chore(deps): patch all Dependabot security alerts

Closes 29 of 30 open Dependabot alerts (all 3 critical, all 17 high):

Python (uv.lock):
- litellm 1.83.0 -> 1.84.10  (CVE-2026-49468, CVE-2026-42208 criticals
  + 8 more high/med/low)
- starlette 0.46.2 -> 1.6.0  (CVE-2026-54283, CVE-2026-48818,
  CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121)
- cryptography 43.0.3 -> 50.0.1  (CVE-2026-69249, CVE-2026-26007,
  CVE-2026-34073, CVE-2024-12797)
- h11 0.14.0 -> 0.16.0  (CVE-2025-43859 critical)
- fastapi 0.115.14 -> 0.141.1  (starlette 1.x support)
- httpx 0.25.2 -> 0.28.1, setuptools 75.9.1 -> 84.0.0,
  wheel 0.41.3 -> 0.48.0

cashu 0.20.x pins conservative upper bounds (httpx<0.26, h11<0.15,
fastapi<0.116, cryptography<44, setuptools<76, wheel<0.42,
importlib-metadata<7) that conflict with every patched version, so the
gated packages are lifted via [tool.uv] override-dependencies. routstr
only imports cashu's wallet-side modules, not its mint/fastapi server
paths. starlette is forced via constraint-dependencies since fastapi
0.141 permits the old in-range 0.46.2.

Code changes required by the bumps:
- httpx 0.28 removed `proxies=`: use `proxy=` in
  routstr/nostr/discovery.py (Tor .onion health fetches) and
  examples/tor.py. The discovery.py path was untested and would have
  raised TypeError at runtime on any .onion provider check.
- tests/integration/test_admin_pricing_rate_validation.py: httpx 0.28
  refuses to encode NaN/Inf client-side (allow_nan=False); send raw
  JSON bytes so the bare NaN/Infinity literals still reach the server,
  which is the behavior under test.

UI (pnpm-lock.yaml):
- browserslist 4.28.1 -> 4.28.9  (CVE-2026-73089, CVE-2026-73088)
- @humanfs/node 0.16.7 -> 0.16.8

Remaining alert: ecdsa (GHSA-wj6h-64fc-37mp, Minerva timing attack) is
already at the latest release 0.19.2 with no fix available upstream;
cashu pins ecdsa<0.20. Deferred until cashu migrates off python-ecdsa.

Verified: 1336 unit + 439 integration tests pass, mypy, ruff, UI lint /
format-check / build all clean. 2 unit test failures
(test_provider_slugs) are pre-existing environment leaks (python-dotenv
loads the parent checkout's .env containing TINFOIL_API_KEY and fail
identically on main.
EOF
)
This commit is contained in:
redshift
2026-09-07 20:14:28 +02:00
parent f32565e254
commit d1feddbd21
6 changed files with 2565 additions and 2063 deletions
+1 -1
View File
@@ -7,7 +7,7 @@ from openai import OpenAI
client = OpenAI(
api_key=os.environ.get("TOKEN"),
base_url=os.environ.get("ONION_URL", "http://roustrjfsdgfiueghsklchg.onion/v1"),
http_client=httpx.Client(proxies="socks5://localhost:9050"),
http_client=httpx.Client(proxy="socks5://localhost:9050"),
)
print(
+27 -3
View File
@@ -6,11 +6,11 @@ readme = "README.md"
requires-python = ">=3.11"
dependencies = [
"fastapi[standard]>=0.115",
"fastapi[standard]>=0.141",
"aiosqlite>=0.20",
"sqlmodel>=0.0.24",
"httpx[socks]>=0.25.2",
"h11>=0.14",
"h11>=0.16",
"greenlet>=3.2.1",
"alembic>=1.13",
"python-json-logger>=2.0.0",
@@ -21,7 +21,7 @@ dependencies = [
"mdurl==0.1.2",
"pillow>=10",
"openai>=1.98.0",
"litellm>=1.55.0",
"litellm>=1.84.0,<1.85",
]
[dependency-groups]
@@ -87,3 +87,27 @@ disallow_untyped_decorators = true
[tool.uv.sources]
routstr = { workspace = true }
# Security overrides (2026-09): cashu 0.20.x pins conservative upper bounds
# (httpx<0.26, h11<0.15, fastapi<0.116, cryptography<44, setuptools<76,
# wheel<0.42) that conflict with patched versions of these libraries.
# routstr only imports cashu's wallet-side modules, which do not exercise
# the fastapi/starlette/h11 server paths cashu's caps were set for.
[tool.uv]
override-dependencies = [
"httpx[socks]>=0.28.0,<1.0", # litellm>=1.84 requires httpx>=0.28 (cashu caps <0.26)
"importlib-metadata>=8.0.0,<9.0", # litellm>=1.84 requires >=8.0 (cashu caps <7.0)
"h11>=0.16.0", # CVE-2025-43859: chunked-encoding smuggling (critical)
"fastapi[standard]>=0.141", # needed for starlette>=1.3.1 line (cashu caps <0.116)
"cryptography>=49.0.0", # GHSA-jwv3-5hgf-82ww et al. (cashu caps <44)
"setuptools>=83.0.0", # CVE-2026-59890, CVE-2025-47273 (cashu caps <76)
"wheel>=0.46.2", # CVE-2026-24049 (cashu caps <0.42)
]
# Floors for transitive deps whose locked versions are still in-range for
# their dependents but below the patched versions. Constraints (unlike
# overrides) don't bypass any upstream pins — they only force the resolver
# to take the fixed versions.
constraint-dependencies = [
"starlette>=1.3.1", # CVE-2026-54283, CVE-2026-48818, CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121
]
+3 -3
View File
@@ -320,18 +320,18 @@ async def fetch_provider_health(endpoint_url: str) -> dict[str, Any]:
is_onion = ".onion" in endpoint_url
# Set up client arguments conditionally
proxies = None
proxy: str | None = None
if is_onion:
try:
tor_proxy = settings.tor_proxy_url
except Exception:
tor_proxy = "socks5://127.0.0.1:9050"
proxies = {"http://": tor_proxy, "https://": tor_proxy} # type: ignore[assignment]
proxy = tor_proxy
async with httpx.AsyncClient(
timeout=httpx.Timeout(30.0),
follow_redirects=True,
proxies=proxies, # type: ignore[arg-type]
proxy=proxy,
) as client:
# Prefer provider's /v1/info for full details
info_url = f"{endpoint_url.rstrip('/')}/v1/info"
@@ -410,12 +410,19 @@ async def test_malformed_auxiliary_rate_is_rejected(
("input_cache_write", float("-inf")),
("completion", -1.0),
):
