Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Dependencies #87

Merged
merged 1 commit into from
Jun 28, 2023
Merged

Update Dependencies #87

merged 1 commit into from
Jun 28, 2023

Conversation

TimPansino
Copy link
Collaborator

Overview

  • Address CVEs found in dependencies by updating to patched versions.
IN1-PYTHON-AIOHTTP-1584144 - aiohttp
CVE-2021-33503 - urllib3
CVE-2022-23491 - certifi
CVE-2023-32681 - requests
CVE-2021-21330 - aiohttp

@hmstepanek
Copy link

It looks like CVE-2021-33503 is in regards to an issue on urllib3 before 1.26.5 but this was already on 1.26.15 so I'm a little confused how this issue came up. Same with CVE-2021-21330 - this was an issue with aiohttp before 3.7.4 but we were already on 3.7.4.

@TimPansino
Copy link
Collaborator Author

It looks like CVE-2021-33503 is in regards to an issue on urllib3 before 1.26.5 but this was already on 1.26.15 so I'm a little confused how this issue came up. Same with CVE-2021-21330 - this was an issue with aiohttp before 3.7.4 but we were already on 3.7.4.

Odd, GitHub scanning tagged those on master but you're right they don't seem to be affected. Others are still valid.

@TimPansino TimPansino force-pushed the update-dependencies branch 2 times, most recently from 35c41a2 to 4d33133 Compare June 28, 2023 17:14
@TimPansino TimPansino merged commit 1043b44 into master Jun 28, 2023
4 checks passed
@TimPansino TimPansino deleted the update-dependencies branch June 28, 2023 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants