Skip to content

chore(deps): update PyJWT security constraint to 2.14.0 - #3991

Merged
jbeckwith-oai merged 12 commits into
mainfrom
dependabot/uv/python-security-b38a5c6da0
Oct 9, 2026
Merged

jbeckwith-oai merged 12 commits into
mainfrom
dependabot/uv/python-security-b38a5c6da0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Current scope

This PR now updates only the contributor PyJWT security constraint and lock entry to 2.14.0. The SDK runtime requirements, AnyIO minimum, and Python minimum stay unchanged. The AnyIO refresh is covered by maintenance PR #3988; the candidate-only policy exception was removed. The notes below are Dependabot's original batch description and include the AnyIO update that is no longer part of this PR.

Bumps the python-security group with 2 updates in the / directory: anyio and pyjwt.

Updates anyio from 4.12.1 to 4.14.2

Release notes

Sourced from anyio's releases.

4.14.2

  • Changed ByteReceiveStream.receive() implementations to raise a ValueError when max_bytes is not a positive integer (#1191)
  • Fixed CapacityLimiter.total_tokens rejecting float("inf") when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (value is math.inf), so only the exact math.inf singleton was accepted, while every backend setter (using math.isinf()) accepts any positive infinity (#1189; PR by @​greymoth-jp).
  • Fixed to_process.run_sync() deadlocking when the worker function writes enough data to sys.stderr to fill the (undrained) pipe buffer. The worker process now redirects sys.stderr to os.devnull as well, matching the documented behavior
  • Fixed TLSStream.wrap() matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (#1208)
  • Fixed anyio.open_process() (and run_process()) ignoring the extra_groups argument, as it mistakenly passed the value of the group argument instead (#1209)
  • Fixed CapacityLimiter.acquire_nowait() and CapacityLimiter.acquire_nowait_on_behalf_of() raising trio.WouldBlock instead of anyio.WouldBlock on the trio backend when there are no tokens available (#1218)
  • Fixed CapacityLimiter on the asyncio backend over-granting tokens (borrowed_tokens exceeding total_tokens and available_tokens going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises WouldBlock (#1170; PR by @​gaoflow)
  • Fixed unnecessary CPU spin when delivering cancellation from CancelScope on asyncio under certain conditions, including improper cancel scope nesting (#1111)

4.14.1

  • Fixed teardown of higher-scoped async fixtures failing on asyncio with RuntimeError: Attempted to exit cancel scope in a different task than it was entered in when an async test raise an outcome exception (e.g., pytest.skip(), pytest.xfail(), or pytest.fail()) (#1179; PR by @​EmmanuelNiyonshuti)
  • Fixed CapacityLimiter.total_tokens rejecting a value of 0 when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (#1183; PR by @​nyxst4ck)

4.14.0

  • Added support for Python 3.15

  • Added an asynchronous implementation of the itertools module (#998; PR by @​11kkw)

  • Added the local_port parameter to connect_tcp() to allow binding to a specific local port before connecting (#1067; PR by @​nullwiz)

  • Added support for custom capacity limiters in async path and file I/O functions and classes

  • Added the create_task() task group method for easier asyncio migration (returns a TaskHandle) (#1098)

  • Changed TaskGroup.start_soon() to return a TaskHandle

  • Added an option for TaskGroup.start() to return a TaskHandle (which then contains the start value in the start_value property)

  • Added the cancel() convenience method to TaskGroup as a shortcut for cancelling the task group's cancel scope

  • Improved the error message when a known backend is not installed to suggest the install command (#1115; PR by @​EmmanuelNiyonshuti)

  • Improved anyio.Path to preserve subclass types by returning Self in methods that return path objects (#1130; PR by @​EmmanuelNiyonshuti)

  • Changed the parameter type annotation in anyio.Path.write_bytes() to accept any ReadableBuffer, thus allowing it to accept bytearray and memoryview to match pathlib.Path.write_bytes() (#1135; PR by @​SAY-5)

  • Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:

    • TaskGroup.start_soon()
    • TaskGroup.start()
    • anyio.from_thread.run()

    This reverts an earlier change from v3.7.0 which was made in error. (#1153)

  • Changed anyio.run to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (#1171; PR by @​gschaffner)

  • Changed several classes (and their subclasses) to have __slots__ (with __weakref__):

    • anyio.CancelScope

... (truncated)

Commits
  • c384f99 Bumped up the version
  • dbba29d Fixed 100% CPU spin on cancel scope misuse (#1217)
  • 6bbc6c3 Fix CapacityLimiter over-granting tokens on asyncio (#1172)
  • 6f82b25 Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky
  • be24b04 Relaxed timeouts to fix test flakiness
  • 8113506 Fix test flakiness caused by slow callback duration logging
  • 1e988b6 Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (#1...
  • 44713f3 Pin setup-uv to a commit sha across downstream jobs (#1213)
  • f1b7301 Fixed stderr writes in a worker subprocess causing a deadlock (#1207)
  • 212be93 Fix flaky test_tcp_listener_same_port using a hardcoded port (#1206)
  • Additional commits viewable in compare view

Updates pyjwt from 2.13.0 to 2.14.0

Release notes

Sourced from pyjwt's releases.

2.14.0

See the 2.14.0 changelog for the complete release details and related security advisories.

Changelog

Sourced from pyjwt's changelog.

v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0>__

Security


- Harden HMAC key validation against public-key material supplied as JWK,
  JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See
  `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__,
  `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__,
  `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__,
  and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__.
- Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing
  redirected destinations from being treated as trusted key sources. See
  `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__.
- Limit repeated JWKS refreshes caused by unknown key IDs while preserving
  normal key-rotation behavior. See
  `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__.
- Handle deeply nested and malformed JWS/JWK input without uncaught recursion
  errors or whole-set parsing failures. See
  `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__
  and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__.
- Enforce compact JWS encoding rules during decoding. See
  `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__.
- Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n
  <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit
  `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__.

Fixed


- Apply HMAC key validation consistently when keys are loaded through
  ``PyJWK`` and ``PyJWKClient``. See
  `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__.
- Reject empty HMAC keys when represented as JWKs.
  See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__.
</code></pre>
</blockquote>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c6fe464b356ff4b1ebc9ba62172d331a40aa27df&quot;&gt;&lt;code&gt;c6fe464&lt;/code&gt;&lt;/a> release: prepare v2.14.0</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f5413029ae7a2e31b1367b5303ea86a2f54ccf42&quot;&gt;&lt;code&gt;f541302&lt;/code&gt;&lt;/a> style: apply Ruff formatting</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/801cd128528c62d9b23fcd161d1a2e1c17982f95&quot;&gt;&lt;code&gt;801cd12&lt;/code&gt;&lt;/a> fix: reject public JWK container HMAC keys</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/af8181ca0bec5e6b372fbba9afbe23702b787ceb&quot;&gt;&lt;code&gt;af8181c&lt;/code&gt;&lt;/a> fix: reject empty HMAC keys from JWKs</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1&quot;&gt;&lt;code&gt;ba4853a&lt;/code&gt;&lt;/a> Throttle repeated PyJWKClient refreshes</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499&quot;&gt;&lt;code&gt;2798504&lt;/code&gt;&lt;/a> fix: reject DER public keys as HMAC secrets</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/8b4e233a22206b34ec1186e912e75c0b2396ac07&quot;&gt;&lt;code&gt;8b4e233&lt;/code&gt;&lt;/a> fix: reject loader-accepted PEM variants</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1f8180a211256dfe5cf32294b6753f554a5a4258&quot;&gt;&lt;code&gt;1f8180a&lt;/code&gt;&lt;/a> fix: format JWS tests</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/cff1ac55fe5f1096fd05295b269fce053ee290ab&quot;&gt;&lt;code&gt;cff1ac5&lt;/code&gt;&lt;/a> Fix redirect handler return annotation</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56&quot;&gt;&lt;code&gt;0a795b8&lt;/code&gt;&lt;/a> Reject redirects in PyJWKClient fetches</li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

@dependabot
dependabot Bot requested a review from a team as a code owner September 29, 2026 19:08
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 29, 2026
@openai-sdks

openai-sdks Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

OkTest Summary

✅ 236/236 SDK tests passed in 10.135s for Python SDK PR #3991.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 295ms
tests/chat-completions-create.test.ts ✅ Passed 253ms
tests/chat-completions-stream.test.ts ✅ Passed 109ms
tests/files-content-binary.test.ts ✅ Passed 169ms
tests/files-create-multipart.test.ts ✅ Passed 143ms
tests/files-list-pagination.test.ts ✅ Passed 152ms
tests/initialize-config.test.ts ✅ Passed 87ms
tests/instance-isolation.test.ts ✅ Passed 121ms
tests/models-list.test.ts ✅ Passed 80ms
tests/responses-background-lifecycle.test.ts ✅ Passed 140ms
tests/responses-body-method-errors.test.ts ✅ Passed 486ms
tests/responses-cancel-timeout.test.ts ✅ Passed 404ms
tests/responses-cancel.test.ts ✅ Passed 225ms
tests/responses-compact-retries.test.ts ✅ Passed 332ms
tests/responses-compact.test.ts ✅ Passed 219ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 281ms
tests/responses-create-advanced.test.ts ✅ Passed 144ms
tests/responses-create-disconnect.test.ts ✅ Passed 1.172s
tests/responses-create-errors.test.ts ✅ Passed 447ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 78ms
tests/responses-create-retries.test.ts ✅ Passed 386ms
tests/responses-create-stream-failures.test.ts ✅ Passed 95ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 191ms
tests/responses-create-stream-wire.test.ts ✅ Passed 2.456s
tests/responses-create-stream.test.ts ✅ Passed 410ms
tests/responses-create-terminal-states.test.ts ✅ Passed 628ms
tests/responses-create-timeout.test.ts ✅ Passed 197ms
tests/responses-create.test.ts ✅ Passed 162ms
tests/responses-delete.test.ts ✅ Passed 153ms
tests/responses-input-items-errors.test.ts ✅ Passed 239ms
tests/responses-input-items-list.test.ts ✅ Passed 208ms
tests/responses-input-items-options.test.ts ✅ Passed 226ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 387ms
tests/responses-input-tokens-count.test.ts ✅ Passed 211ms
tests/responses-malformed-inputs.test.ts ✅ Passed 1.696s
tests/responses-not-found-errors.test.ts ✅ Passed 285ms
tests/responses-parse.test.ts ✅ Passed 222ms
tests/responses-retrieve-retries.test.ts ✅ Passed 246ms
tests/responses-retrieve.test.ts ✅ Passed 203ms
tests/responses-stored-method-errors.test.ts ✅ Passed 1.095s
tests/retry-behavior.test.ts ✅ Passed 3.132s
tests/sdk-error-shape.test.ts ✅ Passed 717ms

View OkTest run #37944162376

SDK merge (44f7ca62032e) · head (464d1a999907) · base (4374b13fc64c) · OkTest (505ac0e34283)

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Castiron custom code

Evaluated main: 8bfffd40158460d0f5e651590b95cfef5292d93e.

✅ No new custom-code files detected.

46 mixed files remain; 0 existing customizations changed.

Compared 4374b13fc64c → 464d1a999907. Generated baselines verified.

46 existing customizations unchanged
  • api.md
  • src/openai/init.py
  • src/openai/_client.py
  • src/openai/resources/audio/transcriptions.py
  • src/openai/resources/audio/translations.py
  • src/openai/resources/beta/agents/environments/files.py
  • src/openai/resources/beta/agents/sessions/artifacts.py
  • src/openai/resources/beta/agents/sessions/sessions.py
  • src/openai/resources/beta/beta.py
  • src/openai/resources/beta/responses/responses.py
  • src/openai/resources/beta/threads/runs/runs.py
  • src/openai/resources/beta/threads/threads.py
  • src/openai/resources/chat/completions/completions.py
  • src/openai/resources/embeddings.py
  • src/openai/resources/files.py
  • src/openai/resources/live/forks.py
  • src/openai/resources/live/live.py
  • src/openai/resources/live/sideband.py
  • src/openai/resources/realtime/api.md
  • src/openai/resources/realtime/realtime.py
  • src/openai/resources/responses/responses.py
  • src/openai/resources/uploads/uploads.py
  • src/openai/resources/vector_stores/file_batches.py
  • src/openai/resources/vector_stores/files.py
  • src/openai/resources/videos.py
  • src/openai/resources/webhooks/init.py
  • src/openai/resources/webhooks/webhooks.py
  • src/openai/types/beta/agent_session_message.py
  • src/openai/types/chat/init.py
  • src/openai/types/chat/chat_completion_message_tool_call.py
  • src/openai/types/fine_tuning/fine_tuning_job_integration.py
  • src/openai/types/realtime/conversation_item_input_audio_transcription_delta_event.py
  • src/openai/types/realtime/realtime_error_event.py
  • src/openai/types/responses/init.py
  • src/openai/types/responses/response.py
  • src/openai/types/responses/response_function_web_search.py
  • src/openai/types/responses/response_function_web_search_param.py
  • src/openai/types/responses/responses_client_event.py
  • src/openai/types/responses/responses_client_event_param.py
  • src/openai/types/responses/tool.py

6 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37945804220 --repo openai/openai-python \
  --name castiron-custom-code-37945804220-1 --dir /tmp/castiron-custom-code-37945804220-1
git apply --stat /tmp/castiron-custom-code-37945804220-1/custom-code.patch
cat /tmp/castiron-custom-code-37945804220-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 8bfffd40158460d0f5e651590b95cfef5292d93e 464d1a99990741fde4c72fd9fa9bf8e80f80d794
python3 scripts/castiron/custom_code_report.py report \
  --base 8bfffd40158460d0f5e651590b95cfef5292d93e \
  --head 464d1a99990741fde4c72fd9fa9bf8e80f80d794 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-464d1a999907
cat /tmp/castiron-custom-code-464d1a999907/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2f395e3c3f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread uv.lock Outdated
… updates

Bumps the python-security group with 2 updates in the / directory: [anyio](https://github.com/agronholm/anyio) and [pyjwt](https://github.com/jpadilla/pyjwt).


Updates `anyio` from 4.12.1 to 4.14.2
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.12.1...4.14.2)

Updates `pyjwt` from 2.13.0 to 2.14.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.14.0)

---
updated-dependencies:
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: direct:production
  dependency-group: python-security
- dependency-name: pyjwt
  dependency-version: 2.14.0
  dependency-type: indirect
  dependency-group: python-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-security-b38a5c6da0 branch from 2f395e3 to fc6ed7e Compare September 30, 2026 00:27
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T14:30:24.996209Z 464d1a9 New commits
🔒 Security Review ✅ Completed 2026-10-09T14:32:05.318387Z 464d1a9 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aaa2cf0e07

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pyproject.toml Outdated
@marcuswood-oai
marcuswood-oai marked this pull request as draft October 1, 2026 21:03
auto-merge was automatically disabled October 1, 2026 21:03

Pull request was converted to draft

@marcuswood-oai
marcuswood-oai marked this pull request as ready for review October 2, 2026 18:15

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5b5a4d9d36

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/check-dependency-security.py Outdated
@jbeckwith-oai

Copy link
Copy Markdown
Contributor

Narrowed this PR to the PyJWT 2.14.0 contributor security update. Removed the AnyIO lock update and the ineffective checker exception. The separate maintenance PR #3988 refreshes AnyIO to 4.15.1 without changing the published >=4.10.0,<5 range. This preserves compatibility for downstream environments pinned to older supported AnyIO versions and leaves the trusted-base security gate intact. The SDK does not use the affected AnyIO process APIs; its HTTPX2 transport uses IDNA before TLS. Focused built-wheel TLS/transport/streaming/file tests passed with AnyIO 4.10.0. PyJWT is used through contributor Azure tooling, not added to published SDK requirements. The trusted-base security checker passes locally. Watching exact-head CI before approval.

@jbeckwith-oai jbeckwith-oai changed the title chore(deps): bump the python-security group across 1 directory with 2 updates chore(deps): update PyJWT security constraint to 2.14.0 Oct 9, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Unknown error
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after comprehensive dependency and compatibility review of 464d1a9 and green exact-head CI. The final diff updates only contributor PyJWT to 2.14.0, including its matching security constraint; no published runtime dependency, Python floor, SDK API, or AnyIO range changes. Removed the ineffective policy exception and kept the AnyIO refresh in #3988. Verified upstream artifact URLs/hashes/sizes, changelog and build backend. Trusted-base security gate, build, lint, Python 3.10/3.14, HTTPX2, CodeQL, breaking-change and custom-code checks pass. Two consecutive independent clean review rounds; the main merge preserved the reviewed patch ID. Ready for normal protected merge.

@jbeckwith-oai
jbeckwith-oai added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit aaed2a7 Oct 9, 2026
28 checks passed
@jbeckwith-oai
jbeckwith-oai deleted the dependabot/uv/python-security-b38a5c6da0 branch October 9, 2026 14:46
@openai-sdks openai-sdks Bot mentioned this pull request Oct 9, 2026
gh-actions-shared Bot pushed a commit to xf-qubit/openai-python that referenced this pull request Oct 9, 2026
Automated Release PR
---


##
[3.28.0](openai/openai-python@v3.27.0...v3.28.0)
(2026-10-09)


### Features

* **api:** add agent environment suspension and expiration
([openai#4046](openai#4046))
([6aa25a9](openai@6aa25a9))


### Chores

* **deps:** bump astral-sh/setup-uv from 10.1.0 to 10.2.0
([openai#4026](openai#4026))
([8bfffd4](openai@8bfffd4))
* **deps:** bump CodeQL init and analyze to 4.38.2
([openai#4025](openai#4025))
([4f5e618](openai@4f5e618))
* **deps:** update PyJWT security constraint to 2.14.0
([openai#3991](openai#3991))
([aaed2a7](openai@aaed2a7))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants