Skip to content

Conversation

@fderuiter
Copy link
Owner

This PR addresses the CI instability caused by pip-audit timeouts when connecting to api.osv.dev. It implements a retry mechanism and increases the timeout. Additionally, it updates the cryptography package to version 46.0.5 to fix a known vulnerability.

Changes:

  • .github/workflows/main.yml: Added retry loop and increased timeout for pip-audit.
  • poetry.lock: Updated cryptography to 46.0.5.

PR created automatically by Jules for task 7329083919513249467 started by @fderuiter

…bility

- Wrap `pip-audit` in a retry loop (3 attempts) to handle intermittent network timeouts from `api.osv.dev`.
- Increase `pip-audit` timeout to 60 seconds (default 15s).
- Update `cryptography` dependency to version 46.0.5 to resolve a security vulnerability (GHSA-...).

Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
@google-labs-jules
Copy link
Contributor

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

- Fix CI failures by adding retry logic and increasing timeout for `pip-audit`.
- Patch `cryptography` vulnerability by updating to version 46.0.5.
- Bump project version to 0.4.2.

Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
@fderuiter fderuiter marked this pull request as ready for review February 11, 2026 01:13
@fderuiter fderuiter merged commit 0b5ae6c into main Feb 11, 2026
13 checks passed
@fderuiter fderuiter deleted the fix-pip-audit-timeout-7329083919513249467 branch February 11, 2026 01:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant