mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-05 20:28:23 +00:00
Closes 29 of 30 open Dependabot alerts (all 3 critical, all 17 high): Python (uv.lock): - litellm 1.83.0 -> 1.84.10 (CVE-2026-49468, CVE-2026-42208 criticals + 8 more high/med/low) - starlette 0.46.2 -> 1.6.0 (CVE-2026-54283, CVE-2026-48818, CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121) - cryptography 43.0.3 -> 50.0.1 (CVE-2026-69249, CVE-2026-26007, CVE-2026-34073, CVE-2024-12797) - h11 0.14.0 -> 0.16.0 (CVE-2025-43859 critical) - fastapi 0.115.14 -> 0.141.1 (starlette 1.x support) - httpx 0.25.2 -> 0.28.1, setuptools 75.9.1 -> 84.0.0, wheel 0.41.3 -> 0.48.0 cashu 0.20.x pins conservative upper bounds (httpx<0.26, h11<0.15, fastapi<0.116, cryptography<44, setuptools<76, wheel<0.42, importlib-metadata<7) that conflict with every patched version, so the gated packages are lifted via [tool.uv] override-dependencies. routstr only imports cashu's wallet-side modules, not its mint/fastapi server paths. starlette is forced via constraint-dependencies since fastapi 0.141 permits the old in-range 0.46.2. Code changes required by the bumps: - httpx 0.28 removed `proxies=`: use `proxy=` in routstr/nostr/discovery.py (Tor .onion health fetches) and examples/tor.py. The discovery.py path was untested and would have raised TypeError at runtime on any .onion provider check. - tests/integration/test_admin_pricing_rate_validation.py: httpx 0.28 refuses to encode NaN/Inf client-side (allow_nan=False); send raw JSON bytes so the bare NaN/Infinity literals still reach the server, which is the behavior under test. UI (pnpm-lock.yaml): - browserslist 4.28.1 -> 4.28.9 (CVE-2026-73089, CVE-2026-73088) - @humanfs/node 0.16.7 -> 0.16.8 Remaining alert: ecdsa (GHSA-wj6h-64fc-37mp, Minerva timing attack) is already at the latest release 0.19.2 with no fix available upstream; cashu pins ecdsa<0.20. Deferred until cashu migrates off python-ecdsa. Verified: 1336 unit + 439 integration tests pass, mypy, ruff, UI lint / format-check / build all clean. 2 unit test failures (test_provider_slugs) are pre-existing environment leaks (python-dotenv loads the parent checkout's .env containing TINFOIL_API_KEY and fail identically on main. EOF )
114 lines
3.5 KiB
TOML
114 lines
3.5 KiB
TOML
[project]
|
|
name = "routstr"
|
|
version = "0.4.7"
|
|
description = "Payment proxy for your LLM endpoint using cashu and nostr."
|
|
readme = "README.md"
|
|
requires-python = ">=3.11"
|
|
|
|
dependencies = [
|
|
"fastapi[standard]>=0.141",
|
|
"aiosqlite>=0.20",
|
|
"sqlmodel>=0.0.24",
|
|
"httpx[socks]>=0.25.2",
|
|
"h11>=0.16",
|
|
"greenlet>=3.2.1",
|
|
"alembic>=1.13",
|
|
"python-json-logger>=2.0.0",
|
|
"cashu>=0.20",
|
|
"marshmallow>=3.13,<4.0",
|
|
"websockets>=12.0",
|
|
"nostr>=0.0.2",
|
|
"mdurl==0.1.2",
|
|
"pillow>=10",
|
|
"openai>=1.98.0",
|
|
"litellm>=1.84.0,<1.85",
|
|
]
|
|
|
|
[dependency-groups]
|
|
dev = [
|
|
"mypy>=1.15.0",
|
|
"ruff>=0.11.6",
|
|
"openai>=1.76.0",
|
|
"pytest>=8.0.0",
|
|
"pytest-asyncio>=0.24.0",
|
|
"pytest-cov>=6.1.1",
|
|
"httpx>=0.25.2",
|
|
"psutil>=5.9.0",
|
|
"aiohttp>=3.9.0",
|
|
"pytest-benchmark>=4.0.0",
|
|
"routstr",
|
|
]
|
|
|
|
[tool.pytest.ini_options]
|
|
testpaths = ["tests"]
|
|
python_files = "test_*.py"
|
|
python_classes = "Test*"
|
|
python_functions = "test_*"
|
|
asyncio_mode = "auto"
|
|
asyncio_default_fixture_loop_scope = "function"
|
|
addopts = [
|
|
"-v",
|
|
"--tb=short",
|
|
"--strict-markers",
|
|
"--disable-warnings",
|
|
"-p",
|
|
"no:warnings",
|
|
]
|
|
markers = [
|
|
"asyncio: marks tests as async (deselect with '-m \"not asyncio\"')",
|
|
"integration: marks tests as integration tests (deselect with '-m \"not integration\"')",
|
|
"unit: marks tests as unit tests",
|
|
"slow: marks tests as slow running (deselect with '-m \"not slow\"')",
|
|
"requires_real_mint: marks tests that require a running Cashu mint instance",
|
|
"requires_docker: marks tests that require Docker services running (deselect with '-m \"not requires_docker\"')",
|
|
"performance: marks tests that measure performance metrics",
|
|
]
|
|
|
|
[build-system]
|
|
requires = ["setuptools", "wheel"]
|
|
build-backend = "setuptools.build_meta"
|
|
|
|
[tool.setuptools]
|
|
packages = ["routstr"]
|
|
|
|
[tool.ruff.lint]
|
|
select = ["E", "F", "I"]
|
|
ignore = ["E501"]
|
|
exclude = ["examples"]
|
|
|
|
[tool.mypy]
|
|
python_version = "3.11"
|
|
ignore_missing_imports = true
|
|
disallow_untyped_defs = true
|
|
check_untyped_defs = true
|
|
disallow_untyped_calls = true
|
|
disallow_incomplete_defs = true
|
|
disallow_untyped_decorators = true
|
|
|
|
[tool.uv.sources]
|
|
routstr = { workspace = true }
|
|
|
|
# Security overrides (2026-09): cashu 0.20.x pins conservative upper bounds
|
|
# (httpx<0.26, h11<0.15, fastapi<0.116, cryptography<44, setuptools<76,
|
|
# wheel<0.42) that conflict with patched versions of these libraries.
|
|
# routstr only imports cashu's wallet-side modules, which do not exercise
|
|
# the fastapi/starlette/h11 server paths cashu's caps were set for.
|
|
[tool.uv]
|
|
override-dependencies = [
|
|
"httpx[socks]>=0.28.0,<1.0", # litellm>=1.84 requires httpx>=0.28 (cashu caps <0.26)
|
|
"importlib-metadata>=8.0.0,<9.0", # litellm>=1.84 requires >=8.0 (cashu caps <7.0)
|
|
"h11>=0.16.0", # CVE-2025-43859: chunked-encoding smuggling (critical)
|
|
"fastapi[standard]>=0.141", # needed for starlette>=1.3.1 line (cashu caps <0.116)
|
|
"cryptography>=49.0.0", # GHSA-jwv3-5hgf-82ww et al. (cashu caps <44)
|
|
"setuptools>=83.0.0", # CVE-2026-59890, CVE-2025-47273 (cashu caps <76)
|
|
"wheel>=0.46.2", # CVE-2026-24049 (cashu caps <0.42)
|
|
]
|
|
|
|
# Floors for transitive deps whose locked versions are still in-range for
|
|
# their dependents but below the patched versions. Constraints (unlike
|
|
# overrides) don't bypass any upstream pins — they only force the resolver
|
|
# to take the fixed versions.
|
|
constraint-dependencies = [
|
|
"starlette>=1.3.1", # CVE-2026-54283, CVE-2026-48818, CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121
|
|
]
|