Skip to content

FedRAMP fix(security): bump urllib3 to >=2.7.0 and drop Python 3.9 support - #899

Closed
pvital wants to merge 7 commits into
fedramp-release-v1.0.0from
fedramp-urllib3-cve-fix
Closed

pvital wants to merge 7 commits into
fedramp-release-v1.0.0from
fedramp-urllib3-cve-fix

Conversation

@pvital

@pvital pvital commented Aug 31, 2026

Copy link
Copy Markdown
Member

Summary

This pull request raises the urllib3 lower bound to 2.7.0 across pyproject.toml and all test requirements files to address CVE-2026-44432 and CVE-2026-44431. It also sets requires-python to >=3.10; remove the Python 3.9 classifier and add
Python 3.14 classifier. Finally, it bumps the package version to 3.5.0.post2.

Files Changed

📄 src/instana/version.py

Bumps the package version from 3.5.0.post1 to 3.5.0.post2.


📄 tests/requirements-cassandra.txt

Upgrades the urllib3 minimum version requirement from >=1.26.5 to >=2.7.0.


📄 tests/requirements-gevent-starlette.txt

Upgrades the urllib3 minimum version requirement from >=1.26.5 to >=2.7.0.


📄 tests/requirements-pre314.txt

Upgrades the urllib3 minimum version requirement from >=1.26.5 to >=2.7.0.


📄 tests/requirements.txt

  • Removes the Python <=3.8 conditional pin for aiohttp, consolidating it to a single aiohttp>=3.8.3 requirement for all Python versions.
  • Removes the Python <3.9 conditional pin for sanic, consolidating it to a single sanic>=19.9.0 requirement for all Python versions.
  • Removes the tracerite<=1.1.1 dependency that was conditionally applied for Python <3.9.
  • Upgrades the urllib3 minimum version requirement from >=1.26.5 to >=2.7.0.

📄 tests_aws/01_lambda/conftest.py

Removes an unused import sys statement from the AWS Lambda test configuration file.

@pvital pvital self-assigned this Aug 31, 2026
@pvital
pvital requested a review from a team as a code owner August 31, 2026 13:08
@pvital pvital added fix fedramp Fedramp related changes labels Aug 31, 2026
@pvital
pvital force-pushed the fedramp-urllib3-cve-fix branch 3 times, most recently from 41ea6a0 to b43b53f Compare August 31, 2026 15:03
pvital and others added 4 commits September 1, 2026 04:22
…VE-2026-44432)

- Raise urllib3 lower bound to 2.7.0 across pyproject.toml and all
  test requirements files to address CVE-2026-44432
- Set requires-python to >=3.10; remove Python 3.9 classifier and add
  Python 3.14 classifier
- Remove version-gated test requirements targeting Python < 3.9
  (aiohttp split, sanic pin, tracerite pin)
- Update CircleCI jobs: change jobs dependent on Python 3.9 to 3.12,
  add python 3.14 job.
- Update AWS Lambda compatible-runtimes: remove python3.9, add python3.14
- Remove unused 'import sys' from Lambda test conftest.py

Signed-off-by: Paulo Vital <paulo.vital@ibm.com>
Starlette-1.0.0 removed `on_startup` and `on_shutdown` parameters from
`Starlette` and `Router`, being replaced by `lifespan`.

Signed-off-by: Paulo Vital <paulo.vital@ibm.com>
(cherry picked from commit 2d3c4c8)
Reverting commit e57ab45 as closing the final release of Python 3.14.0.

Signed-off-by: Paulo Vital <paulo.vital@ibm.com>
(cherry picked from commit 5fd729b)
Signed-off-by: Cagri Yonca <cagri@ibm.com>
(cherry picked from commit 3dab401)
@pvital
pvital force-pushed the fedramp-urllib3-cve-fix branch from b43b53f to 68a6a61 Compare September 1, 2026 11:22
GSVarsha and others added 3 commits September 1, 2026 05:15
- `in` fails while `get()` works—the latter normalizes the input before lookup.

Signed-off-by: Varsha GS <varsha.gs@ibm.com>
(cherry picked from commit 770b298)
- Use the documented `HTTPHeaders` interface instead

Signed-off-by: Varsha GS <varsha.gs@ibm.com>
(cherry picked from commit 90c4669)
Signed-off-by: Paulo Vital <paulo.vital@ibm.com>
@pvital
pvital force-pushed the fedramp-urllib3-cve-fix branch from 68a6a61 to 3028ebd Compare September 1, 2026 12:15

@GSVarsha GSVarsha left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me

@CagriYonca CagriYonca left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A question and a typo, other than these looks good

@@ -1,13 +1,13 @@
# (c) Copyright IBM Corp. 2025

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shall we add kafka-python support, too, while already releasing a version of fedramp?

Comment thread docker-compose.yml
- '9094:9094'
image: public.ecr.aws/ubuntu/kafka:3.1-22.04_edge
depends_on: [zookeeper]
ports:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There is an extra space here

Comment thread .circleci/config.yml
- store-coverage-report

py39gevent_starlette:
py12gevent_starlette:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The name should be py312gevent_starlette.

Comment thread .circleci/config.yml
- py39gevent_starlette
py-version: ["3.10", "3.11", "3.12", "3.13"]
- py312cassandra
# - py12gevent_starlette

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as this

Comment thread .circleci/config.yml
- py39cassandra
- py39gevent_starlette
- py312cassandra
# - py12gevent_starlette

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as this

@pvital

pvital commented Sep 1, 2026

Copy link
Copy Markdown
Member Author

Closing this PR since the fix was addressed directly on the Autotrace webhook image.

@pvital pvital closed this Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fedramp Fedramp related changes fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants