Skip to content

chore(deps): resolve Dependabot security alerts — bump runtime, dev,and CI dependencies - #582

Merged
BinoyOza-okta merged 2 commits into
masterfrom
fix-bump-version
Sep 23, 2026
Merged

BinoyOza-okta merged 2 commits into
masterfrom
fix-bump-version

Conversation

@BinoyOza-okta

Copy link
Copy Markdown
Contributor

Summary

Resolves the open Dependabot security alerts on the repository by upgrading the flagged runtime and development dependencies to their latest secure versions, and bumps actions/setup-python to v7 in both GitHub Actions workflows.

This is a dependency-only change — no SDK code paths, generated models, or API behavior are modified.

Changes

Runtime dependencies

Package Old New
aiohttp 3.13.5 3.14.3
jwcrypto 1.5.7 1.5.8
PyJWT 2.12.1 2.13.0
requests 2.33.0 2.34.2
pillow (extras images) >= 9.0.0, < 12 >= 9.0.0, < 13

Development & testing dependencies

Package Old New
pyfakefs 5.10.2 6.2.0
pytest-asyncio 1.3.0 1.4.0
pytest-randomly 4.0.1 4.1.0
twine 6.2.0 7.0.0

CI

  • actions/setup-python@v6 → actions/setup-python@v7 in both .github/workflows/python-package.yml and .github/workflows/python.yml.

Sources of truth kept in sync

Because the SDK is regenerated from openapi/api.yaml via openapi/generate.sh (OpenAPI Generator 7.7.0), the mustache templates under openapi/templates/ are the ultimate source for the top-level dependency manifests. If we bump only the generated files, the next regeneration would roll the pins back.

Bumped in lock-step:

File Reason
requirements.txt Top-level runtime + dev pins (generated)
test-requirements.txt Top-level test pins (generated)
setup.py install_requires + extras_require["images"] upper bound (generated)
openapi/templates/requirements.mustache Template used to regenerate requirements.txt
openapi/templates/test-requirements.mustache Template for test-requirements.txt
openapi/templates/setup.mustache Template for setup.py
openapi/templates/pyproject.mustache aiohttp floor bumped >= 3.8.4 → >= 3.14.3

Ancillary edits

  • okta/oauth.py and openapi/templates/okta/oauth.mustache: bumped the
    jwcrypto version referenced in the ImportError install-hint string for
    DPoP (>= 1.5.6 → >= 1.5.8) so the message matches the new pinned floor.

Verification

  • pip install -r requirements.txt resolves cleanly.
  • pytest tests/unit/ passes on the bumped stack.
  • Templates and their generated counterparts hold identical version strings.
  • No changes under okta/api/, okta/models/, or openapi/api.yaml — this PR is scoped to dependency management only.

Checklist

  • Only dependency versions and CI action versions changed
  • Templates and generated files kept in lock-step
  • DPoP install-hint string updated to match new jwcrypto floor
  • Unit tests pass on the new stack

Closes #562, #557, #547, #560, #558, #561, #563, #570, #554, #571, #566

…and CI dependencies

Runtime dependencies:
- aiohttp        3.13.5  -> 3.14.3
- jwcrypto       1.5.7   -> 1.5.8
- PyJWT          2.12.1  -> 2.13.0
- requests       2.33.0  -> 2.34.2
- pillow extras  <12     -> <13   (extras_require["images"] upper bound)

Development & testing dependencies:
- pyfakefs        5.10.2 -> 6.2.0
- pytest-asyncio  1.3.0  -> 1.4.0
- pytest-randomly 4.0.1  -> 4.1.0
- twine           6.2.0  -> 7.0.0

CI:
- actions/setup-python v6 -> v7 (both workflows)

Kept in sync across all sources of truth so the next SDK regeneration does not roll versions back:
- requirements.txt, test-requirements.txt, setup.py
- openapi/templates/requirements.mustache
- openapi/templates/test-requirements.mustache
- openapi/templates/setup.mustache
- openapi/templates/pyproject.mustache (aiohttp lower bound 3.8.4 -> 3.14.3)

Also bumped the jwcrypto hint version in the DPoP ImportError message in okta/oauth.py and the corresponding openapi/templates/okta/oauth.mustache so the install hint matches the new pinned floor.

No functional/API changes.

@dhiwakar-okta dhiwakar-okta left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 🚀

@BinoyOza-okta
BinoyOza-okta merged commit 8f6def0 into master Sep 23, 2026
15 checks passed
@BinoyOza-okta
BinoyOza-okta deleted the fix-bump-version branch September 23, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants