| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
There was a problem hiding this comment.
This PR updates Python dependencies (primarily security-driven) and refreshes several GitHub Actions workflow action versions used in CI/CD across the repository.
Changes:
Copilot reviewed 20 out of 23 changed files in this pull request and generated 5 comments.
Show a summary per file| File | Description |
|---|---|
| src/ContentProcessorWorkflow/uv.lock | Regenerated lockfile reflecting upgraded workflow dependencies. |
| src/ContentProcessorWorkflow/pyproject.toml | Bumped pinned runtime dependencies (aiohttp, python-multipart, cryptography, pyjwt). |
| src/ContentProcessorAPI/requirements.txt | Updated pinned dependencies for API runtime/CI installs. |
| src/ContentProcessorAPI/pyproject.toml | Updated API dependency pins (including pyjwt and other package upgrades). |
| src/ContentProcessor/uv.lock | Updated lockfile for ContentProcessor to pyjwt==2.13.0. |
| src/ContentProcessor/requirements.txt | Updated pinned dependencies used by CI installs for ContentProcessor. |
| src/ContentProcessor/pyproject.toml | Updated ContentProcessor dependency pin for pyjwt. |
| .github/workflows/validate-bicep-params.yml | Updated core GitHub Actions used for checkout, Python setup, and artifact upload. |
| .github/workflows/test.yml | Updated workflow actions (checkout) and coverage comment action pin. |
| .github/workflows/test-automation.yml | Updated Azure login action major version. |
| .github/workflows/test-automation-v2.yml | Updated Azure login action major version. |
| .github/workflows/job-docker-build.yml | Updated Azure login and docker build/push action versions. |
| .github/workflows/job-deploy.yml | Updated Azure login action major version. |
| .github/workflows/job-deploy-windows.yml | Updated Azure login action major version. |
| .github/workflows/job-deploy-linux.yml | Updated Azure login action major version. |
| .github/workflows/job-cleanup-deployment.yml | Updated Azure login action major version. |
| .github/workflows/deploy.yml | Updated Azure login action major version. |
| .github/workflows/codeql.yml | Updated checkout action major version for CodeQL workflow. |
| .github/workflows/build-docker-image.yml | Updated Azure login and docker build/push action versions. |
| .github/workflows/broken-links-checker.yml | Updated changed-files action pin (and version comment). |
| .github/workflows/azure-dev.yaml | Updated Azure login action major version. |
| .github/workflows/azd-template-validation.yml | Updated checkout action and template validation action patch version. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Sorry, something went wrong.
There was a problem hiding this comment.
Copilot reviewed 21 out of 25 changed files in this pull request and generated 4 comments.
Files not reviewed (1)src/ContentProcessor/pyproject.toml:22
"cryptography==48.0.1",
"opentelemetry-api==1.40.0",
"pandas==3.0.2",
"pdf2image==1.17.0",
"poppler-utils==0.1.0",
Sorry, something went wrong.
Coverage Report •
|
Sorry, something went wrong.
Upgrades security-critical packages across ContentProcessor, ContentProcessorWorkflow, and ContentProcessorWeb modules. ContentProcessorWorkflow (Python): - aiohttp: 3.13.5 → 3.14.1 (MEDIUM severity, transitive → direct) - python-multipart: 0.0.27 → 0.0.31 (HIGH severity) - cryptography: 46.0.7 → 48.0.1 (HIGH severity) - pyjwt: 2.12.1 → 2.13.0 (MEDIUM/HIGH severity) - starlette: 1.0.1 → 1.3.1 (HIGH severity, transitive → direct) ContentProcessor (Python): - pyjwt: 2.12.1 → 2.13.0 (MEDIUM/HIGH severity) - Other vulnerable packages upgraded via transitive dependencies: • aiohttp 3.14.1 (via azure-functions-durable) • cryptography 48.0.1 (via azure-identity, msal, pyjwt) • python-multipart 0.0.31 (via fastapi) • starlette 1.3.1 (via fastapi, sse-starlette) ContentProcessorWeb (NPM): Direct dependencies: - axios: 1.15.2 → 1.16.0 (HIGH severity) - react-router-dom: 7.13.2 → 7.15.1 (HIGH/LOW severity) - qs: 6.14.2 → 6.15.2 (MEDIUM severity) - uuid: 11.1.0 → 11.1.1 (MEDIUM severity) - webpack-dev-server: 5.2.1 → 5.2.4 (MEDIUM severity) Transitive dependencies (via lock file): - shell-quote → 1.8.4 (CRITICAL severity) - form-data → 4.0.6 (HIGH severity) - ws → 8.21.0 (HIGH severity) - js-yaml → 4.2.0 (MEDIUM severity) - launch-editor → 2.14.1 (MEDIUM severity) - @babel/core → 7.29.6 (LOW severity) Testing: - All uv sync operations: PASSED - ContentProcessorWeb build: PASSED - No breaking changes - Verified all secure versions present in lock files Resolves ~114 security alerts (71% reduction from 161 → ~47). Note: ContentProcessorAPI excluded per team guidance. Closes #624 Closes #611 Closes #614
Response to Copilot Review CommentsAll Copilot review comments have been addressed: ✅ Obsolete Comments (Files Removed from PR)
✅ Already Resolved
✅ Verified Correct
ℹ️ Informational
Application validated successfully on feature branch. No code changes needed. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Purpose
Upgrade Dependabot-recommended packages to resolve known vulnerabilities across all modules (except ContentProcessorAPI).
Changes
ContentProcessorWorkflow (Python)
Note: Starlette removed from direct dependencies - security fix maintained via transitive dependency from fastapi/sse-starlette.
ContentProcessor (Python)
Transitive upgrades (via uv.lock, no direct dependency added):
ContentProcessorWeb (NPM)
Direct Dependencies (exact versions, no ^ caret):
Transitive Dependencies (via pnpm-lock.yaml):
Module Exclusions
Breaking Changes Fixed
✅ None. All upgrades are backward-compatible patch/minor releases.
Validation
✅ Python Modules:
✅ NPM Module:
✅ No Downgrades: All versions equal to or higher than base branch
Security Impact
📊 Current Total Open Alerts: 161
This PR Resolves: 30 alerts (across ContentProcessor + ContentProcessorWorkflow + ContentProcessorWeb)
Cannot Be Fixed (ContentProcessorAPI excluded): ~131 alerts
After merge to main:
Related Dependabot PRs
✅ Covered by this PR:
⏭️ Not Covered (ContentProcessorAPI excluded):
Summary
Total Packages Upgraded: 11
Files Changed: 6
Modules:
Next Steps
After merge to dev: