Repository navigation
fix(deps): bump openapi-python-client to 0.29.1 past advisory - #377
Conversation
0.29.1 escapes OpenAPI-sourced text in its templates, and the repository's two custom endpoint templates were copies of the 0.29.0 originals that no longer render. Rebase them onto 0.29.1 with the same customizations, regenerate the internal client, and follow the generator's new casing for the CallOAuthProviderApi* models.
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Change
openapi-python-clientgeneratessrc/volcano_sdk/_generatedand is only a dev dependency. Before 0.29.1, a malicious OpenAPI document could make it generate arbitrary code. Our input is Hosting's bundled spec, so the practical risk was low, but the dev pin anduv.lockstill carried the vulnerable release.openapi-python-client(pyproject.tomldev pin anduv.lock)uv lock --upgrade-package openapi-python-clientmoved only this package. Its dependency list is unchanged.scripts/generate_openapi.pyruns whatever version is installed, and nothing else pins the generator.Why this isn't only a lock bump
0.29.1's release notes say all custom templates break, because the fix wraps OpenAPI-sourced strings so templates must escape them explicitly. This repo overrides two templates,
openapi/templates/endpoint_module.py.jinjaandendpoint_macros.py.jinja. Both were copies of the 0.29.0 originals, and with a lock-only bumpscripts/generate_openapi.pycrashed (TypeError: unsupported operand type(s) for +: 'PythonCode' and 'str'). That would have failed thegeneratedfreshness check in CI.request_kwargsandbuild_responsehelper names, andUUID | strfor UUID parameters. The only adaptation is(parameter.to_string() | as_unembedded_code).replace(...), becauseto_string()now returns a wrapper instead of astr. A diff against upstream 0.29.1 shows nothing beyond those customizations, so the upstream escaping fixes now apply here too.src/volcano_sdk/_generatedand is all generator output. I compared each changed module's AST before and after, ignoring docstrings. The only executable change isclient.py, where theset_httpx_client,set_async_httpx_clientand__enter__/__aenter__return annotations change from"Client"/"AuthenticatedClient"totyping.Self. Everything else is text:# noqa: PLC0415on the lazy model imports (420 lines)"instead ofr"""with\"escapescallOAuthProviderAPIoperation, so six models change fromCallOAuthProviderAPI*toCallOAuthProviderApi*, with the same module paths. The handwritten private modules and tests that import them follow the new names. That's 15 lines across_auth_values.py,_transport_auth_account.py,_transport_types.py,_tests/test_state.pyand_tests/test_auth_parser_boundaries.py. These are internal types under_generatedand the private_transport*modules, so the public API doesn't change.Verification
uv run --locked poe checkspasses locally with uv 0.12.17 and CPython 3.12.14:policy: passaudit:No known vulnerabilities foundgenerated:OpenAPI generated client is up to datelint/format-check: passtypes: mypyno issues found in 172 source files, basedpyright0 errorstest/coverage: 2336 passed, 100.00% coveragepackage-check/package-extras: wheel and sdist built, quickstarts passed, all tox package envs OKI didn't run the mutation jobs locally. The handwritten changes are identifier renames only.
Cross-language impact
Classification: none. This is a dev-dependency bump with internal generated-code churn. The wire contract, public facade and behavior don't change.
🤖 Generated with Claude Code