Skip to content

security: bump setuptools build requirement to >=83.0.0 - #7

Merged
cw-ananke[bot] merged 1 commit into
mainfrom
deps/security-bumps
Sep 11, 2026
Merged

cw-ananke[bot] merged 1 commit into
mainfrom
deps/security-bumps

Conversation

@cw-ananke

@cw-ananke cw-ananke Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Security bumps

Manifest Package Change Alerts addressed
pyproject.toml (build-system) setuptools ==44.0.0 -> >=83.0.0 4 (3 HIGH, 1 MEDIUM; Dependabot alerts #1-#4, attributed to requirements-rtd.txt)

All four open Dependabot alerts for this repo are setuptools vulnerabilities; the vulnerable pin (setuptools==44.0.0) lives in the [build-system] requires of pyproject.toml, which the dependency graph attributes to the requirements-rtd.txt manifest. Raising the requirement to >=83.0.0 satisfies every first-patched threshold (65.5.1, 70.0.0, 78.1.1, 83.0.0).

Validation

  • uv build (isolated PEP 517 build with setuptools >= 83): sdist + wheel build successfully (thumbor_video_engine-1.2.5).
  • No lockfile in this repo; nothing to regenerate.

Notes

  • No deploy surface on this repo (fast-lane): no platform config (render.yaml/fly.toml/vercel.json/netlify.toml/Procfile) and no Dockerfile.
  • CI is currently red repo-wide for a pre-existing, unrelated reason: test.yml uses actions/upload-artifact@v3 / actions/download-artifact@v3, which GitHub now auto-fails (deprecated artifact actions v3). Per campaign rules, .github/workflows/* is not editable, so this cannot be fixed in this PR. The same failure is visible on Dependabot's own PR Bump setuptools from 44.0.0 to 83.0.0 #6.
  • Supersedes/repeats Dependabot PR Bump setuptools from 44.0.0 to 83.0.0 #6 ("Bump setuptools from 44.0.0 to 83.0.0"); that PR can be closed once this merges (it will auto-close).

Fixes all 4 open Dependabot alerts (setuptools < 65.5.1, < 70.0.0,
< 78.1.1, < 83.0.0) attributed to requirements-rtd.txt. The vulnerable
pin setuptools==44.0.0 lives in pyproject.toml [build-system].

@cloudwalk-review-agent cloudwalk-review-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

This change is correct and appropriately scoped: it updates the build-system setuptools requirement from a vulnerable hard pin (==44.0.0) to a patched floor (>=83.0.0) in pyproject.toml.

I found no concrete regressions in correctness, security, or build contract from the provided diff. For a build backend requirement, a minimum bound is the right shape to keep security posture while allowing compatible newer releases.

@cw-ananke
cw-ananke Bot merged commit 3972c6e into main Sep 11, 2026
1 of 8 checks passed
@cw-ananke
cw-ananke Bot deleted the deps/security-bumps branch September 11, 2026 00:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants