Azure / Azure/azure-functions-python-worker

Protobuf and gRPC Version Updates for Python 3.9 - 3.12

オープン
#1,838 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
announcement area:python-functions
主要言語
Python
スター
357
フォーク
116
平均マージ
32分
マージ済み PR(30日)
1

説明

## Summary

Due to a critical security vulnerability ([CVE-2026-0994](https://nvd.nist.gov/vuln/detail/CVE-2026-0994)) discovered in `protobuf` versions prior to 5.29.6, we are updating the `protobuf` and `grpcio` dependencies in the Python Worker. This update will be rolled out with host version **4.1052** and may cause breaking changes for some Python function apps.

## What's Changing

The following dependency versions are being updated in the Azure Functions Python Worker:

- **protobuf**: `~=4.25.3` → `~=5.29.6`
- **grpcio**: `~=1.59.0` → `~=1.70.0`

## Who Is Affected

This change may affect you if:

- Your Python function app uses `protobuf` or `grpcio` directly in your code or dependencies
- Your app runs on **Python 3.9, 3.10, 3.11, or 3.12**
- You have pinned specific versions of `protobuf` or `grpcio` in your `requirements.txt` that are incompatible with the new versions

## Rollout Timeline

- **Host Version**: 4.1052
- **Expected Completion**: August 2026

## Potential Impact

After this update is deployed, function apps that depend on older versions of `protobuf` or `grpcio` may experience:

- Runtime errors or import failures
- Type incompatibilities if using protobuf-generated code compiled with older versions
- Breaking changes in gRPC functionality due to API changes between major versions

```
RuntimeError: The grpc package installed is at version 1.37.1, but the generated code in
FunctionRpc_pb2_grpc.py depends on grpcio>=1.70.0.
```

## Mitigation Options

### Option 1: Update Your Dependencies

Update your `requirements.txt` to use compatible versions:

```txt
protobuf~=5.29.6
grpcio~=1.70.0
```

### Option 2: Use Isolated Worker Dependencies

If you need to continue using older versions of `protobuf` or `grpcio`, you can set the `PYTHON_ISOLATE_WORKER_DEPENDENCIES` application setting to `1` to prioritize your app's pinned versions.

### Option 3: Migrate to Python >= 3.13

Migrate your existing function apps to run on Python 3.13 or Python 3.14.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

ファイル、テスト、エントリーポイントは指定されていません。まず Python Worker の依存関係の宣言を見つけ、Python 3.9–3.12 の依存関係がどのようにテストされているかを確認します。protobuf が ~=5.29.6 に、grpcio が ~=1.70.0 に更新され、対象の worker テストまたは互換性チェックが通れば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
python
領域
backend, security
issue の種類
リファクタリング
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。