Skip to content

Bump oauthlib from 3.3.1 to 4.0.0 - #1074

Merged
podkidyshev merged 1 commit into
mainfrom
dependabot/uv/oauthlib-4.0.0
Oct 1, 2026
Merged

podkidyshev merged 1 commit into
mainfrom
dependabot/uv/oauthlib-4.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps oauthlib from 3.3.1 to 4.0.0.

Release notes

Sourced from oauthlib's releases.

4.0.0

Introduction

The release 4.0.0 defines the foundation that enables AI contributions and will improve the maintenance of oauthlib by using AI agents, skills, code for both contributors and maintainers. It includes devcontainer, skills and cleanup of instructions.

What's Changed

Important: this release contains 2 breaking changes. See CHANGELOG.rst for details:

  • Removed JSONP support from token revocation endpoint (#951)
  • Client authentication validation reorganized across grants (#919, #920): the grant_type parameter is now validated before client authentication.

New Contributors

Full Changelog: oauthlib/oauthlib@v3.3.1...v4.0.0

Changelog

Sourced from oauthlib's changelog.

4.0.0 (2026-09-28):

OAuth2.0 Provider:

  • Breaking: #951: Removed JSONP support from token revocation endpoint. JSONP has been superseded by CORS for cross-origin requests. The enable_jsonp parameter has been removed from RevocationEndpoint and the callback parameter has been removed from prepare_token_revocation_request.
  • Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client.
  • #963: Improved PKCE code comparison

Misc:

  • #904: Stop installing examples into site-packages.
  • #930: Add devcontainer, Add Python3.14, Python3.14t.
  • #931: Fix ruff checks about unused variables.
  • #932: Dropped EOL Python 3.8 from CI.
  • #934: Pre-commit hooks autoupdate.
  • #938: Fix typos discovered by typos.
  • Add OAuthLib Maintainer agent for automated issue/PR triage and release management.
Commits
  • 145a9a4 Release 4.0.0: clarify changelog breaking changes and reformat entries
  • c8344d6 Update CHANGELOG.rst
  • e172830 Release 4.0.0: bump version to 4.0.0 and update changelog
  • 40b0ab5 Merge pull request #963 from oauthlib/ft/pkcecode
  • 1b68cea Merge pull request #920 from hekhuisk/validate-client-authentication
  • c951a1d Organized validate_client functions for all grant to avoid mistake in grnat i...
  • 74664d3 Improve PKCE code comparison
  • 9859b05 Merge pull request #950 from oauthlib/feature/3.4.0-maintainer-agent
  • 9bf9b97 Merge branch 'master' into feature/3.4.0-maintainer-agent
  • 1ba7429 Clarify agent instructions
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: NVIDIA/cloudai/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 42016909-725d-4daa-9ae2-af552f889ef9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@podkidyshev

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [oauthlib](https://github.com/oauthlib/oauthlib) from 3.3.1 to 4.0.0.
- [Release notes](https://github.com/oauthlib/oauthlib/releases)
- [Changelog](https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst)
- [Commits](oauthlib/oauthlib@v3.3.1...v4.0.0)

---
updated-dependencies:
- dependency-name: oauthlib
  dependency-version: 4.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/oauthlib-4.0.0 branch from e711e26 to 7e4d1ac Compare October 1, 2026 13:19

@podkidyshev podkidyshev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed oauthlib 3.3.1 -> 4.0.0 on the exact rebased head.

CloudAI reaches oauthlib through kubernetes 35.0.0 -> requests-oauthlib 2.0.0. The relevant use is OAuth2 client refresh of expired OIDC kubeconfigs. CloudAI has no direct oauthlib imports or provider/revocation usage. Documented JSONP/revocation removals and provider authentication-validation changes do not affect this path.

Validation:

  • Both pinned artifact URLs/SHA256 hashes match PyPI metadata; downloaded wheel and sdist hashes verified. Not yanked, Python >=3.9 compatible with CloudAI >=3.10; PyPI reports no affecting vulnerabilities.
  • Publisher provenance identifies oauthlib/oauthlib, python-build.yml. All 75 Python package files match upstream v4.0.0 byte-for-byte. Runtime source diff reviewed; no suspicious changes found.
  • 132 focused Kubernetes, registration, installer and workload tests passed with updated locked environments on Python 3.10 and 3.14.
  • Temporary integration probes passed for both 3.3.1 and 4.0.0 on both Python versions: actual CloudAI KubernetesSystem initialization with expired/unexpired OIDC kubeconfigs, real OAuth2Session refresh request construction and oauthlib response parsing, Basic auth and grant/refresh parameters, rotated credential persistence, all three Kubernetes API clients receiving refreshed tokens, and authenticated bearer requests. Only external HTTP transport was mocked; no live credentials/cluster used.
  • pre-commit uv.lock passes; fresh CI passes lint, full pytest 3.14 and smoke 3.10/3.14.
  • Remote PR tree 013b4525f79384522f80b9ffa8293419e1cf3828 matches locally tested tree. Only three oauthlib substitutions in uv.lock; no code changes.

Safe for CloudAI's examined use. External applications using removed revocation APIs or provider behavior need their own compatibility assessment.

@podkidyshev
podkidyshev merged commit 70b3af8 into main Oct 1, 2026
5 checks passed
@podkidyshev
podkidyshev deleted the dependabot/uv/oauthlib-4.0.0 branch October 1, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant