Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch critical and high severity security vulnerabilities in dependencies #128

Open
wants to merge 38 commits into
base: main
Choose a base branch
from

Conversation

arpitjain099
Copy link

@arpitjain099 arpitjain099 commented Oct 20, 2024

Purpose

This PR fixes critical and high severity security vulnerabilities in dependencies which can also be imported in people cloning and using this repo - so it's important that these vulnerabilities are fixed on time.

You can find details about these changes here -
https://github.com/arpitjain099/openai/pulls?q=is%3Apr+is%3Aclosed+label%3Adependencies

Does this introduce a breaking change?

[ ] Yes
[X] No

Pull Request Type

Security vulnerability patch

[ ] Bugfix
[ ] Feature
[ ] Code style update (formatting, local variables)
[ ] Refactoring (no functional changes, no api changes)
[ ] Documentation content changes
[X] Other... Please describe: Fixing crit

How to Test

  • Get the code
git clone [repo-address]
cd [repo-name]
git checkout [branch-name]
npm install
  • Test the code

What to Check

Verify that the following are valid

  • ...

Other Information

dependabot bot and others added 30 commits October 20, 2024 03:14
Bumps the pip group with 1 update in the /End_to_end_Solutions/AOAISearchDemo/app directory: [azure-identity](https://github.com/Azure/azure-sdk-for-python).


Updates `azure-identity` from 1.13.0b3 to 1.16.1
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-python/blob/main/doc/esrp_release.md)
- [Commits](Azure/azure-sdk-for-python@azure-identity_1.13.0b3...azure-identity_1.16.1)

---
updated-dependencies:
- dependency-name: azure-identity
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps the pip group with 1 update in the /End_to_end_Solutions/AOAISearchDemo/app directory: [langchain](https://github.com/langchain-ai/langchain).


Updates `langchain` from 0.0.139 to 0.2.10
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@v0.0.139...langchain==0.2.10)

---
updated-dependencies:
- dependency-name: langchain
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <[email protected]>
…utions/AOAISearchDemo/app/pip-c2c2e90543

Bump azure-identity from 1.13.0b3 to 1.16.1 in /End_to_end_Solutions/AOAISearchDemo/app in the pip group across 1 directory
…utions/AOAISearchDemo/app/pip-99c25bc862

Bump langchain from 0.0.139 to 0.2.10 in /End_to_end_Solutions/AOAISearchDemo/app in the pip group across 1 directory
---
updated-dependencies:
- dependency-name: aiohttp
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [langchain](https://github.com/langchain-ai/langchain) from 0.0.329 to 0.2.10.
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@v0.0.329...langchain==0.2.10)

---
updated-dependencies:
- dependency-name: langchain
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.0.2 to 3.1.3.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.0.2...3.1.3)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
…o_end_Solutions/AOAISearchDemo/app/frontend/dompurify-3.1.3

Bump dompurify from 3.0.2 to 3.1.3 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
…utions/AOAISearchDemo/notebooks/langchain-0.2.10

Bump langchain from 0.0.329 to 0.2.10 in /End_to_end_Solutions/AOAISearchDemo/notebooks
…utions/AOAIVirtualAssistant/src/notebooks/aiohttp-3.10.2

Bump aiohttp from 3.8.4 to 3.10.2 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [pillow](https://github.com/python-pillow/Pillow) from 10.2.0 to 10.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@10.2.0...10.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [idna](https://github.com/kjd/idna) from 3.4 to 3.7.
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.rst)
- [Commits](kjd/idna@v3.4...v3.7)

---
updated-dependencies:
- dependency-name: idna
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
…utions/AOAIVirtualAssistant/src/notebooks/idna-3.7

Bump idna from 3.4 to 3.7 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
…utions/AOAIVirtualAssistant/src/notebooks/pillow-10.3.0

Bump pillow from 10.2.0 to 10.3.0 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) from 7.20.13 to 7.25.7.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.25.7/packages/babel-traverse)

---
updated-dependencies:
- dependency-name: "@babel/traverse"
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [flask](https://github.com/pallets/flask) from 2.2.2 to 2.2.5.
- [Release notes](https://github.com/pallets/flask/releases)
- [Changelog](https://github.com/pallets/flask/blob/main/CHANGES.rst)
- [Commits](pallets/flask@2.2.2...2.2.5)

---
updated-dependencies:
- dependency-name: flask
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [fonttools](https://github.com/fonttools/fonttools) from 4.39.0 to 4.43.0.
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.39.0...4.43.0)

---
updated-dependencies:
- dependency-name: fonttools
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
…utions/AOAISearchDemo/app/flask-2.2.5

Bump flask from 2.2.2 to 2.2.5 in /End_to_end_Solutions/AOAISearchDemo/app
…lutions/AOAIVirtualAssistant/src/notebooks/fonttools-4.43.0

Bump fonttools from 4.39.0 to 4.43.0 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [black](https://github.com/psf/black) from 23.1.0 to 24.3.0.
- [Release notes](https://github.com/psf/black/releases)
- [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)
- [Commits](psf/black@23.1.0...24.3.0)

---
updated-dependencies:
- dependency-name: black
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
…o_end_Solutions/AOAISearchDemo/app/frontend/babel/traverse-7.25.7

Bump @babel/traverse from 7.20.13 to 7.25.7 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
…lutions/AOAIVirtualAssistant/src/notebooks/black-24.3.0

Bump black from 23.1.0 to 24.3.0 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [rollup](https://github.com/rollup/rollup) from 3.20.6 to 3.29.5.
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v3.20.6...v3.29.5)

---
updated-dependencies:
- dependency-name: rollup
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
arpitjain099 and others added 5 commits October 20, 2024 12:35
…to_end_Solutions/AOAISearchDemo/app/frontend/rollup-3.29.5

Bump rollup from 3.20.6 to 3.29.5 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 4.2.2 to 4.5.5.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v4.5.5/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v4.5.5/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [azure-identity](https://github.com/Azure/azure-sdk-for-python) from 1.12.0 to 1.16.1.
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-python/blob/main/doc/esrp_release.md)
- [Commits](Azure/azure-sdk-for-python@azure-identity_1.12.0...azure-identity_1.16.1)

---
updated-dependencies:
- dependency-name: azure-identity
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
…lutions/AOAISearchDemo/notebooks/azure-identity-1.16.1

Bump azure-identity from 1.12.0 to 1.16.1 in /End_to_end_Solutions/AOAISearchDemo/notebooks
…to_end_Solutions/AOAISearchDemo/app/frontend/vite-4.5.5

Bump vite from 4.2.2 to 4.5.5 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
@arpitjain099
Copy link
Author

Please review @kristapratico @luisquintanilla @colombod

arpitjain099 and others added 3 commits October 20, 2024 12:54
…tion

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…tion

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Fix code scanning alert no. 44: Information exposure through an exception
@arpitjain099
Copy link
Author

Hi @kristapratico @luisquintanilla @colombod
Please review this PR when you can. Thank you!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant