Skip to content

Sync 3.x with main - #401

Closed
broHeryk wants to merge 9 commits into
release/3.xfrom
main
Closed

Sync 3.x with main#401
broHeryk wants to merge 9 commits into
release/3.xfrom
main

Conversation

@broHeryk

@broHeryk broHeryk commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Description

Closes #[ISSUE NUMBER]

Please put here the intent of your pull request.

Dependencies

List the other pull requests that should be merged before/along this one.

Checklist

  • Referenced an issue in the PR title or description
  • Filled properly the description and dependencies, if any
  • Unit tests updated or added
  • Docstrings added or updated
  • Updated the documentation in docsrc folder

catalinsymphony and others added 9 commits September 3, 2025 16:23
* Fix datahose implementation: use datahose api in datahose loop replacing the datafeed api
* Update packages for snyk

* Allow more types of licenses

* Upgrade packages flagged by safety check

* Add flag to skip checking dev deps

* Version increase
* Add MAINTAINERS.md file

Signed-off-by: Juan Estrella <juan.estrella@finos.org>

* Make maintainer email optional

Drop the please-add-email placeholder and label the column Email (optional). Existing addresses are left unchanged.

Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>

* Update MAINTAINERS.md

* Pin GitHub Actions to commit SHAs and fix CVE/license scan findings

Semgrep flagged mutable action tags (checkout/setup-python/cache/upload-artifact)
across all workflows as a supply-chain risk. Safety flagged aiohttp, cryptography,
idna, pyjwt and urllib3 CVEs; bumped cryptography and split aiohttp by Python
version (3.14+ drops py3.9 support), and added -i ignores for findings whose fix
requires dropping Python 3.9, matching the policy already used elsewhere in CI.

* Bump aiohttp, idna, PyJWT minimum versions to fix new CVE findings

Safety flagged CRLF/smuggling CVEs in aiohttp<3.13.4, idna<3.15, and
several PyJWT<2.13.0 issues that weren't yet covered by the CI
workflows' -i ignore lists.

* Add BSD-3-Clause to authorized licenses for liccheck

idna 3.19 report license as 'BSD-3-Clause' string, not 'BSD'.

---------

Signed-off-by: Juan Estrella <juan.estrella@finos.org>
Signed-off-by: Juan Estrella <36825759+TheJuanAndOnly99@users.noreply.github.com>
Co-authored-by: Thibault Pensec <39826516+thibauult@users.noreply.github.com>
Co-authored-by: Thibault Pensec <thibault.pensec@symphony.com>
* Add AI agent example wiring LangGraph + Vertex AI Gemini into a Symphony bot

Mirrors the Java BDK's bdk-ai-agent-example: any message addressed to the bot
is forwarded to a LangGraph ReAct agent backed by Gemini, with BDK-backed
tools for user lookup, room member listing, and sending messages.

* Add opsx commands and openspec skills used to author the AI agent example

* Pin GitHub Actions to commit SHAs and address CVE/license findings

Harden workflows against supply-chain tag mutation by pinning actions to
SHAs, bump cryptography to >=48.0.1 for a CVE fix, allow BSD-3-Clause
license, and add a documented safety-policy exception for CVE 96886
(fix requires urllib3 2.7.0 which drops Python 3.9 support).

* Pin upload-artifact SHA, fix aiohttp CVE coverage for PR checks

Semgrep flagged mutable actions/upload-artifact@v4 tag; safety flagged
aiohttp 3.13.5 CVEs because cve-scanning-python.yml was missing the -i
ignore flags already present in security.yml for py3.9-only findings.
… a patch release. (#397)

Prepares a patch release so consumers can pull the cryptography>=48.0.1
constraint already merged to main via #390, closing CVE-2026-34180 on
downstream Symphony bots that depend on symphony-bdk-python.
Signed-off-by: Juan Estrella <juan.estrella@finos.org>
* Raise cryptography ceiling to allow the patched 50.x

The current constraint, cryptography>=48.0.1,<49.0.0, cannot resolve to a
version free of known CVEs:

  48.0.1  CVE-2026-69247 and CVE-2026-69249
  49.0.0  CVE-2026-69247
  50.0.x  clean

Both CVEs were published 2026-08-03, before 2.11.3 was released, so every
version the released constraint permits is affected. Downstream consumers
cannot work around this: anything satisfying the BDK is vulnerable, and
anything patched fails resolution. It surfaces as a hard failure in image
compliance scanning.

This is the second time in eight days the ceiling has blocked a security
fix. #397 raised it from <47.0.0 to <49.0.0 for CVE-2026-34180, and it is
already stale again.

Verified: the full test suite passes on the new lock and identically on
the old pin, so this is not masking a regression.

  cryptography 48.0.1  560 passed, 3 skipped
  cryptography 50.0.0  560 passed, 3 skipped
  cryptography 50.0.1  560 passed, 3 skipped   (the locked version)

poetry.lock regenerated with Poetry 2.4.2; cryptography 48.0.1 to 50.0.1
is the only package change, none added or removed.

* Bump version to 2.11.4 to prepare a patch release

Included here so merging this PR leaves main release-ready, rather than
needing a second PR before the fix can reach consumers.

The constraint fix in #390 sat unreleased for five days because the
version bump was a separate change (#397). The CVEs this PR addresses
are live in the released 2.11.3, so the gap matters.

Follows the same convention as #397: pyproject.toml only. The lock is
unaffected, project version is not part of its content hash.
@broHeryk broHeryk closed this Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants