-
Notifications
You must be signed in to change notification settings - Fork 836
Comparing changes
Open a pull request
base repository: ietf-tools/datatracker
base: main
head repository: Bbjj88h/datatracker
compare: main
- 8 commits
- 3 files changed
- 2 contributors
Commits on Sep 6, 2024
-
fix: requirements.txt to reduce vulnerabilities
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7886958 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7886959
Configuration menu - View commit details
-
Copy full SHA for 1f1b4cb - Browse repository at this point
Copy the full SHA 1f1b4cbView commit details
Commits on Sep 7, 2024
-
[Snyk] Security upgrade django from 3.2.25 to 4.2.16 (#6)
 ### Snyk has created this PR to fix 2 vulnerabilities in the pip dependencies of this project. #### Snyk changed the following file(s): - `requirements.txt` <details> <summary>
⚠️ <b>Warning</b></summary> ``` xml2rfc 3.23.0 requires platformdirs, which is not installed. xml2rfc 3.23.0 requires configargparse, which is not installed. xml2rfc 3.23.0 requires google-i18n-address, which is not installed. xml2rfc 3.23.0 requires intervaltree, which is not installed. xml2rfc 3.23.0 requires jinja2, which is not installed. xml2rfc 3.23.0 requires pycountry, which is not installed. xml2rfc 3.23.0 has requirement lxml<5.0.0,>=4.9.0, but you have lxml 5.3.0. scout-apm 2.26.1 has requirement urllib3[secure]<2; python_version >= "3.5", but you have urllib3 2.0.7. pydantic-settings 2.0.3 has requirement pydantic>=2.0.1, but you have pydantic 1.10.18. celery 5.3.0 requires kombu, which is not installed. ``` </details> --- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - Max score is 1000. Note that the real score may have changed since the PR was raised. > - This PR was automatically created by Snyk using the credentials of a real user. > - Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0Zjc1MjU0ZS05OWIwLTQ5ZmYtYjI1YS01Mzg0ZmMzMmVmNmMiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjRmNzUyNTRlLTk5YjAtNDlmZi1iMjVhLTUzODRmYzMyZWY2YyJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr) 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates) 🛠 [Adjust project settings](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read about Snyk's upgrade logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Denial of Service (DoS)](https://learn.snyk.io/lesson/no-rate-limiting/?loc=fix-pr) [//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"django","from":"3.2.25","to":"4.2.16"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"}],"prId":"4f75254e-99b0-49ff-b25a-5384fc32ef6c","prPublicId":"4f75254e-99b0-49ff-b25a-5384fc32ef6c","packageManager":"pip","priorityScoreList":[601,631],"projectPublicId":"d094c9a8-e306-4733-ad3f-06eef1488691","projectUrl":"https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","pr-warning-shown","priorityScore"],"type":"auto","upgrade":[],"vulns":["SNYK-PYTHON-DJANGO-7886958","SNYK-PYTHON-DJANGO-7886959"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'Configuration menu - View commit details
-
Copy full SHA for 15797e0 - Browse repository at this point
Copy the full SHA 15797e0View commit details -
fix: requirements.txt to reduce vulnerabilities
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7435780 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436273 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436514 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7436646 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642790 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642791 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642813 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7642814 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7886958 - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7886959 - https://snyk.io/vuln/SNYK-PYTHON-SQLPARSE-6615674
Configuration menu - View commit details
-
Copy full SHA for d98a2e2 - Browse repository at this point
Copy the full SHA d98a2e2View commit details
Commits on Sep 12, 2024
-
fix: package.json & yarn.lock to reduce vulnerabilities
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-SEND-7926862
Configuration menu - View commit details
-
Copy full SHA for 43317e1 - Browse repository at this point
Copy the full SHA 43317e1View commit details
Commits on Sep 14, 2024
-
[Snyk] Security upgrade send from 0.18.0 to 0.19.0 (#8)
 ### Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project. #### Snyk changed the following file(s): - `package.json` - `yarn.lock` #### Note for [zero-installs](https://yarnpkg.com/features/zero-installs) users If you are using the Yarn feature [zero-installs](https://yarnpkg.com/features/zero-installs) that was introduced in Yarn V2, note that this PR does not update the `.yarn/cache/` directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run `yarn` to update the contents of the `./yarn/cache` directory. If you are not using zero-install you can ignore this as your flow should likely be unchanged. #### Vulnerabilities that will be fixed with an upgrade: | | Issue | Score | :-------------------------:|:-------------------------|:-------------------------  | Cross-site Scripting <br/>[SNYK-JS-SEND-7926862](https://snyk.io/vuln/SNYK-JS-SEND-7926862) | **391** --- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - Max score is 1000. Note that the real score may have changed since the PR was raised. > - This PR was automatically created by Snyk using the credentials of a real user. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI5MzdhMjEzMS1lYWY3LTQwM2YtOTZiYS03ODY1M2VmNDA2MjkiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjkzN2EyMTMxLWVhZjctNDAzZi05NmJhLTc4NjUzZWY0MDYyOSJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/bjacentah/project/74a1b366-1ce8-45c5-b68a-45917705af4a?utm_source=github&utm_medium=referral&page=fix-pr) 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates) 🛠 [Adjust project settings](https://app.snyk.io/org/bjacentah/project/74a1b366-1ce8-45c5-b68a-45917705af4a?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read about Snyk's upgrade logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Cross-site Scripting](https://learn.snyk.io/lesson/dom-based-xss/?loc=fix-pr) [//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"send","from":"0.18.0","to":"0.19.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No Known Exploit","id":"SNYK-JS-SEND-7926862","priority_score":391,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"2.1","score":105},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Cross-site Scripting"}],"prId":"937a2131-eaf7-403f-96ba-78653ef40629","prPublicId":"937a2131-eaf7-403f-96ba-78653ef40629","packageManager":"yarn","priorityScoreList":[391],"projectPublicId":"74a1b366-1ce8-45c5-b68a-45917705af4a","projectUrl":"https://app.snyk.io/org/bjacentah/project/74a1b366-1ce8-45c5-b68a-45917705af4a?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","priorityScore"],"type":"auto","upgrade":["SNYK-JS-SEND-7926862"],"vulns":["SNYK-JS-SEND-7926862"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'
Configuration menu - View commit details
-
Copy full SHA for 5534b6f - Browse repository at this point
Copy the full SHA 5534b6fView commit details
Commits on Sep 17, 2024
-
[Snyk] Fix for 11 vulnerabilities (#7)
 ### Snyk has created this PR to fix 11 vulnerabilities in the pip dependencies of this project. #### Snyk changed the following file(s): - `requirements.txt` <details> <summary>
⚠️ <b>Warning</b></summary> ``` xml2rfc 3.23.0 requires platformdirs, which is not installed. xml2rfc 3.23.0 requires configargparse, which is not installed. xml2rfc 3.23.0 requires google-i18n-address, which is not installed. xml2rfc 3.23.0 requires intervaltree, which is not installed. xml2rfc 3.23.0 requires jinja2, which is not installed. xml2rfc 3.23.0 requires pycountry, which is not installed. xml2rfc 3.23.0 has requirement lxml<5.0.0,>=4.9.0, but you have lxml 5.3.0. scout-apm 2.26.1 has requirement urllib3[secure]<2; python_version >= "3.5", but you have urllib3 2.0.7. pydantic-settings 2.0.3 has requirement pydantic>=2.0.1, but you have pydantic 1.10.18. celery 5.3.0 requires kombu, which is not installed. ``` </details> --- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - Max score is 1000. Note that the real score may have changed since the PR was raised. > - This PR was automatically created by Snyk using the credentials of a real user. > - Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0YjA4ODZlOS1hYjA4LTRjYmUtYmUzOS01NjM1YTM3MGJkNDciLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjRiMDg4NmU5LWFiMDgtNGNiZS1iZTM5LTU2MzVhMzcwYmQ0NyJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr) 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates) 🛠 [Adjust project settings](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read about Snyk's upgrade logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Denial of Service (DoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr) 🦉 [Directory Traversal](https://learn.snyk.io/lesson/directory-traversal/?loc=fix-pr) 🦉 [SQL Injection](https://learn.snyk.io/lesson/sql-injection/?loc=fix-pr) 🦉 [More lessons are available in Snyk Learn](https://learn.snyk.io/?loc=fix-pr) [//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"django","from":"3.2.25","to":"4.2.16"},{"name":"sqlparse","from":"0.4.4","to":"0.5.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7435780","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7436273","priority_score":529,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Timing Attack"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7436514","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Directory Traversal"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7436646","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7642790","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7642791","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7642813","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Uncontrolled Resource Consumption"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7642814","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"SQL Injection"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No Known Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial of Service (DoS)"},{"exploit_maturity":"Proof of Concept","id":"SNYK-PYTHON-SQLPARSE-6615674","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled Recursion"}],"prId":"4b0886e9-ab08-4cbe-be39-5635a370bd47","prPublicId":"4b0886e9-ab08-4cbe-be39-5635a370bd47","packageManager":"pip","priorityScoreList":[559,529,559,559,559,559,559,559,601,631,696],"projectPublicId":"d094c9a8-e306-4733-ad3f-06eef1488691","projectUrl":"https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["pr-warning-shown","priorityScore"],"type":"auto","upgrade":[],"vulns":["SNYK-PYTHON-DJANGO-7435780","SNYK-PYTHON-DJANGO-7436273","SNYK-PYTHON-DJANGO-7436514","SNYK-PYTHON-DJANGO-7436646","SNYK-PYTHON-DJANGO-7642790","SNYK-PYTHON-DJANGO-7642791","SNYK-PYTHON-DJANGO-7642813","SNYK-PYTHON-DJANGO-7642814","SNYK-PYTHON-DJANGO-7886958","SNYK-PYTHON-DJANGO-7886959","SNYK-PYTHON-SQLPARSE-6615674"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'Configuration menu - View commit details
-
Copy full SHA for 8c0020d - Browse repository at this point
Copy the full SHA 8c0020dView commit details -
fix: requirements.txt to reduce vulnerabilities
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-SQLPARSE-6615674
Configuration menu - View commit details
-
Copy full SHA for e2b6eff - Browse repository at this point
Copy the full SHA e2b6effView commit details
Commits on Sep 19, 2024
-
[Snyk] Security upgrade sqlparse from 0.4.4 to 0.5.0 (#9)
 ### Snyk has created this PR to fix 1 vulnerabilities in the pip dependencies of this project. #### Snyk changed the following file(s): - `requirements.txt` <details> <summary>
⚠️ <b>Warning</b></summary> ``` xml2rfc 3.23.1 requires platformdirs, which is not installed. xml2rfc 3.23.1 requires configargparse, which is not installed. xml2rfc 3.23.1 requires google-i18n-address, which is not installed. xml2rfc 3.23.1 requires intervaltree, which is not installed. xml2rfc 3.23.1 requires jinja2, which is not installed. xml2rfc 3.23.1 requires pycountry, which is not installed. xml2rfc 3.23.1 has requirement lxml<5.0.0,>=4.9.0, but you have lxml 5.3.0. scout-apm 2.26.1 has requirement urllib3[secure]<2; python_version >= "3.5", but you have urllib3 2.0.7. pydantic-settings 2.0.3 has requirement pydantic>=2.0.1, but you have pydantic 1.10.18. celery 5.3.0 requires kombu, which is not installed. ``` </details> --- > [!IMPORTANT] > > - Check the changes in this PR to ensure they won't cause issues with your project. > - Max score is 1000. Note that the real score may have changed since the PR was raised. > - This PR was automatically created by Snyk using the credentials of a real user. > - Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded. --- **Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs._ For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIxZmY2NWIyOC0zZWJhLTRkMmYtODVlNC02Mjg4NTJmMjNkZTkiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjFmZjY1YjI4LTNlYmEtNGQyZi04NWU0LTYyODg1MmYyM2RlOSJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr) 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates) 🛠 [Adjust project settings](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read about Snyk's upgrade logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr) [//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"sqlparse","from":"0.4.4","to":"0.5.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Proof of Concept","id":"SNYK-PYTHON-SQLPARSE-6615674","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled Recursion"}],"prId":"1ff65b28-3eba-4d2f-85e4-628852f23de9","prPublicId":"1ff65b28-3eba-4d2f-85e4-628852f23de9","packageManager":"pip","priorityScoreList":[696],"projectPublicId":"d094c9a8-e306-4733-ad3f-06eef1488691","projectUrl":"https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","pr-warning-shown","priorityScore"],"type":"auto","upgrade":[],"vulns":["SNYK-PYTHON-SQLPARSE-6615674"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'Configuration menu - View commit details
-
Copy full SHA for f024ef2 - Browse repository at this point
Copy the full SHA f024ef2View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff main...main