mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-05 12:28:22 +00:00
chore(deps): patch all Dependabot security alerts
Closes 29 of 30 open Dependabot alerts (all 3 critical, all 17 high): Python (uv.lock): - litellm 1.83.0 -> 1.84.10 (CVE-2026-49468, CVE-2026-42208 criticals + 8 more high/med/low) - starlette 0.46.2 -> 1.6.0 (CVE-2026-54283, CVE-2026-48818, CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121) - cryptography 43.0.3 -> 50.0.1 (CVE-2026-69249, CVE-2026-26007, CVE-2026-34073, CVE-2024-12797) - h11 0.14.0 -> 0.16.0 (CVE-2025-43859 critical) - fastapi 0.115.14 -> 0.141.1 (starlette 1.x support) - httpx 0.25.2 -> 0.28.1, setuptools 75.9.1 -> 84.0.0, wheel 0.41.3 -> 0.48.0 cashu 0.20.x pins conservative upper bounds (httpx<0.26, h11<0.15, fastapi<0.116, cryptography<44, setuptools<76, wheel<0.42, importlib-metadata<7) that conflict with every patched version, so the gated packages are lifted via [tool.uv] override-dependencies. routstr only imports cashu's wallet-side modules, not its mint/fastapi server paths. starlette is forced via constraint-dependencies since fastapi 0.141 permits the old in-range 0.46.2. Code changes required by the bumps: - httpx 0.28 removed `proxies=`: use `proxy=` in routstr/nostr/discovery.py (Tor .onion health fetches) and examples/tor.py. The discovery.py path was untested and would have raised TypeError at runtime on any .onion provider check. - tests/integration/test_admin_pricing_rate_validation.py: httpx 0.28 refuses to encode NaN/Inf client-side (allow_nan=False); send raw JSON bytes so the bare NaN/Infinity literals still reach the server, which is the behavior under test. UI (pnpm-lock.yaml): - browserslist 4.28.1 -> 4.28.9 (CVE-2026-73089, CVE-2026-73088) - @humanfs/node 0.16.7 -> 0.16.8 Remaining alert: ecdsa (GHSA-wj6h-64fc-37mp, Minerva timing attack) is already at the latest release 0.19.2 with no fix available upstream; cashu pins ecdsa<0.20. Deferred until cashu migrates off python-ecdsa. Verified: 1336 unit + 439 integration tests pass, mypy, ruff, UI lint / format-check / build all clean. 2 unit test failures (test_provider_slugs) are pre-existing environment leaks (python-dotenv loads the parent checkout's .env containing TINFOIL_API_KEY and fail identically on main. EOF )
This commit is contained in:
+1
-1
@@ -7,7 +7,7 @@ from openai import OpenAI
|
||||
client = OpenAI(
|
||||
api_key=os.environ.get("TOKEN"),
|
||||
base_url=os.environ.get("ONION_URL", "http://roustrjfsdgfiueghsklchg.onion/v1"),
|
||||
http_client=httpx.Client(proxies="socks5://localhost:9050"),
|
||||
http_client=httpx.Client(proxy="socks5://localhost:9050"),
|
||||
)
|
||||
|
||||
print(
|
||||
|
||||
+27
-3
@@ -6,11 +6,11 @@ readme = "README.md"
|
||||
requires-python = ">=3.11"
|
||||
|
||||
dependencies = [
|
||||
"fastapi[standard]>=0.115",
|
||||
"fastapi[standard]>=0.141",
|
||||
"aiosqlite>=0.20",
|
||||
"sqlmodel>=0.0.24",
|
||||
"httpx[socks]>=0.25.2",
|
||||
"h11>=0.14",
|
||||
"h11>=0.16",
|
||||
"greenlet>=3.2.1",
|
||||
"alembic>=1.13",
|
||||
"python-json-logger>=2.0.0",
|
||||
@@ -21,7 +21,7 @@ dependencies = [
|
||||
"mdurl==0.1.2",
|
||||
"pillow>=10",
|
||||
"openai>=1.98.0",
|
||||
"litellm>=1.55.0",
|
||||
"litellm>=1.84.0,<1.85",
|
||||
]
|
||||
|
||||
[dependency-groups]
|
||||
@@ -87,3 +87,27 @@ disallow_untyped_decorators = true
|
||||
|
||||
[tool.uv.sources]
|
||||
routstr = { workspace = true }
|
||||
|
||||
# Security overrides (2026-09): cashu 0.20.x pins conservative upper bounds
|
||||
# (httpx<0.26, h11<0.15, fastapi<0.116, cryptography<44, setuptools<76,
|
||||
# wheel<0.42) that conflict with patched versions of these libraries.
|
||||
# routstr only imports cashu's wallet-side modules, which do not exercise
|
||||
# the fastapi/starlette/h11 server paths cashu's caps were set for.
|
||||
[tool.uv]
|
||||
override-dependencies = [
|
||||
"httpx[socks]>=0.28.0,<1.0", # litellm>=1.84 requires httpx>=0.28 (cashu caps <0.26)
|
||||
"importlib-metadata>=8.0.0,<9.0", # litellm>=1.84 requires >=8.0 (cashu caps <7.0)
|
||||
"h11>=0.16.0", # CVE-2025-43859: chunked-encoding smuggling (critical)
|
||||
"fastapi[standard]>=0.141", # needed for starlette>=1.3.1 line (cashu caps <0.116)
|
||||
"cryptography>=49.0.0", # GHSA-jwv3-5hgf-82ww et al. (cashu caps <44)
|
||||
"setuptools>=83.0.0", # CVE-2026-59890, CVE-2025-47273 (cashu caps <76)
|
||||
"wheel>=0.46.2", # CVE-2026-24049 (cashu caps <0.42)
|
||||
]
|
||||
|
||||
# Floors for transitive deps whose locked versions are still in-range for
|
||||
# their dependents but below the patched versions. Constraints (unlike
|
||||
# overrides) don't bypass any upstream pins — they only force the resolver
|
||||
# to take the fixed versions.
|
||||
constraint-dependencies = [
|
||||
"starlette>=1.3.1", # CVE-2026-54283, CVE-2026-48818, CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121
|
||||
]
|
||||
|
||||
@@ -320,18 +320,18 @@ async def fetch_provider_health(endpoint_url: str) -> dict[str, Any]:
|
||||
is_onion = ".onion" in endpoint_url
|
||||
|
||||
# Set up client arguments conditionally
|
||||
proxies = None
|
||||
proxy: str | None = None
|
||||
if is_onion:
|
||||
try:
|
||||
tor_proxy = settings.tor_proxy_url
|
||||
except Exception:
|
||||
tor_proxy = "socks5://127.0.0.1:9050"
|
||||
proxies = {"http://": tor_proxy, "https://": tor_proxy} # type: ignore[assignment]
|
||||
proxy = tor_proxy
|
||||
|
||||
async with httpx.AsyncClient(
|
||||
timeout=httpx.Timeout(30.0),
|
||||
follow_redirects=True,
|
||||
proxies=proxies, # type: ignore[arg-type]
|
||||
proxy=proxy,
|
||||
) as client:
|
||||
# Prefer provider's /v1/info for full details
|
||||
info_url = f"{endpoint_url.rstrip('/')}/v1/info"
|
||||
|
||||
@@ -410,12 +410,19 @@ async def test_malformed_auxiliary_rate_is_rejected(
|
||||
("input_cache_write", float("-inf")),
|
||||
("completion", -1.0),
|
||||
):
|
||||
# Send raw bytes rather than `json=`: httpx>=0.28 refuses to encode
|
||||
# non-finite floats itself (allow_nan=False), but the point of this
|
||||
# test is that the SERVER answers the bare NaN/Infinity literals
|
||||
# with a 422, so the literals must still reach it.
|
||||
body = json.dumps(
|
||||
_payload(
|
||||
provider_id, model_id="aux-rate", pricing=_pricing(**{field: bad})
|
||||
)
|
||||
).encode("utf-8")
|
||||
resp = await integration_client.post(
|
||||
f"/admin/api/upstream-providers/{provider_id}/models",
|
||||
headers=_admin_headers(),
|
||||
json=_payload(
|
||||
provider_id, model_id="aux-rate", pricing=_pricing(**{field: bad})
|
||||
),
|
||||
headers={**_admin_headers(), "content-type": "application/json"},
|
||||
content=body,
|
||||
)
|
||||
|
||||
assert resp.status_code == 422, field
|
||||
|
||||
Generated
+50
-28
@@ -398,12 +398,16 @@ packages:
|
||||
peerDependencies:
|
||||
react-hook-form: ^7.55.0
|
||||
|
||||
'@humanfs/core@0.19.1':
|
||||
resolution: {integrity: sha512-5DyQ4+1JEUzejeK1JGICcideyfUbGixgS9jNgex5nqkW+cY7WZhxBigmieN5Qnw9ZosSNVC9KQKyb+GUaGyKUA==}
|
||||
'@humanfs/core@0.19.2':
|
||||
resolution: {integrity: sha512-UhXNm+CFMWcbChXywFwkmhqjs3PRCmcSa/hfBgLIb7oQ5HNb1wS0icWsGtSAUNgefHeI+eBrA8I1fxmbHsGdvA==}
|
||||
engines: {node: '>=18.18.0'}
|
||||
|
||||
'@humanfs/node@0.16.7':
|
||||
resolution: {integrity: sha512-/zUx+yOsIrG4Y43Eh2peDeKCxlRt/gET6aHfaKpuq267qXdYDFViVHfMaLyygZOnl0kGWxFIgsBy8QFuTLUXEQ==}
|
||||
'@humanfs/node@0.16.8':
|
||||
resolution: {integrity: sha512-gE1eQNZ3R++kTzFUpdGlpmy8kDZD/MLyHqDwqjkVQI0JMdI1D51sy1H958PNXYkM2rAac7e5/CnIKZrHtPh3BQ==}
|
||||
engines: {node: '>=18.18.0'}
|
||||
|
||||
'@humanfs/types@0.15.0':
|
||||
resolution: {integrity: sha512-ZZ1w0aoQkwuUuC7Yf+7sdeaNfqQiiLcSRbfI08oAxqLtpXQr9AIVX7Ay7HLDuiLYAaFPu8oBYNq/QIi9URHJ3Q==}
|
||||
engines: {node: '>=18.18.0'}
|
||||
|
||||
'@humanwhocodes/module-importer@1.0.1':
|
||||
@@ -1860,6 +1864,11 @@ packages:
|
||||
engines: {node: '>=6.0.0'}
|
||||
hasBin: true
|
||||
|
||||
baseline-browser-mapping@2.11.21:
|
||||
resolution: {integrity: sha512-uh8vpY/1/YyFkunIDFH/12p7/7VdPKA1hejMVEbdkEaWnUz0Hesvx5EbiU6XxjyHZIOju+ZMbQJkRh+es3/spQ==}
|
||||
engines: {node: '>=6.0.0'}
|
||||
hasBin: true
|
||||
|
||||
brace-expansion@1.1.18:
|
||||
resolution: {integrity: sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==}
|
||||
|
||||
@@ -1871,8 +1880,8 @@ packages:
|
||||
resolution: {integrity: sha512-yQbXgO/OSZVD2IsiLlro+7Hf6Q18EJrKSEsdoMzKePKXct3gvD8oLcOQdIzGupr5Fj+EDe8gO/lxc1BzfMpxvA==}
|
||||
engines: {node: '>=8'}
|
||||
|
||||
browserslist@4.28.1:
|
||||
resolution: {integrity: sha512-ZC5Bd0LgJXgwGqUknZY/vkUQ04r8NXnJZ3yYi4vDmSiZmC/pdSN0NbNRPxZpbtO4uAfDUAFffO8IZoM3Gj8IkA==}
|
||||
browserslist@4.28.9:
|
||||
resolution: {integrity: sha512-EWazOblFYUvlGZcfGhPUPmYh3nikUxBVb+y9MJun5f3hBi812X+8MSQTujLBtgK3cf51fJWbWfOjyeO954d+Eg==}
|
||||
engines: {node: ^6 || ^7 || ^8 || ^9 || ^10 || ^11 || ^12 || >=13.7}
|
||||
hasBin: true
|
||||
|
||||
@@ -1899,6 +1908,9 @@ packages:
|
||||
caniuse-lite@1.0.30001776:
|
||||
resolution: {integrity: sha512-sg01JDPzZ9jGshqKSckOQthXnYwOEP50jeVFhaSFbZcOy05TiuuaffDOfcwtCisJ9kNQuLBFibYywv2Bgm9osw==}
|
||||
|
||||
caniuse-lite@1.0.30001810:
|
||||
resolution: {integrity: sha512-TITQPUkaz+aVk5GL6NhOdwk1aEaNTSDPsGFWrTuhKGtjTF70jL/Oht2W4c6rXUe5fu7Ie19VIahAXHIIiWWNeg==}
|
||||
|
||||
chalk@4.1.2:
|
||||
resolution: {integrity: sha512-oKnbhFyRIXpUuez8iBMmyEa4nbj4IOQyuhc/wy9kY7/WVPcwIO9VA668Pu8RkO7+0G76SLROeyw9CpQ061i4mA==}
|
||||
engines: {node: '>=10'}
|
||||
@@ -2068,8 +2080,8 @@ packages:
|
||||
resolution: {integrity: sha512-KIN/nDJBQRcXw0MLVhZE9iQHmG68qAVIBg9CqmUYjmQIhgij9U5MFvrqkUL5FbtyyzZuOeOt0zdeRe4UY7ct+A==}
|
||||
engines: {node: '>= 0.4'}
|
||||
|
||||
electron-to-chromium@1.5.307:
|
||||
resolution: {integrity: sha512-5z3uFKBWjiNR44nFcYdkcXjKMbg5KXNdciu7mhTPo9tB7NbqSNP2sSnGR+fqknZSCwKkBN+oxiiajWs4dT6ORg==}
|
||||
electron-to-chromium@1.5.422:
|
||||
resolution: {integrity: sha512-UvA/32XqrLDdZSn7Jllo1AYNcWji/G0d5M0GTViE7KoGBiMunw3a34Sb2KO4ZZyrSEhqsxFoVhWWJshdyfKqJA==}
|
||||
|
||||
embla-carousel-react@8.6.0:
|
||||
resolution: {integrity: sha512-0/PjqU7geVmo6F734pmPqpyHqiM99olvyecY7zdweCw+6tKEXnrE90pBiBbMMU8s5tICemzpQ3hi5EpxzGW+JA==}
|
||||
@@ -2841,8 +2853,9 @@ packages:
|
||||
sass:
|
||||
optional: true
|
||||
|
||||
node-releases@2.0.36:
|
||||
resolution: {integrity: sha512-TdC8FSgHz8Mwtw9g5L4gR/Sh9XhSP/0DEkQxfEFXOpiul5IiHgHan2VhYYb6agDSfp4KuvltmGApc8HMgUrIkA==}
|
||||
node-releases@2.0.54:
|
||||
resolution: {integrity: sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==}
|
||||
engines: {node: '>=18'}
|
||||
|
||||
object-assign@4.1.1:
|
||||
resolution: {integrity: sha512-rJgTQnkUnH1sFw8yT6VSU3zD3sWmu6sZhIseY8VX+GRu3P6F7Fu+JNDoXfklElbLJSnc3FUQHVe4cU5hj+BcUg==}
|
||||
@@ -3408,8 +3421,8 @@ packages:
|
||||
unrs-resolver@1.11.1:
|
||||
resolution: {integrity: sha512-bSjt9pjaEBnNiGgc9rUiHGKv5l4/TGzDmYw3RhnkJGtLhbnnA/5qJj7x3dNDCRx/PJxu774LlH8lCOlB4hEfKg==}
|
||||
|
||||
update-browserslist-db@1.2.3:
|
||||
resolution: {integrity: sha512-Js0m9cx+qOgDxo0eMiFGEueWztz+d4+M3rGlmKPT+T4IS/jP4ylw3Nwpu6cpTTP8R1MAC1kF4VbdLt3ARf209w==}
|
||||
update-browserslist-db@1.3.2:
|
||||
resolution: {integrity: sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==}
|
||||
hasBin: true
|
||||
peerDependencies:
|
||||
browserslist: '>= 4.21.0'
|
||||
@@ -3576,7 +3589,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@babel/compat-data': 7.29.0
|
||||
'@babel/helper-validator-option': 7.27.1
|
||||
browserslist: 4.28.1
|
||||
browserslist: 4.28.9
|
||||
lru-cache: 5.1.1
|
||||
semver: 6.3.1
|
||||
|
||||
@@ -3753,13 +3766,18 @@ snapshots:
|
||||
