Skip to content

fix(doctest): bump click version to address CVE-2026-7246 - #5792

Closed
dai-chen wants to merge 1 commit into
opensearch-project:mainfrom
dai-chen:fix/doctest-click-cve
Closed

dai-chen wants to merge 1 commit into
opensearch-project:mainfrom
dai-chen:fix/doctest-click-cve

Conversation

@dai-chen

Copy link
Copy Markdown
Collaborator

Description

Bumps click from 7.1.2 to >=8.3.3 in doctest/requirements.txt to address CVE-2026-7246 (command injection in click.edit(), fixed in click 8.3.3). Test-only doctest dependency; not part of the shipped runtime.

Related Issues

#5445

Check List

  • New functionality includes testing.
  • New functionality has been documented.
  • New functionality has javadoc added.
  • New functionality has a user manual doc added.
  • New PPL command checklist all confirmed.
  • API changes companion pull request created.
  • Commits are signed per the DCO using --signoff or -s.
  • Public documentation issue/PR created.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
For more information on following Developer Certificate of Origin and signing off your commits, please check here.

click 7.1.2 is affected by CVE-2026-7246 (command injection in
click.edit(), fixed in 8.3.3). click >= 8.2 requires Python >= 3.10,
while doctest/bootstrap.sh resolves to Python 3.9 in the Linux CI
container, so the patched release cannot be required unconditionally.
Use environment markers, mirroring sql-cli's 1.0-legacy setup.py.

click is a test-only doctest dependency and the vulnerable click.edit()
API is not used; test_docs.py only calls click.echo().

Signed-off-by: Chen Dai <daichen@amazon.com>
@dai-chen dai-chen self-assigned this Sep 22, 2026
@dai-chen dai-chen added the dependencies Pull requests that update a dependency file label Sep 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

PR Code Analyzer ❗

AI-powered 'Code-Diff-Analyzer' found issues on commit 7cc75c1.

PathLineSeverityDescription
doctest/requirements.txt3highDependency version change: 'click' is upgraded from a pinned version (==7.1.2) to open-ended version ranges (>=8.3.3 and >=8.1.8,<8.2). The comment references CVE-2026-7246 as justification, but this CVE cannot be verified here. Open-ended lower bounds (>=8.3.3) allow any future click release to be pulled in, increasing supply chain exposure. Maintainers should verify the CVE exists, confirm the minimum versions cited are sufficient mitigations, and consider tighter upper-bound pins to limit future drift.

The table above displays the top 10 most important findings.

Total: 1 | Critical: 0 | High: 1 | Medium: 0 | Low: 0


Pull Requests Author(s): Please update your Pull Request according to the report above.

Repository Maintainer(s): You can bypass diff analyzer by adding label skip-diff-analyzer after reviewing the changes carefully, then re-run failed actions. To re-enable the analyzer, remove the label, then re-run all actions.


⚠️ Note: The Code-Diff-Analyzer helps protect against potentially harmful code patterns. Please ensure you have thoroughly reviewed the changes beforehand.

Thanks.

@codecov

codecov Bot commented Sep 22, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 63.26%. Comparing base (a29cf85) to head (7cc75c1).
⚠️ Report is 1 commits behind head on main.

❌ Your project check has failed because the head coverage (63.26%) is below the target coverage (99.00%). You can increase the head coverage or adjust the target coverage.

Additional details and impacted files
@@             Coverage Diff              @@
##               main    #5792      +/-   ##
============================================
+ Coverage     63.24%   63.26%   +0.01%     
- Complexity     8820     8823       +3     
============================================
  Files           938      938              
  Lines         40211    40217       +6     
  Branches       4530     4532       +2     
============================================
+ Hits          25432    25442      +10     
+ Misses        13957    13951       -6     
- Partials        822      824       +2     
Flag Coverage Δ
sql-engine 63.26% <ø> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dai-chen dai-chen closed this Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant