fix(security): bump pytest >=9.0.3 in examples/python (ENG-14486)#151
Conversation
- pytest 8.4.2 → 9.0.3 (CVE-2025-71176 — local privilege escalation via /tmp/pytest-of-{user} directory) - Bumped python constraint ^3.9 → ^3.10 (requests >=2.33.0 and pytest >=9.0.3 both require Python >=3.10; 3.9 support was already broken) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 0 minutes and 59 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Vulnerability Fix
CVE-2025-71176 — pytest through 9.0.2 on UNIX relies on directories with the
/tmp/pytest-of-{user}name pattern, which allows local users to cause a denial of service or possibly gain privileges.Changes
pytest = ">=9.0.3"as an explicit dev dependency inexamples/python/pyproject.toml^3.9→^3.10:requests >= 2.33.0already requires Python >=3.10 andpytest >= 9.0.3also requires >=3.10, so Python 3.9 support was effectively already brokenLinear: ENG-14486
Changelog impact summary