'@standard-schema/utils': 0.3.0
|
||||
react-hook-form: 7.71.2(react@19.2.4)
|
||||
|
||||
'@humanfs/core@0.19.1': {}
|
||||
|
||||
'@humanfs/node@0.16.7':
|
||||
'@humanfs/core@0.19.2':
|
||||
dependencies:
|
||||
'@humanfs/core': 0.19.1
|
||||
'@humanfs/types': 0.15.0
|
||||
|
||||
'@humanfs/node@0.16.8':
|
||||
dependencies:
|
||||
'@humanfs/core': 0.19.2
|
||||
'@humanfs/types': 0.15.0
|
||||
'@humanwhocodes/retry': 0.4.3
|
||||
|
||||
'@humanfs/types@0.15.0': {}
|
||||
|
||||
'@humanwhocodes/module-importer@1.0.1': {}
|
||||
|
||||
'@humanwhocodes/retry@0.4.3': {}
|
||||
@@ -5181,6 +5199,8 @@ snapshots:
|
||||
|
||||
baseline-browser-mapping@2.10.0: {}
|
||||
|
||||
baseline-browser-mapping@2.11.21: {}
|
||||
|
||||
brace-expansion@1.1.18:
|
||||
dependencies:
|
||||
balanced-match: 1.0.2
|
||||
@@ -5194,13 +5214,13 @@ snapshots:
|
||||
dependencies:
|
||||
fill-range: 7.1.1
|
||||
|
||||
browserslist@4.28.1:
|
||||
browserslist@4.28.9:
|
||||
dependencies:
|
||||
baseline-browser-mapping: 2.10.0
|
||||
caniuse-lite: 1.0.30001776
|
||||
electron-to-chromium: 1.5.307
|
||||
node-releases: 2.0.36
|
||||
update-browserslist-db: 1.2.3(browserslist@4.28.1)
|
||||
baseline-browser-mapping: 2.11.21
|
||||
caniuse-lite: 1.0.30001810
|
||||
electron-to-chromium: 1.5.422
|
||||
node-releases: 2.0.54
|
||||
update-browserslist-db: 1.3.2(browserslist@4.28.9)
|
||||
|
||||
call-bind-apply-helpers@1.0.2:
|
||||
dependencies:
|
||||
@@ -5225,6 +5245,8 @@ snapshots:
|
||||
|
||||
caniuse-lite@1.0.30001776: {}
|
||||
|
||||
caniuse-lite@1.0.30001810: {}
|
||||
|
||||
chalk@4.1.2:
|
||||
dependencies:
|
||||
ansi-styles: 4.3.0
|
||||
@@ -5384,7 +5406,7 @@ snapshots:
|
||||
es-errors: 1.3.0
|
||||
gopd: 1.2.0
|
||||
|
||||
electron-to-chromium@1.5.307: {}
|
||||
electron-to-chromium@1.5.422: {}
|
||||
|
||||
embla-carousel-react@8.6.0(react@19.2.4):
|
||||
dependencies:
|
||||
@@ -5740,7 +5762,7 @@ snapshots:
|
||||
'@eslint/eslintrc': 3.3.3
|
||||
'@eslint/js': 9.38.0
|
||||
'@eslint/plugin-kit': 0.4.0
|
||||
'@humanfs/node': 0.16.7
|
||||
'@humanfs/node': 0.16.8
|
||||
'@humanwhocodes/module-importer': 1.0.1
|
||||
'@humanwhocodes/retry': 0.4.3
|
||||
'@types/estree': 1.0.8
|
||||
@@ -6303,7 +6325,7 @@ snapshots:
|
||||
- '@babel/core'
|
||||
- babel-plugin-macros
|
||||
|
||||
node-releases@2.0.36: {}
|
||||
node-releases@2.0.54: {}
|
||||
|
||||
object-assign@4.1.1: {}
|
||||
|
||||
@@ -6968,9 +6990,9 @@ snapshots:
|
||||
'@unrs/resolver-binding-win32-ia32-msvc': 1.11.1
|
||||
'@unrs/resolver-binding-win32-x64-msvc': 1.11.1
|
||||
|
||||
update-browserslist-db@1.2.3(browserslist@4.28.1):
|
||||
update-browserslist-db@1.3.2(browserslist@4.28.9):
|
||||
dependencies:
|
||||
browserslist: 4.28.1
|
||||
browserslist: 4.28.9
|
||||
escalade: 3.2.0
|
||||
picocolors: 1.1.1
|
||||
|
||||
|
||||
Reference in New Issue
Block a user