# Send raw bytes rather than `json=`: httpx>=0.28 refuses to encode
# non-finite floats itself (allow_nan=False), but the point of this
# test is that the SERVER answers the bare NaN/Infinity literals
# with a 422, so the literals must still reach it.
body = json.dumps(
_payload(
provider_id, model_id="aux-rate", pricing=_pricing(**{field: bad})
)
).encode("utf-8")
resp = await integration_client.post(
f"/admin/api/upstream-providers/{provider_id}/models",
headers=_admin_headers(),
json=_payload(
provider_id, model_id="aux-rate", pricing=_pricing(**{field: bad})
),
headers={**_admin_headers(), "content-type": "application/json"},
content=body,
)
assert resp.status_code == 422, field
+50 -28
View File
@@ -398,12 +398,16 @@ packages:
peerDependencies:
react-hook-form: ^7.55.0
'@humanfs/core@0.19.1':
resolution: {integrity: sha512-5DyQ4+1JEUzejeK1JGICcideyfUbGixgS9jNgex5nqkW+cY7WZhxBigmieN5Qnw9ZosSNVC9KQKyb+GUaGyKUA==}
'@humanfs/core@0.19.2':
resolution: {integrity: sha512-UhXNm+CFMWcbChXywFwkmhqjs3PRCmcSa/hfBgLIb7oQ5HNb1wS0icWsGtSAUNgefHeI+eBrA8I1fxmbHsGdvA==}
engines: {node: '>=18.18.0'}
'@humanfs/node@0.16.7':
resolution: {integrity: sha512-/zUx+yOsIrG4Y43Eh2peDeKCxlRt/gET6aHfaKpuq267qXdYDFViVHfMaLyygZOnl0kGWxFIgsBy8QFuTLUXEQ==}
'@humanfs/node@0.16.8':
resolution: {integrity: sha512-gE1eQNZ3R++kTzFUpdGlpmy8kDZD/MLyHqDwqjkVQI0JMdI1D51sy1H958PNXYkM2rAac7e5/CnIKZrHtPh3BQ==}
engines: {node: '>=18.18.0'}
'@humanfs/types@0.15.0':
resolution: {integrity: sha512-ZZ1w0aoQkwuUuC7Yf+7sdeaNfqQiiLcSRbfI08oAxqLtpXQr9AIVX7Ay7HLDuiLYAaFPu8oBYNq/QIi9URHJ3Q==}
engines: {node: '>=18.18.0'}
'@humanwhocodes/module-importer@1.0.1':
@@ -1860,6 +1864,11 @@ packages:
engines: {node: '>=6.0.0'}
hasBin: true
baseline-browser-mapping@2.11.21:
resolution: {integrity: sha512-uh8vpY/1/YyFkunIDFH/12p7/7VdPKA1hejMVEbdkEaWnUz0Hesvx5EbiU6XxjyHZIOju+ZMbQJkRh+es3/spQ==}
engines: {node: '>=6.0.0'}
hasBin: true
brace-expansion@1.1.18:
resolution: {integrity: sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==}
@@ -1871,8 +1880,8 @@ packages:
resolution: {integrity: sha512-yQbXgO/OSZVD2IsiLlro+7Hf6Q18EJrKSEsdoMzKePKXct3gvD8oLcOQdIzGupr5Fj+EDe8gO/lxc1BzfMpxvA==}
engines: {node: '>=8'}
browserslist@4.28.1:
resolution: {integrity: sha512-ZC5Bd0LgJXgwGqUknZY/vkUQ04r8NXnJZ3yYi4vDmSiZmC/pdSN0NbNRPxZpbtO4uAfDUAFffO8IZoM3Gj8IkA==}
browserslist@4.28.9:
resolution: {integrity: sha512-EWazOblFYUvlGZcfGhPUPmYh3nikUxBVb+y9MJun5f3hBi812X+8MSQTujLBtgK3cf51fJWbWfOjyeO954d+Eg==}
engines: {node: ^6 || ^7 || ^8 || ^9 || ^10 || ^11 || ^12 || >=13.7}
hasBin: true
@@ -1899,6 +1908,9 @@ packages:
caniuse-lite@1.0.30001776:
resolution: {integrity: sha512-sg01JDPzZ9jGshqKSckOQthXnYwOEP50jeVFhaSFbZcOy05TiuuaffDOfcwtCisJ9kNQuLBFibYywv2Bgm9osw==}
caniuse-lite@1.0.30001810:
resolution: {integrity: sha512-TITQPUkaz+aVk5GL6NhOdwk1aEaNTSDPsGFWrTuhKGtjTF70jL/Oht2W4c6rXUe5fu7Ie19VIahAXHIIiWWNeg==}
chalk@4.1.2:
resolution: {integrity: sha512-oKnbhFyRIXpUuez8iBMmyEa4nbj4IOQyuhc/wy9kY7/WVPcwIO9VA668Pu8RkO7+0G76SLROeyw9CpQ061i4mA==}
engines: {node: '>=10'}
@@ -2068,8 +2080,8 @@ packages:
resolution: {integrity: sha512-KIN/nDJBQRcXw0MLVhZE9iQHmG68qAVIBg9CqmUYjmQIhgij9U5MFvrqkUL5FbtyyzZuOeOt0zdeRe4UY7ct+A==}
engines: {node: '>= 0.4'}
electron-to-chromium@1.5.307:
resolution: {integrity: sha512-5z3uFKBWjiNR44nFcYdkcXjKMbg5KXNdciu7mhTPo9tB7NbqSNP2sSnGR+fqknZSCwKkBN+oxiiajWs4dT6ORg==}
electron-to-chromium@1.5.422:
resolution: {integrity: sha512-UvA/32XqrLDdZSn7Jllo1AYNcWji/G0d5M0GTViE7KoGBiMunw3a34Sb2KO4ZZyrSEhqsxFoVhWWJshdyfKqJA==}
embla-carousel-react@8.6.0:
