Files
routstr-core/pyproject.toml
T
redshift d1feddbd21 chore(deps): patch all Dependabot security alerts
Closes 29 of 30 open Dependabot alerts (all 3 critical, all 17 high):

Python (uv.lock):
- litellm 1.83.0 -> 1.84.10  (CVE-2026-49468, CVE-2026-42208 criticals
  + 8 more high/med/low)
- starlette 0.46.2 -> 1.6.0  (CVE-2026-54283, CVE-2026-48818,
  CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121)
- cryptography 43.0.3 -> 50.0.1  (CVE-2026-69249, CVE-2026-26007,
  CVE-2026-34073, CVE-2024-12797)
- h11 0.14.0 -> 0.16.0  (CVE-2025-43859 critical)
- fastapi 0.115.14 -> 0.141.1  (starlette 1.x support)
- httpx 0.25.2 -> 0.28.1, setuptools 75.9.1 -> 84.0.0,
  wheel 0.41.3 -> 0.48.0

cashu 0.20.x pins conservative upper bounds (httpx<0.26, h11<0.15,
fastapi<0.116, cryptography<44, setuptools<76, wheel<0.42,
importlib-metadata<7) that conflict with every patched version, so the
gated packages are lifted via [tool.uv] override-dependencies. routstr
only imports cashu's wallet-side modules, not its mint/fastapi server
paths. starlette is forced via constraint-dependencies since fastapi
0.141 permits the old in-range 0.46.2.

Code changes required by the bumps:
- httpx 0.28 removed `proxies=`: use `proxy=` in
  routstr/nostr/discovery.py (Tor .onion health fetches) and
  examples/tor.py. The discovery.py path was untested and would have
  raised TypeError at runtime on any .onion provider check.
- tests/integration/test_admin_pricing_rate_validation.py: httpx 0.28
  refuses to encode NaN/Inf client-side (allow_nan=False); send raw
  JSON bytes so the bare NaN/Infinity literals still reach the server,
  which is the behavior under test.

UI (pnpm-lock.yaml):
- browserslist 4.28.1 -> 4.28.9  (CVE-2026-73089, CVE-2026-73088)
- @humanfs/node 0.16.7 -> 0.16.8

Remaining alert: ecdsa (GHSA-wj6h-64fc-37mp, Minerva timing attack) is
already at the latest release 0.19.2 with no fix available upstream;
cashu pins ecdsa<0.20. Deferred until cashu migrates off python-ecdsa.

Verified: 1336 unit + 439 integration tests pass, mypy, ruff, UI lint /
format-check / build all clean. 2 unit test failures
(test_provider_slugs) are pre-existing environment leaks (python-dotenv
loads the parent checkout's .env containing TINFOIL_API_KEY and fail
identically on main.
EOF
)
2026-09-07 20:14:28 +02:00

114 lines
3.5 KiB
TOML

[project]
name = "routstr"
version = "0.4.7"
description = "Payment proxy for your LLM endpoint using cashu and nostr."
readme = "README.md"
requires-python = ">=3.11"
dependencies = [
"fastapi[standard]>=0.141",
"aiosqlite>=0.20",
"sqlmodel>=0.0.24",
"httpx[socks]>=0.25.2",
"h11>=0.16",
"greenlet>=3.2.1",
"alembic>=1.13",
"python-json-logger>=2.0.0",
"cashu>=0.20",
"marshmallow>=3.13,<4.0",
"websockets>=12.0",
"nostr>=0.0.2",
"mdurl==0.1.2",
"pillow>=10",
"openai>=1.98.0",
"litellm>=1.84.0,<1.85",
]
[dependency-groups]
dev = [
"mypy>=1.15.0",
"ruff>=0.11.6",
"openai>=1.76.0",
"pytest>=8.0.0",
"pytest-asyncio>=0.24.0",
"pytest-cov>=6.1.1",
"httpx>=0.25.2",
"psutil>=5.9.0",
"aiohttp>=3.9.0",
"pytest-benchmark>=4.0.0",
"routstr",
]
[tool.pytest.ini_options]
testpaths = ["tests"]
python_files = "test_*.py"
python_classes = "Test*"
python_functions = "test_*"
asyncio_mode = "auto"
asyncio_default_fixture_loop_scope = "function"
addopts = [
"-v",
"--tb=short",
"--strict-markers",
"--disable-warnings",
"-p",
"no:warnings",
]
markers = [
"asyncio: marks tests as async (deselect with '-m \"not asyncio\"')",
"integration: marks tests as integration tests (deselect with '-m \"not integration\"')",
"unit: marks tests as unit tests",
"slow: marks tests as slow running (deselect with '-m \"not slow\"')",
"requires_real_mint: marks tests that require a running Cashu mint instance",
"requires_docker: marks tests that require Docker services running (deselect with '-m \"not requires_docker\"')",
"performance: marks tests that measure performance metrics",
]
[build-system]
requires = ["setuptools", "wheel"]
build-backend = "setuptools.build_meta"
[tool.setuptools]
packages = ["routstr"]
[tool.ruff.lint]
select = ["E", "F", "I"]
ignore = ["E501"]
exclude = ["examples"]
[tool.mypy]
python_version = "3.11"
ignore_missing_imports = true
disallow_untyped_defs = true
check_untyped_defs = true
disallow_untyped_calls = true
disallow_incomplete_defs = true
disallow_untyped_decorators = true
[tool.uv.sources]
routstr = { workspace = true }
# Security overrides (2026-09): cashu 0.20.x pins conservative upper bounds
# (httpx<0.26, h11<0.15, fastapi<0.116, cryptography<44, setuptools<76,
# wheel<0.42) that conflict with patched versions of these libraries.
# routstr only imports cashu's wallet-side modules, which do not exercise
# the fastapi/starlette/h11 server paths cashu's caps were set for.
[tool.uv]
override-dependencies = [
"httpx[socks]>=0.28.0,<1.0", # litellm>=1.84 requires httpx>=0.28 (cashu caps <0.26)
"importlib-metadata>=8.0.0,<9.0", # litellm>=1.84 requires >=8.0 (cashu caps <7.0)
"h11>=0.16.0", # CVE-2025-43859: chunked-encoding smuggling (critical)
"fastapi[standard]>=0.141", # needed for starlette>=1.3.1 line (cashu caps <0.116)
"cryptography>=49.0.0", # GHSA-jwv3-5hgf-82ww et al. (cashu caps <44)
"setuptools>=83.0.0", # CVE-2026-59890, CVE-2025-47273 (cashu caps <76)
"wheel>=0.46.2", # CVE-2026-24049 (cashu caps <0.42)
]
# Floors for transitive deps whose locked versions are still in-range for
# their dependents but below the patched versions. Constraints (unlike
# overrides) don't bypass any upstream pins — they only force the resolver
# to take the fixed versions.
constraint-dependencies = [
"starlette>=1.3.1", # CVE-2026-54283, CVE-2026-48818, CVE-2026-48817, CVE-2026-48710, CVE-2025-62727, CVE-2025-54121
]