Skip to content

[Backport release/3.0.0] Harden CI dependencies, update Starlette, and align aiohttp - #7836

Merged
kellyguo11 merged 5 commits into
isaac-sim:release/3.0.0from
kellyguo11:codex/backport-mr8-security-hardening-release-3.0.0
Sep 16, 2026
Merged

kellyguo11 merged 5 commits into
isaac-sim:release/3.0.0from
kellyguo11:codex/backport-mr8-security-hardening-release-3.0.0

Conversation

@kellyguo11

@kellyguo11 kellyguo11 commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Description

Backports the security and supply-chain hardening to release/3.0.0.

  • applies internal MR !8, including checksum verification before the release cuRobo image removes pip or executes the commit-pinned get-pip.py bootstrap
  • installs CI contract-test tools from a complete hash-locked, wheel-only requirements file
  • restricts Git LFS downloads and redirects to HTTPS
  • raises Starlette to >=1.3.1
  • pins aiohttp to ==3.14.1 to match isaacsim-kernel==6.1.0.0
  • adds dependency-selection and supply-chain regression coverage

Develop PR: #7835

Type of change

  • Bug fix (non-breaking change which fixes an issue)

Release backport

  • Already targets release/3.0.0

Screenshots

Not applicable.

Validation

  • Docker/security contract tests: 48 passed, 14 subtests passed
  • Full pre-commit suite passed
  • Changelog fragment validation passed
  • uv lock --check passed
  • Independently verified the pinned get-pip.py digest

Checklist

  • I have read and understood the contribution guidelines
  • I have run the pre-commit checks
  • Documentation is not required for this dependency and CI hardening change
  • My changes generate no new warnings
  • I have added tests that prove the fix is effective
  • I have added a changelog fragment for the affected package
  • My name already exists in CONTRIBUTORS.md

@kellyguo11
kellyguo11 requested a review from a team September 15, 2026 22:24
@kellyguo11

Copy link
Copy Markdown
Contributor Author

run-ci

@github-actions github-actions Bot added isaac-lab Related to Isaac Lab team infrastructure labels Sep 15, 2026
@isaaclab-bot isaaclab-bot Bot added ci:run-docker Trigger the on-demand Docker and GPU CI workflow and removed ci:run-docker Trigger the on-demand Docker and GPU CI workflow labels Sep 15, 2026
@greptile-apps

greptile-apps Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge; no concrete correctness, security, or workflow failure remains.

Summary

This backport hardens CI and container dependency acquisition while upgrading security-sensitive runtime dependencies.

  • Installs contract-test tooling from a hash-locked, wheel-only requirements closure.
  • Restricts Git LFS and get-pip downloads to HTTPS and verifies downloaded artifacts before installation or destructive cleanup.
  • Raises Starlette and aiohttp minimum versions and overrides Isaac Sim’s older aiohttp pin.
  • Adds regression coverage for dependency selection, checksums, redirect restrictions, and bootstrap ordering.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  CI[CI workflow] --> Venv[Python 3.12 contract environment]
  Lock[Hash-locked test requirements] --> Venv
  Venv --> Tests[Container security contract tests]
  HTTPS[HTTPS-only downloads] --> Verify[SHA-256 verification]
  Verify --> LFS[Install Git LFS]
  Verify --> Cleanup[Remove damaged pip]
  Cleanup --> Bootstrap[Execute commit-pinned get-pip.py]
  Manifest[Dependency constraints] --> Resolve[uv resolution]
  Resolve --> Patched[Starlette 1.3.1+ and aiohttp 3.14.3+]
Loading

Reviews (1) · Last reviewed commit: "Format release security dependency test"

@kellyguo11 kellyguo11 changed the title [Backport release/3.0.0] Harden CI dependencies and update Starlette and aiohttp [Backport release/3.0.0] Harden CI dependencies, update Starlette, and align aiohttp Sep 15, 2026
@kellyguo11

Copy link
Copy Markdown
Contributor Author

run-ci

@isaaclab-bot isaaclab-bot Bot added ci:run-docker Trigger the on-demand Docker and GPU CI workflow and removed ci:run-docker Trigger the on-demand Docker and GPU CI workflow labels Sep 15, 2026

@isaaclab-review-bot isaaclab-review-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Isaac Lab Review Bot

The supply-chain hardening is coherent, but the Starlette dependency change removes an explicitly documented Isaac Sim 6.1 compatibility ceiling and now resolves a major-version jump without documenting or constraining compatibility.

  • Design and architecture: The verified-download flow consistently restricts redirects to HTTPS and verifies checksums before destructive or executable steps. The CI contract-test environment is hash-locked and wheel-only, with the requirements file integrated into change detection.
  • API: The aiohttp pin is synchronized between project metadata, the lockfile, and regression tests. However, starlette>=1.3.1 replaces the prior >=0.46.0,<0.50 compatibility range, allowing the lockfile to select 1.6.0 while Isaac Sim 6.1 remains unchanged. Restore a verified upper bound or document why the broader range remains compatible.
  • Implementation: The cuRobo bootstrap correctly downloads and verifies the pinned script before removing pip or executing it, with cleanup and checksum-failure coverage. The contract-test requirements include the required pytest and YAML dependency closure and are checked with uv pip check.

Minor fixes needed. Posted 1 actionable finding inline.

Automated review; human maintainers own approval decisions.

Comment thread pyproject.toml
"pillow>=12.3.0",
"botocore", # omni.replicator.core S3 backend
"starlette>=0.46.0,<0.50", # livestream; range coexists with isaacsim 6.1
"starlette>=1.3.1", # livestream; minimum patched for current security advisories

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Warning · Api — Starlette Isaac Sim compatibility ceiling removed

The replaced specifier >=0.46.0,<0.50 carried an explicit note that the range must coexist with Isaac Sim 6.1's livestream stack. The new >=1.3.1 removes the ceiling entirely and the lock now resolves 1.6.0, a major-version jump beyond the stated security floor, while isaacsim[all,extscache]==6.1.0.0 is unchanged and aiohttp in the same patch was pinned exactly for kernel alignment. Retain a verified upper bound or record why coexistence still holds.

@kellyguo11

Copy link
Copy Markdown
Contributor Author

run-ci

@isaaclab-bot isaaclab-bot Bot added ci:run-docker Trigger the on-demand Docker and GPU CI workflow and removed ci:run-docker Trigger the on-demand Docker and GPU CI workflow labels Sep 15, 2026
@kellyguo11
kellyguo11 merged commit 581ffe6 into isaac-sim:release/3.0.0 Sep 16, 2026
72 of 89 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

infrastructure isaac-lab Related to Isaac Lab team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants