Skip to content

chore(deps): update GitPython to 3.2.0 - #220

Merged
landrisek-r7 merged 1 commit into
masterfrom
fix-snyk-vulns-20260921
Oct 1, 2026
Merged

landrisek-r7 merged 1 commit into
masterfrom
fix-snyk-vulns-20260921

Conversation

@landrisek-r7

@landrisek-r7 landrisek-r7 commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

What

Updates the GitPython dependency to the latest release and aligns the pin across both manifests.

Package Was Now
GitPython 3.1.59 (requirements.txt), 3.1.50 (setup.py) 3.2.0

Why

GitPython was declared in two places with different exact pins — requirements.txt (3.1.59) and setup.py install_requires (3.1.50). Both were bumped to 3.2.0 (the current latest) so the runtime and install-time dependency sets stay consistent.

GitPython is used only in version_bump_validator.py (Repo(), remote().refs, tree traversal, blob.data_stream). The 3.2.0 changelog's only breaking changes are dropping Python 3.7 support and deprecating the odbt=GitDB backend — neither applies here (CI runs Python 3.11 and the code never passes odbt).

Verification

  • CI green on the current commit: build, Python lint, unit tests, secret scanning, and Cortex/Renovate config checks all pass.
  • Only the GitPython pin changed, in both requirements.txt and setup.py; version bumped to 2.47.35 with a changelog entry.

Fixes: SOAR-22160 | SOAR-22161 | SOAR-22162

@landrisek-r7
landrisek-r7 requested a review from a team as a code owner September 21, 2026 11:22
@snyk-io

snyk-io Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

lmacoun-r7
lmacoun-r7 previously approved these changes Sep 21, 2026

@joneill-r7 joneill-r7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

in order to release this you need a version bump in the _init_.py and a changelog entry. this has an example #218

@landrisek-r7

Copy link
Copy Markdown
Contributor Author

Addressed review feedback: bumped VERSION to 2.47.35 in icon_validator/__init__.py and added a changelog entry in README.md (following the pattern from #218). Ready for re-review, @joneill-r7.

joneill-r7
joneill-r7 previously approved these changes Sep 23, 2026
Comment thread README.md Outdated

## Changelog

* 2.47.35 - Updated dependencies to resolve Snyk vulnerabilities (`GitPython` 3.1.60)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's not mention vulnerabilities etc as its public library 😃

Suggested change
* 2.47.35 - Updated dependencies to resolve Snyk vulnerabilities (`GitPython` 3.1.60)
* 2.47.35 - Updated dependencies (`GitPython` 3.1.60)

Comment thread requirements.txt Outdated
PyYAML==6.0.1
dacite==1.6.0
GitPython==3.1.59
GitPython==3.1.60

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How about bumping it to at least 3.1.62?

Comment thread README.md Outdated

## Changelog

* 2.47.35 - Updated dependencies to resolve Snyk vulnerabilities (`GitPython` 3.1.60)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since it's a public repo I would suggest to use just a Updated dependencies or similarly like in https://github.com/rapid7/icon-integrations-validators/pull/220/changes#diff-b335630551682c19a781afebcf4d07bf978fb1f8ac04c6bf87428ed5106870f5L66

@landrisek-r7
landrisek-r7 force-pushed the fix-snyk-vulns-20260921 branch 2 times, most recently from 8fda3fc to 922504d Compare September 30, 2026 11:50
igorski-r7
igorski-r7 previously approved these changes Sep 30, 2026

@igorski-r7 igorski-r7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but probably worth testing with building it locally and running over an example plugin 😃

@landrisek-r7

Copy link
Copy Markdown
Contributor Author

@lcwiklinski-r7 both points addressed in the latest commit: bumped GitPython to 3.2.0 (above the suggested 3.1.62) and simplified the changelog wording to just "Updated dependencies". Mind converting to an approval if it looks good? 🙏

lcwiklinski-r7
lcwiklinski-r7 previously approved these changes Sep 30, 2026

@lcwiklinski-r7 lcwiklinski-r7 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, make sure to align description and test it

@landrisek-r7 landrisek-r7 changed the title fix(deps): resolve Snyk vulnerabilities chore(deps): update GitPython to 3.2.0 Sep 30, 2026
@landrisek-r7
landrisek-r7 merged commit a1d9c43 into master Oct 1, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants