mirror of
https://github.com/crewAIInc/crewAI.git
synced 2026-09-21 18:36:47 +00:00
pip-audit started failing on every open PR. The advisory is against pip itself: PYSEC-2026-3721 / CVE-2026-13346, which OSV records as affecting pip up to but not including 26.2. The floor was already pinned at >=26.1.2, so the previously patched version became the vulnerable one. Not caused by any open PR. Reproduced on tag 1.15.17 itself (`b3ab193c3`), which resolves pip 26.1.2: `uv run pip-audit` with CI's exact arguments reports "Found 1 known vulnerability" there with no branch changes at all. That is why this is its own PR rather than a fix inside whichever PR happened to run first. Raising the floor rather than adding --ignore-vuln, since a patched release exists: 26.2 fixes it and 26.2.1 is current. The trailing comment follows the convention already used for setuptools>=83.0.0. The uv.lock change is deliberately hand-scoped to pip's four lines. Running `uv lock` -- with either uv 0.11.12 or 0.11.15 -- also re-expands environment markers for numpy, humanfriendly, grpcio, mcp and a dozen nvidia-* packages, because the committed lock was produced by a uv that simplifies markers differently from any version available here. Those rewrites change CUDA and platform resolution and have no business riding along in a security fix. The four lines applied here are exactly the ones uv itself produced for pip. Verified: `uv lock --check` passes, so the lock is consistent with pyproject and needs no regeneration; pip resolves to 26.2.1; `uv run pip-audit` with CI's arguments reports "No known vulnerabilities found, 1 ignored"; crewai and crewai_core still import. Claude-Session: https://claude.ai/code/session_01RfV2uMqWRcdfufMvtdCVoN Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Vidit Ostwal <110953813+Vidit-Ostwal@users.noreply.github.com>
12 KiB
12 KiB