ -131,7 +131,7 @@ postgresql = [
]
bedrock = [
"beautifulsoup4>=4.13.4",
"bedrock-agentcore>=1.7.0,<1.8.0",
"bedrock-agentcore>=1.18.1,<2.0.0",
"playwright>=1.52.0",
"nest-asyncio>=1.6.0",
]

View File

@@ -78,8 +78,8 @@ qdrant = [
"qdrant-client[fastembed]~=1.14.3",
]
aws = [
"boto3~=1.42.90",
"aiobotocore~=3.5.0",
"boto3~=1.43.46",
"aiobotocore~=3.8.0",
]
watson = [
"ibm-watsonx-ai~=1.3.39",
@@ -91,8 +91,8 @@ litellm = [
"litellm>=1.84.0,<2",
]
bedrock = [
"boto3~=1.42.90",
"aiobotocore~=3.5.0",
"boto3~=1.43.46",
"aiobotocore~=3.8.0",
]
google-genai = [
"google-genai~=1.65.0",