Repository navigation
fix: allow oauthlib 4.x - #971
Merged
Merged
Conversation
Signed-off-by: Paddy Hannon <pih@ehukai.com> AOS-Session: 01a0f91e-4c76-7691-9cc7-acaa414b4a20 AOS-Session: pi-1790885871-80347-0ea3f429 AOS-Commit-Time: 2026-10-01T20:25:07Z Signed-off-by: Vu Anh Phung <vu.phung@databricks.com> Co-authored-by: Isaac <no-reply@databricks.com>
Signed-off-by: Paddy Hannon <pih@ehukai.com> AOS-Session: pi-1790885871-80347-0ea3f429 AOS-Commit-Time: 2026-10-01T20:33:15Z Signed-off-by: Vu Anh Phung <vu.phung@databricks.com> Co-authored-by: Isaac <no-reply@databricks.com>
Revert formatting-only churn from regenerating the lock with Poetry 2.3.2 so the lock matches the Poetry version CI pins. No dependency changes. Signed-off-by: Vu Anh Phung <vu.phung@databricks.com> Co-authored-by: Isaac <no-reply@databricks.com>
|
Integration tests triggered. View workflow runs. Result posts back here as the "Python Integration Tests" check. |
1 similar comment
|
Integration tests triggered. View workflow runs. Result posts back here as the "Python Integration Tests" check. |
vikrantpuppala
approved these changes
Oct 6, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What type of PR is this?
Description
Widens the
oauthlibconstraint from^3.1.0to>=3.1.0,<5.0.0and locks 4.0.0, so downstream consumers can pick up the fixes for CVE-2026-49264 and CVE-2026-49265, which are only available in oauthlib 4.0.0. Both advisories are in oauthlib's provider-side code. The connector only usesWebApplicationClientandOAuth2Error, which behave the same in 4.0.0. The 3.1.0 floor stays so consumers whose other dependencies cap oauthlib below 4 don't hit resolver conflicts.This carries @hannonpi1228's commits from #966, rebased onto main, so the checks that need repository secrets (DBR LTS Install) can run. Those checks can't run on fork PRs. The extra commit only reverts lock-file formatting churn from Poetry 2.3.2 back to the CI-pinned 2.2.1.
How is this tested?
The full unit suite passes with oauthlib 4.0.0 installed. I ran the four
WebApplicationClientcalls the connector makes under oauthlib 3.3.1 and 4.0.0, and they produce identical output.poetry check --lockpasses with Poetry 2.2.1.Related Tickets & Documents
Closes #964
Based on #966
This pull request and its description were written by Isaac.
This PR was created with GitHub MCP.