Repository navigation
chore(deps): resolve Dependabot security alerts — bump runtime, dev,and CI dependencies - #582
Merged
Merged
Conversation
…and CI dependencies Runtime dependencies: - aiohttp 3.13.5 -> 3.14.3 - jwcrypto 1.5.7 -> 1.5.8 - PyJWT 2.12.1 -> 2.13.0 - requests 2.33.0 -> 2.34.2 - pillow extras <12 -> <13 (extras_require["images"] upper bound) Development & testing dependencies: - pyfakefs 5.10.2 -> 6.2.0 - pytest-asyncio 1.3.0 -> 1.4.0 - pytest-randomly 4.0.1 -> 4.1.0 - twine 6.2.0 -> 7.0.0 CI: - actions/setup-python v6 -> v7 (both workflows) Kept in sync across all sources of truth so the next SDK regeneration does not roll versions back: - requirements.txt, test-requirements.txt, setup.py - openapi/templates/requirements.mustache - openapi/templates/test-requirements.mustache - openapi/templates/setup.mustache - openapi/templates/pyproject.mustache (aiohttp lower bound 3.8.4 -> 3.14.3) Also bumped the jwcrypto hint version in the DPoP ImportError message in okta/oauth.py and the corresponding openapi/templates/okta/oauth.mustache so the install hint matches the new pinned floor. No functional/API changes.
aditya-okta
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves the open Dependabot security alerts on the repository by upgrading the flagged runtime and development dependencies to their latest secure versions, and bumps
actions/setup-pythonto v7 in both GitHub Actions workflows.This is a dependency-only change — no SDK code paths, generated models, or API behavior are modified.
Changes
Runtime dependencies
aiohttpjwcryptoPyJWTrequestspillow(extrasimages)>= 9.0.0, < 12>= 9.0.0, < 13Development & testing dependencies
pyfakefspytest-asynciopytest-randomlytwineCI
actions/setup-python@v6→actions/setup-python@v7in both.github/workflows/python-package.ymland.github/workflows/python.yml.Sources of truth kept in sync
Because the SDK is regenerated from
openapi/api.yamlviaopenapi/generate.sh(OpenAPI Generator 7.7.0), the mustache templates underopenapi/templates/are the ultimate source for the top-level dependency manifests. If we bump only the generated files, the next regeneration would roll the pins back.Bumped in lock-step:
requirements.txttest-requirements.txtsetup.pyinstall_requires+extras_require["images"]upper bound (generated)openapi/templates/requirements.mustacherequirements.txtopenapi/templates/test-requirements.mustachetest-requirements.txtopenapi/templates/setup.mustachesetup.pyopenapi/templates/pyproject.mustacheaiohttpfloor bumped>= 3.8.4→>= 3.14.3Ancillary edits
okta/oauth.pyandopenapi/templates/okta/oauth.mustache: bumped thejwcryptoversion referenced in theImportErrorinstall-hint string forDPoP (
>= 1.5.6→>= 1.5.8) so the message matches the new pinned floor.Verification
pip install -r requirements.txtresolves cleanly.pytest tests/unit/passes on the bumped stack.okta/api/,okta/models/, oropenapi/api.yaml— this PR is scoped to dependency management only.Checklist
jwcryptofloorCloses #562, #557, #547, #560, #558, #561, #563, #570, #554, #571, #566