Azure / Azure/azure-functions-python-worker
Protobuf and gRPC Version Updates for Python 3.9 - 3.12
- 主要言語
- Python
- スター
- 357
- フォーク
- 116
- 平均マージ
- 32分
- マージ済み PR(30日)
- 1
説明
## Summary
Due to a critical security vulnerability ([CVE-2026-0994](https://nvd.nist.gov/vuln/detail/CVE-2026-0994)) discovered in `protobuf` versions prior to 5.29.6, we are updating the `protobuf` and `grpcio` dependencies in the Python Worker. This update will be rolled out with host version **4.1052** and may cause breaking changes for some Python function apps.
## What's Changing
The following dependency versions are being updated in the Azure Functions Python Worker:
- **protobuf**: `~=4.25.3` → `~=5.29.6`
- **grpcio**: `~=1.59.0` → `~=1.70.0`
## Who Is Affected
This change may affect you if:
- Your Python function app uses `protobuf` or `grpcio` directly in your code or dependencies
- Your app runs on **Python 3.9, 3.10, 3.11, or 3.12**
- You have pinned specific versions of `protobuf` or `grpcio` in your `requirements.txt` that are incompatible with the new versions
## Rollout Timeline
- **Host Version**: 4.1052
- **Expected Completion**: August 2026
## Potential Impact
After this update is deployed, function apps that depend on older versions of `protobuf` or `grpcio` may experience:
- Runtime errors or import failures
- Type incompatibilities if using protobuf-generated code compiled with older versions
- Breaking changes in gRPC functionality due to API changes between major versions
```
RuntimeError: The grpc package installed is at version 1.37.1, but the generated code in
FunctionRpc_pb2_grpc.py depends on grpcio>=1.70.0.
```
## Mitigation Options
### Option 1: Update Your Dependencies
Update your `requirements.txt` to use compatible versions:
```txt
protobuf~=5.29.6
grpcio~=1.70.0
```
### Option 2: Use Isolated Worker Dependencies
If you need to continue using older versions of `protobuf` or `grpcio`, you can set the `PYTHON_ISOLATE_WORKER_DEPENDENCIES` application setting to `1` to prioritize your app's pinned versions.
### Option 3: Migrate to Python >= 3.13
Migrate your existing function apps to run on Python 3.13 or Python 3.14.
コントリビューションガイド
調査の方向性
ファイル、テスト、エントリーポイントは指定されていません。まず Python Worker の依存関係の宣言を見つけ、Python 3.9–3.12 の依存関係がどのようにテストされているかを確認します。protobuf が ~=5.29.6 に、grpcio が ~=1.70.0 に更新され、対象の worker テストまたは互換性チェックが通れば完了です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- python
- 領域
- backend, security
- issue の種類
- リファクタリング
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 活発さ
- 停滞
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 35/100