From 8b0d793713dd69d9a4f6ee3046d20da35d766e0f Mon Sep 17 00:00:00 2001 From: Christian Krakau-Louis Date: Fri, 22 May 2026 23:13:34 +0200 Subject: [PATCH] Fix vulnerable musicround dependencies --- requirements.txt | 3 ++- tests/test_security.py | 24 ++++++++++++++++++++++++ 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/requirements.txt b/requirements.txt index b16db2a..4808b5b 100644 --- a/requirements.txt +++ b/requirements.txt @@ -5,7 +5,8 @@ flask_migrate requests pydub reportlab -PyJWT +PyJWT>=2.10.1 +idna>=3.11 python-dotenv deezer-python Flask-Assets diff --git a/tests/test_security.py b/tests/test_security.py index 005aa4b..c3fb92e 100644 --- a/tests/test_security.py +++ b/tests/test_security.py @@ -124,6 +124,30 @@ class TestDependencySecurity: assert 'authlib>=1.6.5' in content, \ "authlib should be pinned to >= 1.6.5 to fix known vulnerabilities" + def test_pyjwt_version(self): + """Test that PyJWT is at least version 2.10.1.""" + requirements_path = os.path.join( + os.path.dirname(__file__), '..', 'requirements.txt' + ) + + with open(requirements_path, 'r') as f: + content = f.read() + + assert 'PyJWT>=2.10.1' in content, \ + "PyJWT should be pinned to >= 2.10.1 to fix known vulnerabilities" + + def test_idna_version(self): + """Test that idna is at least version 3.11.""" + requirements_path = os.path.join( + os.path.dirname(__file__), '..', 'requirements.txt' + ) + + with open(requirements_path, 'r') as f: + content = f.read() + + assert 'idna>=3.11' in content, \ + "idna should be pinned to >= 3.11 to fix known vulnerabilities" + class TestInputValidation: """Test that user input is properly validated."""