Azure / Azure/azure-functions-python-worker

Protobuf and gRPC Version Updates for Python 3.9 - 3.12

Abierto
#1,838 0 comentarios 0 reacciones 0 asignados Ver en GitHub
announcement area:python-functions
Lenguaje dominante
Python
Estrellas
357
Forks
116
Merge medio
32 min
PR fusionados (30 d)
1

Descripción

## Summary

Due to a critical security vulnerability ([CVE-2026-0994](https://nvd.nist.gov/vuln/detail/CVE-2026-0994)) discovered in `protobuf` versions prior to 5.29.6, we are updating the `protobuf` and `grpcio` dependencies in the Python Worker. This update will be rolled out with host version **4.1052** and may cause breaking changes for some Python function apps.

## What's Changing

The following dependency versions are being updated in the Azure Functions Python Worker:

- **protobuf**: `~=4.25.3` → `~=5.29.6`
- **grpcio**: `~=1.59.0` → `~=1.70.0`

## Who Is Affected

This change may affect you if:

- Your Python function app uses `protobuf` or `grpcio` directly in your code or dependencies
- Your app runs on **Python 3.9, 3.10, 3.11, or 3.12**
- You have pinned specific versions of `protobuf` or `grpcio` in your `requirements.txt` that are incompatible with the new versions

## Rollout Timeline

- **Host Version**: 4.1052
- **Expected Completion**: August 2026

## Potential Impact

After this update is deployed, function apps that depend on older versions of `protobuf` or `grpcio` may experience:

- Runtime errors or import failures
- Type incompatibilities if using protobuf-generated code compiled with older versions
- Breaking changes in gRPC functionality due to API changes between major versions

```
RuntimeError: The grpc package installed is at version 1.37.1, but the generated code in
FunctionRpc_pb2_grpc.py depends on grpcio>=1.70.0.
```

## Mitigation Options

### Option 1: Update Your Dependencies

Update your `requirements.txt` to use compatible versions:

```txt
protobuf~=5.29.6
grpcio~=1.70.0
```

### Option 2: Use Isolated Worker Dependencies

If you need to continue using older versions of `protobuf` or `grpcio`, you can set the `PYTHON_ISOLATE_WORKER_DEPENDENCIES` application setting to `1` to prioritize your app's pinned versions.

### Option 3: Migrate to Python >= 3.13

Migrate your existing function apps to run on Python 3.13 or Python 3.14.

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

No se nombran archivos, pruebas ni puntos de entrada. Empieza localizando las declaraciones de dependencias de Python Worker y comprobando cómo se prueban las dependencias de Python 3.9–3.12. Se considera terminado cuando protobuf se haya actualizado a ~=5.29.6, grpcio a ~=1.70.0 y la prueba afectada del worker o las comprobaciones de compatibilidad pasen correctamente.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python
Área
backend, security
Tipo de issue
Refactorización
Dificultad
3/5
Tiempo estimado
1-2 días
Estado de actividad
Estancado
Claridad
Necesita aclaración
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.