Bump oauthlib from 3.3.1 to 4.0.0 - #1074
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: NVIDIA/cloudai/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@dependabot rebase |
Bumps [oauthlib](https://github.com/oauthlib/oauthlib) from 3.3.1 to 4.0.0. - [Release notes](https://github.com/oauthlib/oauthlib/releases) - [Changelog](https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst) - [Commits](oauthlib/oauthlib@v3.3.1...v4.0.0) --- updated-dependencies: - dependency-name: oauthlib dependency-version: 4.0.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
e711e26 to
7e4d1ac
Compare
podkidyshev
left a comment
There was a problem hiding this comment.
Reviewed oauthlib 3.3.1 -> 4.0.0 on the exact rebased head.
CloudAI reaches oauthlib through kubernetes 35.0.0 -> requests-oauthlib 2.0.0. The relevant use is OAuth2 client refresh of expired OIDC kubeconfigs. CloudAI has no direct oauthlib imports or provider/revocation usage. Documented JSONP/revocation removals and provider authentication-validation changes do not affect this path.
Validation:
- Both pinned artifact URLs/SHA256 hashes match PyPI metadata; downloaded wheel and sdist hashes verified. Not yanked, Python >=3.9 compatible with CloudAI >=3.10; PyPI reports no affecting vulnerabilities.
- Publisher provenance identifies oauthlib/oauthlib, python-build.yml. All 75 Python package files match upstream v4.0.0 byte-for-byte. Runtime source diff reviewed; no suspicious changes found.
- 132 focused Kubernetes, registration, installer and workload tests passed with updated locked environments on Python 3.10 and 3.14.
- Temporary integration probes passed for both 3.3.1 and 4.0.0 on both Python versions: actual CloudAI KubernetesSystem initialization with expired/unexpired OIDC kubeconfigs, real OAuth2Session refresh request construction and oauthlib response parsing, Basic auth and grant/refresh parameters, rotated credential persistence, all three Kubernetes API clients receiving refreshed tokens, and authenticated bearer requests. Only external HTTP transport was mocked; no live credentials/cluster used.
- pre-commit uv.lock passes; fresh CI passes lint, full pytest 3.14 and smoke 3.10/3.14.
- Remote PR tree 013b4525f79384522f80b9ffa8293419e1cf3828 matches locally tested tree. Only three oauthlib substitutions in uv.lock; no code changes.
Safe for CloudAI's examined use. External applications using removed revocation APIs or provider behavior need their own compatibility assessment.
Bumps oauthlib from 3.3.1 to 4.0.0.
Release notes
Sourced from oauthlib's releases.
Changelog
Sourced from oauthlib's changelog.
Commits
145a9a4Release 4.0.0: clarify changelog breaking changes and reformat entriesc8344d6Update CHANGELOG.rste172830Release 4.0.0: bump version to 4.0.0 and update changelog40b0ab5Merge pull request #963 from oauthlib/ft/pkcecode1b68ceaMerge pull request #920 from hekhuisk/validate-client-authenticationc951a1dOrganized validate_client functions for all grant to avoid mistake in grnat i...74664d3Improve PKCE code comparison9859b05Merge pull request #950 from oauthlib/feature/3.4.0-maintainer-agent9bf9b97Merge branch 'master' into feature/3.4.0-maintainer-agent1ba7429Clarify agent instructions