Repository navigation
chore(deps): update PyJWT security constraint to 2.14.0 - #3991
Conversation
Castiron custom codeEvaluated main: ✅ No new custom-code files detected. 46 mixed files remain; 0 existing customizations changed. Compared 46 existing customizations unchanged
6 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 37945804220 --repo openai/openai-python \
--name castiron-custom-code-37945804220-1 --dir /tmp/castiron-custom-code-37945804220-1
git apply --stat /tmp/castiron-custom-code-37945804220-1/custom-code.patch
cat /tmp/castiron-custom-code-37945804220-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin 8bfffd40158460d0f5e651590b95cfef5292d93e 464d1a99990741fde4c72fd9fa9bf8e80f80d794
python3 scripts/castiron/custom_code_report.py report \
--base 8bfffd40158460d0f5e651590b95cfef5292d93e \
--head 464d1a99990741fde4c72fd9fa9bf8e80f80d794 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-464d1a999907
cat /tmp/castiron-custom-code-464d1a999907/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2f395e3c3f
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
… updates Bumps the python-security group with 2 updates in the / directory: [anyio](https://github.com/agronholm/anyio) and [pyjwt](https://github.com/jpadilla/pyjwt). Updates `anyio` from 4.12.1 to 4.14.2 - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.12.1...4.14.2) Updates `pyjwt` from 2.13.0 to 2.14.0 - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.14.0) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: direct:production dependency-group: python-security - dependency-name: pyjwt dependency-version: 2.14.0 dependency-type: indirect dependency-group: python-security ... Signed-off-by: dependabot[bot] <support@github.com>
2f395e3 to
fc6ed7e
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aaa2cf0e07
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Pull request was converted to draft
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5b5a4d9d36
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Narrowed this PR to the PyJWT 2.14.0 contributor security update. Removed the AnyIO lock update and the ineffective checker exception. The separate maintenance PR #3988 refreshes AnyIO to 4.15.1 without changing the published >=4.10.0,<5 range. This preserves compatibility for downstream environments pinned to older supported AnyIO versions and leaves the trusted-base security gate intact. The SDK does not use the affected AnyIO process APIs; its HTTPX2 transport uses IDNA before TLS. Focused built-wheel TLS/transport/streaming/file tests passed with AnyIO 4.10.0. PyJWT is used through contributor Azure tooling, not added to published SDK requirements. The trusted-base security checker passes locally. Watching exact-head CI before approval. |
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Approved after comprehensive dependency and compatibility review of 464d1a9 and green exact-head CI. The final diff updates only contributor PyJWT to 2.14.0, including its matching security constraint; no published runtime dependency, Python floor, SDK API, or AnyIO range changes. Removed the ineffective policy exception and kept the AnyIO refresh in #3988. Verified upstream artifact URLs/hashes/sizes, changelog and build backend. Trusted-base security gate, build, lint, Python 3.10/3.14, HTTPX2, CodeQL, breaking-change and custom-code checks pass. Two consecutive independent clean review rounds; the main merge preserved the reviewed patch ID. Ready for normal protected merge.
Automated Release PR --- ## [3.28.0](openai/openai-python@v3.27.0...v3.28.0) (2026-10-09) ### Features * **api:** add agent environment suspension and expiration ([openai#4046](openai#4046)) ([6aa25a9](openai@6aa25a9)) ### Chores * **deps:** bump astral-sh/setup-uv from 10.1.0 to 10.2.0 ([openai#4026](openai#4026)) ([8bfffd4](openai@8bfffd4)) * **deps:** bump CodeQL init and analyze to 4.38.2 ([openai#4025](openai#4025)) ([4f5e618](openai@4f5e618)) * **deps:** update PyJWT security constraint to 2.14.0 ([openai#3991](openai#3991)) ([aaed2a7](openai@aaed2a7)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Current scope
This PR now updates only the contributor PyJWT security constraint and lock entry to 2.14.0. The SDK runtime requirements, AnyIO minimum, and Python minimum stay unchanged. The AnyIO refresh is covered by maintenance PR #3988; the candidate-only policy exception was removed. The notes below are Dependabot's original batch description and include the AnyIO update that is no longer part of this PR.
Bumps the python-security group with 2 updates in the / directory: anyio and pyjwt.
Updates
anyiofrom 4.12.1 to 4.14.2Release notes
Sourced from anyio's releases.
... (truncated)
Commits
c384f99Bumped up the versiondbba29dFixed 100% CPU spin on cancel scope misuse (#1217)6bbc6c3Fix CapacityLimiter over-granting tokens on asyncio (#1172)6f82b25Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flakybe24b04Relaxed timeouts to fix test flakiness8113506Fix test flakiness caused by slow callback duration logging1e988b6Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (#1...44713f3Pin setup-uv to a commit sha across downstream jobs (#1213)f1b7301Fixed stderr writes in a worker subprocess causing a deadlock (#1207)212be93Fix flaky test_tcp_listener_same_port using a hardcoded port (#1206)Updates
pyjwtfrom 2.13.0 to 2.14.0Release notes
Sourced from pyjwt's releases.
Changelog
Sourced from pyjwt's changelog.