Skip to content

DAS-2466: Address vulnerabilities in urllib3#58

Merged
jackiryan merged 7 commits intonasa:mainfrom
flamingbear:mhs/DAS-2466/mitigate-urllib3-vulnerabilities
Jan 7, 2026
Merged

DAS-2466: Address vulnerabilities in urllib3#58
jackiryan merged 7 commits intonasa:mainfrom
flamingbear:mhs/DAS-2466/mitigate-urllib3-vulnerabilities

Conversation

@flamingbear
Copy link
Copy Markdown
Member

@flamingbear flamingbear commented Jan 6, 2026

Description

Updates harmony-service-lib to address vulnerability is urllib3.

I updated this to include a release since this is addressing a vulnerability in the service code.

Additionally:

  • updates GitHub workflows to use python 3.12
  • Adds python 3.13 to tests Dependencies are too strict for that...
  • Duplicates .snyk files in appropriate locations. where to place a .snyk

Jira Issue ID

DAS-2466

Local Test Steps

Build and test locally

❯ ./bin/build-image && ./bin/build-test && ./bin/run-test

Deploy to Harmony-In-A-Box and run the regression tests against localhost.

Extra credit: build the new doc environment and run that notebook as well.

PR Acceptance Checklist

  • Jira ticket acceptance criteria met.
  • CHANGELOG.md updated to include high level summary of PR changes.
  • docker/service_version.txt updated if publishing a release.
  • Tests added/updated and passing.
  • Documentation updated (if needed).

@flamingbear flamingbear marked this pull request as ready for review January 6, 2026 23:00
@flamingbear flamingbear requested a review from jackiryan January 6, 2026 23:00
Copy link
Copy Markdown
Collaborator

@jackiryan jackiryan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This all makes sense to me, no notes.

@jackiryan jackiryan merged commit 98f69c7 into nasa:main Jan 7, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants