• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zentralopensource / zentral / 36712050021
91%

Build:
DEFAULT BRANCH: main
Ran 30 Sep 2026 12:10PM UTC
Jobs 1
Files 1035
Run time 3min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

30 Sep 2026 11:05AM UTC coverage: 90.908%. Remained the same
36712050021

push

github

np5
Bump oauthlib to 4.0.0

Security release. 4.0.0 closes two advisories against 3.3.1:

- GHSA-hj66-6f7g-4r5v (CVE-2026-49264), medium: JSONP callback injection in
  the RevocationEndpoint of the OAuth 2.0 provider.
- GHSA-xpv3-w29h-x7cv (CVE-2026-49265), medium: timing attack on the PKCE
  code_verifier comparison of the OAuth 2.0 provider.

Both are in the provider (server) code. Zentral uses oauthlib only as a
client, through requests-oauthlib: OAuth 1 request signing in the MDM DEP
client, and the OAuth 2 flow of google-auth-oauthlib in the Google Workspace
connections. Thus neither advisory is reachable here. The bump removes the
finding from the dependency scanners.

The cost is a major version. The breaking changes are:

- The provider RevocationEndpoint loses enable_jsonp, and the client
  prepare_token_revocation_request loses its callback parameter. Neither
  Zentral, requests-oauthlib 2.0.0 nor google-auth-oauthlib 1.2.4 calls the
  revocation request.
- The provider grant types validate grant_type before client authentication.
  Zentral has no OAuth provider.

The client, OAuth 1 and common modules only have renames of unused local
variables, and oauthlib.oauth2 exports more names, not fewer. InvalidGrantError,
which the Google Workspace tests import, is unchanged.

requests-oauthlib is the only installed package that requires oauthlib, with
oauthlib>=3.0.0 and no upper bound, so no other pin moves. pip check is clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

52832 of 58116 relevant lines covered (90.91%)

0.91 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36712050021.1 30 Sep 2026 12:10PM UTC 1035
90.91
GitHub Action Run
Source Files on build 36712050021
  • Tree
  • List 1035
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36712050021
  • 079329eb on github
  • Prev Build on main (#36483798952)
  • Next Build on main (#36716898383)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc