fix(deps): address reviewer feedback on PyYAML security hardening
- Fix step definitions: remove unused imports (sys, Any, Dict), move all imports to module level, drop noqa suppressor, fix docstring step to use context.text, use packaging.version for correct semver check - Upgrade version floor from 6.0.2 to 6.0.3 in step text and feature file to match pyproject.toml constraint and issue requirement - Fix CONTRIBUTORS.md: correct PR number (#11012 -> #11017), issue reference (#13605 -> #11012), and version string (6.0.2 -> 6.0.3) ISSUES CLOSED: #11012
This commit is contained in:
+1
-1
@@ -120,4 +120,4 @@ Below are some specific details of individual PR contributions.
|
||||
* Jeffrey Phillips Freeman has contributed the `--format`/`-f` flag to `agents session tell` (issue #10466): adds JSON envelope output for machine-readable workflows alongside existing Rich console output, with Behave BDD test coverage verifying all four non-rich format paths (JSON, YAML, plain, table) and the short `-f` flag alias.
|
||||
* HAL 9000 has contributed the Semgrep guard for broad exception suppression (PR #9185 / issue #9103): added two new Semgrep rules (`python-no-suppressed-exception` and `python-no-suppress-exception`) to automate enforcement of error propagation guidelines, integrated Semgrep into `nox -s lint` in audit mode with migration plan for ~337 existing violations, and comprehensive BDD test coverage across all rule patterns and escape hatch scenarios.
|
||||
* HAL 9000 has contributed the `ProviderRegistry.FALLBACK_ORDER` fix (#10906): added the missing `ProviderType.GEMINI` to the fallback provider order list so that when only a Gemini API key is configured, the registry correctly selects it as the default provider. Includes BDD regression scenarios in `features/fallback_gemini_provider.feature`.
|
||||
* HAL 9000 has contributed the PyYAML security hardening fix (PR #11012 / issue #13605): added `pyyaml>=6.0.2` as an explicit runtime dependency in `pyproject.toml` to mitigate CVE-2025-8045, replacing the previous implicit transitive-only dependency chain that left YAML config loading vulnerable to silent supply-chain breakage from upstream dependency changes.
|
||||
* HAL 9000 has contributed the PyYAML security hardening fix (PR #11017 / issue #11012): added `pyyaml>=6.0.3` as an explicit runtime dependency in `pyproject.toml` to mitigate CVE-2025-8045, replacing the previous implicit transitive-only dependency chain that left YAML config loading vulnerable to silent supply-chain breakage from upstream dependency changes.
|
||||
|
||||
@@ -6,7 +6,7 @@ Feature: PyYAML runtime dependency is explicitly declared
|
||||
Scenario: PyYAML is available at runtime for actor config loading
|
||||
When I verify that PyYAML can be imported
|
||||
Then PyYAML should be importable without error
|
||||
And its version should be >= 6.0.2 to mitigate CVE-2025-8045
|
||||
And its version should be >= 6.0.3 to mitigate CVE-2025-8045
|
||||
|
||||
Scenario: Actor YAML loading works with available PyYAML
|
||||
Given a valid YAML actor config file "test.yaml" with content:
|
||||
|
||||
@@ -2,53 +2,44 @@
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import sys
|
||||
from typing import Any, Dict
|
||||
import json
|
||||
import os
|
||||
import tempfile
|
||||
|
||||
import yaml
|
||||
from behave import given, then, when
|
||||
from packaging.version import Version
|
||||
|
||||
|
||||
@when("I verify that PyYAML can be imported")
|
||||
def step_verify_pyyaml_importable(context) -> None:
|
||||
"""Attempt to import PyYAML module."""
|
||||
context.pyyaml_import_result = "not_attempted"
|
||||
try:
|
||||
import yaml # noqa: F401
|
||||
context.pyyaml_import_result = "success"
|
||||
except ImportError as exc:
|
||||
context.pyyaml_import_result = f"fail:{exc}"
|
||||
context.pyyaml_import_result = "success"
|
||||
|
||||
|
||||
@then("PyYAML should be importable without error")
|
||||
def step_pyyaml_import_succeeds(context) -> None:
|
||||
"""Verify PyYAML import was successful."""
|
||||
assert (
|
||||
context.pyyaml_import_result == "success"
|
||||
), f"PyYAML import failed: {context.pyyaml_import_result}"
|
||||
assert context.pyyaml_import_result == "success", (
|
||||
f"PyYAML import failed: {context.pyyaml_import_result}"
|
||||
)
|
||||
|
||||
|
||||
@then("its version should be >= 6.0.2 to mitigate CVE-2025-8045")
|
||||
@then("its version should be >= 6.0.3 to mitigate CVE-2025-8045")
|
||||
def step_pyyaml_version_check(context) -> None:
|
||||
"""Verify PyYAML version meets security floor."""
|
||||
import yaml
|
||||
|
||||
version_str = getattr(yaml, "__version__", "unknown")
|
||||
parts = version_str.split(".")[:3]
|
||||
major, minor = int(parts[0]), int(parts[1])
|
||||
|
||||
assert (major, minor) >= (6, 0), (
|
||||
f"PyYAML version {version_str} is below security floor 6.0.2 (CVE-2025-8045)"
|
||||
assert Version(version_str) >= Version("6.0.3"), (
|
||||
f"PyYAML version {version_str} is below security floor 6.0.3 (CVE-2025-8045)"
|
||||
)
|
||||
|
||||
|
||||
@given(
|
||||
'a valid YAML actor config file "test.yaml" with content:',
|
||||
)
|
||||
def step_give_yaml_config_file(context, content: str) -> None:
|
||||
def step_give_yaml_config_file(context) -> None:
|
||||
"""Create a temporary YAML config file for testing."""
|
||||
import tempfile
|
||||
import os
|
||||
|
||||
content = context.text
|
||||
context.temp_dir = tempfile.mkdtemp()
|
||||
config_path = os.path.join(context.temp_dir, "test.yaml")
|
||||
with open(config_path, "w", encoding="utf-8") as f:
|
||||
@@ -59,17 +50,13 @@ def step_give_yaml_config_file(context, content: str) -> None:
|
||||
@when("I load the YAML config using PyYAML safe_load")
|
||||
def step_load_yaml_safe_load(context) -> None:
|
||||
"""Load the YAML config file using yaml.safe_load."""
|
||||
import yaml
|
||||
|
||||
with open(context.config_file, "r", encoding="utf-8") as f:
|
||||
with open(context.config_file, encoding="utf-8") as f:
|
||||
context.loaded_config = yaml.safe_load(f)
|
||||
|
||||
|
||||
@then("the loaded config should equal {expected}")
|
||||
def step_config_matches_expected(context, expected: str) -> None:
|
||||
"""Verify the loaded YAML config matches expected value."""
|
||||
import json
|
||||
|
||||
expected_dict = json.loads(expected)
|
||||
assert context.loaded_config == expected_dict, (
|
||||
f"Expected {expected_dict}, got {context.loaded_config}"
|
||||
|
||||
Reference in New Issue
Block a user