resolution: {integrity: sha512-0/PjqU7geVmo6F734pmPqpyHqiM99olvyecY7zdweCw+6tKEXnrE90pBiBbMMU8s5tICemzpQ3hi5EpxzGW+JA==}
@@ -2841,8 +2853,9 @@ packages:
sass:
optional: true
node-releases@2.0.36:
resolution: {integrity: sha512-TdC8FSgHz8Mwtw9g5L4gR/Sh9XhSP/0DEkQxfEFXOpiul5IiHgHan2VhYYb6agDSfp4KuvltmGApc8HMgUrIkA==}
node-releases@2.0.54:
resolution: {integrity: sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==}
engines: {node: '>=18'}
object-assign@4.1.1:
resolution: {integrity: sha512-rJgTQnkUnH1sFw8yT6VSU3zD3sWmu6sZhIseY8VX+GRu3P6F7Fu+JNDoXfklElbLJSnc3FUQHVe4cU5hj+BcUg==}
@@ -3408,8 +3421,8 @@ packages:
unrs-resolver@1.11.1:
resolution: {integrity: sha512-bSjt9pjaEBnNiGgc9rUiHGKv5l4/TGzDmYw3RhnkJGtLhbnnA/5qJj7x3dNDCRx/PJxu774LlH8lCOlB4hEfKg==}
update-browserslist-db@1.2.3:
resolution: {integrity: sha512-Js0m9cx+qOgDxo0eMiFGEueWztz+d4+M3rGlmKPT+T4IS/jP4ylw3Nwpu6cpTTP8R1MAC1kF4VbdLt3ARf209w==}
update-browserslist-db@1.3.2:
resolution: {integrity: sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==}
hasBin: true
peerDependencies:
browserslist: '>= 4.21.0'
@@ -3576,7 +3589,7 @@ snapshots:
dependencies:
'@babel/compat-data': 7.29.0
'@babel/helper-validator-option': 7.27.1
browserslist: 4.28.1
browserslist: 4.28.9
lru-cache: 5.1.1
semver: 6.3.1
@@ -3753,13 +3766,18 @@ snapshots:
'@standard-schema/utils': 0.3.0
react-hook-form: 7.71.2(react@19.2.4)
'@humanfs/core@0.19.1': {}
'@humanfs/node@0.16.7':
'@humanfs/core@0.19.2':
dependencies:
'@humanfs/core': 0.19.1
'@humanfs/types': 0.15.0
'@humanfs/node@0.16.8':
dependencies:
'@humanfs/core': 0.19.2
'@humanfs/types': 0.15.0
'@humanwhocodes/retry': 0.4.3
'@humanfs/types@0.15.0': {}
'@humanwhocodes/module-importer@1.0.1': {}
'@humanwhocodes/retry@0.4.3': {}
@@ -5181,6 +5199,8 @@ snapshots:
baseline-browser-mapping@2.10.0: {}
baseline-browser-mapping@2.11.21: {}
brace-expansion@1.1.18:
dependencies:
balanced-match: 1.0.2
@@ -5194,13 +5214,13 @@ snapshots:
dependencies:
fill-range: 7.1.1
browserslist@4.28.1:
browserslist@4.28.9:
dependencies:
baseline-browser-mapping: 2.10.0
caniuse-lite: 1.0.30001776
electron-to-chromium: 1.5.307
node-releases: 2.0.36
update-browserslist-db: 1.2.3(browserslist@4.28.1)
baseline-browser-mapping: 2.11.21
caniuse-lite: 1.0.30001810
electron-to-chromium: 1.5.422
node-releases: 2.0.54
update-browserslist-db: 1.3.2(browserslist@4.28.9)
call-bind-apply-helpers@1.0.2:
dependencies:
@@ -5225,6 +5245,8 @@ snapshots:
caniuse-lite@1.0.30001776: {}
caniuse-lite@1.0.30001810: {}
chalk@4.1.2:
dependencies:
ansi-styles: 4.3.0
@@ -5384,7 +5406,7 @@ snapshots:
es-errors: 1.3.0
gopd: 1.2.0
electron-to-chromium@1.5.307: {}
electron-to-chromium@1.5.422: {}
embla-carousel-react@8.6.0(react@19.2.4):
dependencies:
@@ -5740,7 +5762,7 @@ snapshots:
'@eslint/eslintrc': 3.3.3
'@eslint/js': 9.38.0
'@eslint/plugin-kit': 0.4.0
'@humanfs/node': 0.16.7
'@humanfs/node': 0.16.8
'@humanwhocodes/module-importer': 1.0.1
'@humanwhocodes/retry': 0.4.3
'@types/estree': 1.0.8
@@ -6303,7 +6325,7 @@ snapshots:
- '@babel/core'
- babel-plugin-macros
node-releases@2.0.36: {}
node-releases@2.0.54: {}
object-assign@4.1.1: {}
@@ -6968,9 +6990,9 @@ snapshots:
'@unrs/resolver-binding-win32-ia32-msvc': 1.11.1
'@unrs/resolver-binding-win32-x64-msvc': 1.11.1
update-browserslist-db@1.2.3(browserslist@4.28.1):
update-browserslist-db@1.3.2(browserslist@4.28.9):
dependencies:
browserslist: 4.28.1
browserslist: 4.28.9
escalade: 3.2.0
picocolors: 1.1.1
Generated
+2473 -2024
View File
File diff suppressed because it is too large Load Diff