workflows: drop requests dependency from p2pool hash verification
What changed, and why it matters
This commit fixes a broken GitHub workflow script that verifies P2Pool software hashes. The script previously used the third-party 'requests' library, which is not installed on the slim Ubuntu runner used by the project. The change switches to Python's built-in 'urllib' library so the automated check can run again. It is a reliability/maintenance fix, not a security vulnerability patch.
No security action required. Treat as routine CI maintenance. Optionally review that urllib's default timeout and TLS handling are acceptable for this internal automation use case.
Security signals we found
No change to cryptographic verification or trust model
No new network endpoints or user-controlled inputs introduced
No secrets, keys, or signatures modified
CI workflow reliability fix only
Evidence from the diff
The commit modifies .github/verify_p2pool.py to replace the external requests dependency with urllib.request.urlopen and json.load for a single GitHub API call. The change is functionally equivalent for fetching JSON from https://api.github.com/repos/SChernykh/p2pool/releases/latest. No cryptographic verification logic, URL endpoints, or trust assumptions were changed. The prior failure mode was a ModuleNotFoundError causing CI to fail, not a bypass of the hash verification.
Changed components
.github/verify_p2pool.pyInspect captured patch +4 / −3
diff --git a/.github/verify_p2pool.py b/.github/verify_p2pool.py
index 2c1de80..0d2ae02 100644
--- a/.github/verify_p2pool.py
+++ b/.github/verify_p2pool.py
@@ -1,6 +1,6 @@
-import requests
+import json
import subprocess
-from urllib.request import urlretrieve
+from urllib.request import urlopen, urlretrieve
import difflib
sech_key = "https://p2pool.io/SChernykh.asc"
@@ -32,7 +32,8 @@ def get_hash(fname):
def main():
global p2pool_files, sech_key, sech_key_backup, sech_key_fp
p2pool_tag_api = "https://api.github.com/repos/SChernykh/p2pool/releases/latest"
- data = requests.get(p2pool_tag_api).json()
+ with urlopen(p2pool_tag_api) as response:
+ data = json.load(response)
tag = data["tag_name"]
head = f"p2pool-{tag}-"
url = f"https://github.com/SChernykh/p2pool/releases/download/{tag}/"
Why this scored 21/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.