Skip to content

fix(api): require patched JWT and HTTP dependencies - #853

Open
xianshijing-lk wants to merge 2 commits into
fix/dependency-security-2026from
fix/api-security-dependencies
Open

xianshijing-lk wants to merge 2 commits into
fix/dependency-security-2026from
fix/api-security-dependencies

Conversation

@xianshijing-lk

Copy link
Copy Markdown
Contributor

Published livekit-api metadata permits old vulnerable PyJWT/aiohttp versions even when the workspace lockfile is updated. Require PyJWT >=2.15.1, aiohttp >=3.14.4 on Python 3.10+, and security floors for idna and multidict. Refresh both the root and local-video example lockfiles. Add a padded-signature regression test for the PyJWT 2.15.0 compatibility issue fixed in 2.15.1.

Preserve Python 3.9 support: it uses aiohttp >=3.13.5 and the last compatible multidict release. Their newer security fixes require Python 3.10+, so known aiohttp/multidict advisories remain on Python 3.9. This PR deliberately does not claim those findings are fixed. SDK users who need the complete HTTP dependency fixes must use Python 3.10+.

Expand API/failover CI to Python 3.9–3.14 and add built-wheel tests on Windows/macOS at the oldest/newest supported Python versions, with both minimum direct dependencies and current releases. Python 3.9 uses pytest 8.4.2 in an explicitly private temporary directory; modern test jobs use patched pytest.

Validation: built API/protocol wheels and sdists; 37 token/webhook/API/failover tests passed in each of 12 fresh environments (Python 3.9–3.14 × lowest-direct/highest); uv pip check passed in every environment; both mypy checks passed; Ruff passed. With the final runtime dependencies, all 163 RTC tests passed against a local LiveKit server (3 skips). The modern Python dependency scan reports no known vulnerabilities; Python 3.9 residual findings are documented above.

Land after the tooling PR. Supersedes the revision-only aiohttp PR #843 and the runtime/example updates from #711. Includes the PyJWT lock update from #841 if it has not landed already. Publish a livekit-api patch release after merging so consumers receive the new dependency requirements; no livekit or livekit-protocol release is required for these metadata changes.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Devin Review: 1 flag

Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant