Azure / Azure/azure-functions-python-worker
Protobuf and gRPC Version Updates for Python 3.9 - 3.12
- Lingua principale
- Python
- Stelle
- 357
- Fork
- 116
- Merge medio
- 32m
- PR unite (30g)
- 1
Descrizione
## Summary
Due to a critical security vulnerability ([CVE-2026-0994](https://nvd.nist.gov/vuln/detail/CVE-2026-0994)) discovered in `protobuf` versions prior to 5.29.6, we are updating the `protobuf` and `grpcio` dependencies in the Python Worker. This update will be rolled out with host version **4.1052** and may cause breaking changes for some Python function apps.
## What's Changing
The following dependency versions are being updated in the Azure Functions Python Worker:
- **protobuf**: `~=4.25.3` → `~=5.29.6`
- **grpcio**: `~=1.59.0` → `~=1.70.0`
## Who Is Affected
This change may affect you if:
- Your Python function app uses `protobuf` or `grpcio` directly in your code or dependencies
- Your app runs on **Python 3.9, 3.10, 3.11, or 3.12**
- You have pinned specific versions of `protobuf` or `grpcio` in your `requirements.txt` that are incompatible with the new versions
## Rollout Timeline
- **Host Version**: 4.1052
- **Expected Completion**: August 2026
## Potential Impact
After this update is deployed, function apps that depend on older versions of `protobuf` or `grpcio` may experience:
- Runtime errors or import failures
- Type incompatibilities if using protobuf-generated code compiled with older versions
- Breaking changes in gRPC functionality due to API changes between major versions
```
RuntimeError: The grpc package installed is at version 1.37.1, but the generated code in
FunctionRpc_pb2_grpc.py depends on grpcio>=1.70.0.
```
## Mitigation Options
### Option 1: Update Your Dependencies
Update your `requirements.txt` to use compatible versions:
```txt
protobuf~=5.29.6
grpcio~=1.70.0
```
### Option 2: Use Isolated Worker Dependencies
If you need to continue using older versions of `protobuf` or `grpcio`, you can set the `PYTHON_ISOLATE_WORKER_DEPENDENCIES` application setting to `1` to prioritize your app's pinned versions.
### Option 3: Migrate to Python >= 3.13
Migrate your existing function apps to run on Python 3.13 or Python 3.14.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Non sono indicati file, test o punti di ingresso. Inizia individuando le dichiarazioni delle dipendenze di Python Worker e verificando come vengono testate le dipendenze di Python 3.9–3.12. Il lavoro è completato quando protobuf è aggiornato a ~=5.29.6, grpcio a ~=1.70.0 e il test del worker interessato o i controlli di compatibilità hanno esito positivo.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- python
- Ambito
- backend, security
- Tipo di issue
- Refactoring
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Stato di attività
- Ferma
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 35/100