Skip to content

fix(deps): remediate Medium Vanta vulns for POT-2290 (aiohttp/GitPython/h2) - #1049

Draft
shmbhvi101 wants to merge 1 commit into
mainfrom
cursor/pot-2290-vanta-vulnerability-fixes-65c5
Draft

fix(deps): remediate Medium Vanta vulns for POT-2290 (aiohttp/GitPython/h2)#1049
shmbhvi101 wants to merge 1 commit into
mainfrom
cursor/pot-2290-vanta-vulnerability-fixes-65c5

Conversation

@shmbhvi101

Copy link
Copy Markdown
Contributor

Vulnerability details

Linear: POT-2290

# Package Vulnerable range Fixed / status Advisory
1 aiohttp (pip) <= 3.14.1 Workspace locks aiohttp==3.14.3; floors >=3.14.3; hygiene stub refresh CVE-2026-59881 / dependabot/374
2 GitPython (pip) <= 3.1.55 Floor raised >=3.1.59; empty legacy/uv.lock removes ghost 3.1.54 dependabot/373
3 GitPython (pip) <= 3.1.56 Same as above dependabot/372
4 aiohttp (pip) <= 3.14.1 Same as #1 CVE-2026-69243 / dependabot/375
5 GitPython (pip) <= 3.1.57 Floor >=3.1.59 dependabot/382
6 h2 (pip) <= 4.4.0 Floor h2>=4.4.1 (CVE-2026-71554); ghost httpx[http2]→h2==4.3.0 cleared via empty legacy lock dependabot/379

Fix summary

  • These Medium findings match the Dependabot alerts remediations already landed in fix(deps): remediate Medium Vanta vulns for POT-2266 (stale legacy/uv.lock + h2) #1048 (POT-2266). Vanta still listed them under POT-2290, so this follow-up refreshes the dependency-graph hygiene stub and tightens the GitPython floor.
  • Bump empty potpie-legacy stub 0.2.00.2.1 (+ matching legacy/uv.lock) so GitHub’s SBOM re-indexes past the deleted-path ghost pins (aiohttp==3.14.1, gitpython==3.1.54, h2==4.3.0).
  • Raise gitpython override/constraint floors 3.1.583.1.59 in root, context-engine, and sandbox manifests + lock metadata.
  • Confirm existing floors remain: aiohttp>=3.14.3, h2>=4.4.1.

Validation

  • Manifest scan: no resolved aiohttp<=3.14.1, gitpython<=3.1.57, or h2<=4.4.0 in any uv.lock
  • Locked aiohttp==3.14.3 in root / context-engine / sandbox locks
  • legacy/uv.lock contains only potpie-legacy==0.2.1
  • OSV: aiohttp@3.14.3, GitPython@3.1.59, h2@4.4.1 → 0 vulns

Review

Please review: @yashkrishan
(Automated requested_reviewers API may return 403 for this integration token.)

Do not mark Linear Done — Vanta poller closes when findings clear.

Linear note

Linear MCP auth / LINEAR_API_KEY is unavailable in this cloud agent environment, so POT-2290 could not be moved to In Progress or commented on automatically. After authenticating Linear MCP or adding LINEAR_API_KEY, please comment with this PR URL.

Linear Issue: POT-2290

Open in Web Open in Cursor 

Confirm Medium Vanta remediations for potpie-ai/potpie (same Dependabot
alerts as #1048): aiohttp>=3.14.3, gitpython>=3.1.59, h2>=4.4.1, and bump
the empty potpie-legacy hygiene stub 0.2.0 -> 0.2.1 so GitHub's dependency
graph refreshes past the ghost legacy/uv.lock pins.

Linear: POT-2290

Co-authored-by: Shambhavi Shinde <shmbhvi101@users.noreply.github.com>
@linear-code

linear-code Bot commented Aug 12, 2026

Copy link
Copy Markdown

POT-2290

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: a55a0b03-be3a-4109-ae13-bbb54e60f49f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants