Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: ietf-tools/datatracker
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: main
Choose a base ref
...
head repository: Bbjj88h/datatracker
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: main
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 8 commits
  • 3 files changed
  • 2 contributors

Commits on Sep 6, 2024

  1. fix: requirements.txt to reduce vulnerabilities

    The following vulnerabilities are fixed by pinning transitive dependencies:
    - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7886958
    - https://snyk.io/vuln/SNYK-PYTHON-DJANGO-7886959
    snyk-bot committed Sep 6, 2024
    Configuration menu
    Copy the full SHA
    1f1b4cb View commit details
    Browse the repository at this point in the history

Commits on Sep 7, 2024

  1. [Snyk] Security upgrade django from 3.2.25 to 4.2.16 (#6)

    ![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
    
    ### Snyk has created this PR to fix 2 vulnerabilities in the pip
    dependencies of this project.
    
    #### Snyk changed the following file(s):
    
    - `requirements.txt`
    
    
    
    <details>
    <summary>⚠️ <b>Warning</b></summary>
    
    ```
    xml2rfc 3.23.0 requires platformdirs, which is not installed.
    xml2rfc 3.23.0 requires configargparse, which is not installed.
    xml2rfc 3.23.0 requires google-i18n-address, which is not installed.
    xml2rfc 3.23.0 requires intervaltree, which is not installed.
    xml2rfc 3.23.0 requires jinja2, which is not installed.
    xml2rfc 3.23.0 requires pycountry, which is not installed.
    xml2rfc 3.23.0 has requirement lxml<5.0.0,>=4.9.0, but you have lxml 5.3.0.
    scout-apm 2.26.1 has requirement urllib3[secure]<2; python_version >= "3.5", but you have urllib3 2.0.7.
    pydantic-settings 2.0.3 has requirement pydantic>=2.0.1, but you have pydantic 1.10.18.
    celery 5.3.0 requires kombu, which is not installed.
    ```
    
    </details>
    
    
    
    
    
    ---
    
    > [!IMPORTANT]
    >
    > - Check the changes in this PR to ensure they won't cause issues with
    your project.
    > - Max score is 1000. Note that the real score may have changed since
    the PR was raised.
    > - This PR was automatically created by Snyk using the credentials of a
    real user.
    > - Some vulnerabilities couldn't be fully fixed and so Snyk will still
    find them when the project is tested again. This may be because the
    vulnerability existed within more than one direct dependency, but not
    all of the affected dependencies could be upgraded.
    
    ---
    
    **Note:** _You are seeing this because you or someone else with access
    to this repository has authorized Snyk to open fix PRs._
    
    For more information: <img
    src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0Zjc1MjU0ZS05OWIwLTQ5ZmYtYjI1YS01Mzg0ZmMzMmVmNmMiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjRmNzUyNTRlLTk5YjAtNDlmZi1iMjVhLTUzODRmYzMyZWY2YyJ9fQ=="
    width="0" height="0"/>
    🧐 [View latest project
    report](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr)
    📜 [Customise PR
    templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates)
    🛠 [Adjust project
    settings](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings)
    📚 [Read about Snyk's upgrade
    logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities)
    
    ---
    
    **Learn how to fix vulnerabilities with free interactive lessons:**
    
    🦉 [Denial of Service
    (DoS)](https://learn.snyk.io/lesson/no-rate-limiting/?loc&#x3D;fix-pr)
    
    [//]: #
    'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"django","from":"3.2.25","to":"4.2.16"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service
    (DoS)"}],"prId":"4f75254e-99b0-49ff-b25a-5384fc32ef6c","prPublicId":"4f75254e-99b0-49ff-b25a-5384fc32ef6c","packageManager":"pip","priorityScoreList":[601,631],"projectPublicId":"d094c9a8-e306-4733-ad3f-06eef1488691","projectUrl":"https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","pr-warning-shown","priorityScore"],"type":"auto","upgrade":[],"vulns":["SNYK-PYTHON-DJANGO-7886958","SNYK-PYTHON-DJANGO-7886959"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'
    Bbjj88h authored Sep 7, 2024
    Configuration menu
    Copy the full SHA
    15797e0 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    d98a2e2 View commit details
    Browse the repository at this point in the history

Commits on Sep 12, 2024

  1. fix: package.json & yarn.lock to reduce vulnerabilities

    The following vulnerabilities are fixed with an upgrade:
    - https://snyk.io/vuln/SNYK-JS-SEND-7926862
    snyk-bot committed Sep 12, 2024
    Configuration menu
    Copy the full SHA
    43317e1 View commit details
    Browse the repository at this point in the history

Commits on Sep 14, 2024

  1. [Snyk] Security upgrade send from 0.18.0 to 0.19.0 (#8)

    ![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
    
    ### Snyk has created this PR to fix 1 vulnerabilities in the yarn
    dependencies of this project.
    
    #### Snyk changed the following file(s):
    
    - `package.json`
    - `yarn.lock`
    
    
    #### Note for
    [zero-installs](https://yarnpkg.com/features/zero-installs) users
    
    If you are using the Yarn feature
    [zero-installs](https://yarnpkg.com/features/zero-installs) that was
    introduced in Yarn V2, note that this PR does not update the
    `.yarn/cache/` directory meaning this code cannot be pulled and
    immediately developed on as one would expect for a zero-install project
    - you will need to run `yarn` to update the contents of the
    `./yarn/cache` directory.
    If you are not using zero-install you can ignore this as your flow
    should likely be unchanged.
    
    
    
    
    #### Vulnerabilities that will be fixed with an upgrade:
    
    |  | Issue | Score | 
    
    :-------------------------:|:-------------------------|:-------------------------
    ![low
    severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png
    'low severity') | Cross-site Scripting
    <br/>[SNYK-JS-SEND-7926862](https://snyk.io/vuln/SNYK-JS-SEND-7926862) |
    &nbsp;&nbsp;**391**&nbsp;&nbsp;
    
    
    
    
    ---
    
    > [!IMPORTANT]
    >
    > - Check the changes in this PR to ensure they won't cause issues with
    your project.
    > - Max score is 1000. Note that the real score may have changed since
    the PR was raised.
    > - This PR was automatically created by Snyk using the credentials of a
    real user.
    
    ---
    
    **Note:** _You are seeing this because you or someone else with access
    to this repository has authorized Snyk to open fix PRs._
    
    For more information: <img
    src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI5MzdhMjEzMS1lYWY3LTQwM2YtOTZiYS03ODY1M2VmNDA2MjkiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjkzN2EyMTMxLWVhZjctNDAzZi05NmJhLTc4NjUzZWY0MDYyOSJ9fQ=="
    width="0" height="0"/>
    🧐 [View latest project
    report](https://app.snyk.io/org/bjacentah/project/74a1b366-1ce8-45c5-b68a-45917705af4a?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr)
    📜 [Customise PR
    templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates)
    🛠 [Adjust project
    settings](https://app.snyk.io/org/bjacentah/project/74a1b366-1ce8-45c5-b68a-45917705af4a?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings)
    📚 [Read about Snyk's upgrade
    logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities)
    
    ---
    
    **Learn how to fix vulnerabilities with free interactive lessons:**
    
    🦉 [Cross-site
    Scripting](https://learn.snyk.io/lesson/dom-based-xss/?loc&#x3D;fix-pr)
    
    [//]: #
    'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"send","from":"0.18.0","to":"0.19.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-JS-SEND-7926862","priority_score":391,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"2.1","score":105},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Cross-site
    Scripting"}],"prId":"937a2131-eaf7-403f-96ba-78653ef40629","prPublicId":"937a2131-eaf7-403f-96ba-78653ef40629","packageManager":"yarn","priorityScoreList":[391],"projectPublicId":"74a1b366-1ce8-45c5-b68a-45917705af4a","projectUrl":"https://app.snyk.io/org/bjacentah/project/74a1b366-1ce8-45c5-b68a-45917705af4a?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","priorityScore"],"type":"auto","upgrade":["SNYK-JS-SEND-7926862"],"vulns":["SNYK-JS-SEND-7926862"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'
    Bbjj88h authored Sep 14, 2024
    Configuration menu
    Copy the full SHA
    5534b6f View commit details
    Browse the repository at this point in the history

Commits on Sep 17, 2024

  1. [Snyk] Fix for 11 vulnerabilities (#7)

    ![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
    
    ### Snyk has created this PR to fix 11 vulnerabilities in the pip
    dependencies of this project.
    
    #### Snyk changed the following file(s):
    
    - `requirements.txt`
    
    
    
    <details>
    <summary>⚠️ <b>Warning</b></summary>
    
    ```
    xml2rfc 3.23.0 requires platformdirs, which is not installed.
    xml2rfc 3.23.0 requires configargparse, which is not installed.
    xml2rfc 3.23.0 requires google-i18n-address, which is not installed.
    xml2rfc 3.23.0 requires intervaltree, which is not installed.
    xml2rfc 3.23.0 requires jinja2, which is not installed.
    xml2rfc 3.23.0 requires pycountry, which is not installed.
    xml2rfc 3.23.0 has requirement lxml<5.0.0,>=4.9.0, but you have lxml 5.3.0.
    scout-apm 2.26.1 has requirement urllib3[secure]<2; python_version >= "3.5", but you have urllib3 2.0.7.
    pydantic-settings 2.0.3 has requirement pydantic>=2.0.1, but you have pydantic 1.10.18.
    celery 5.3.0 requires kombu, which is not installed.
    ```
    
    </details>
    
    
    
    
    
    ---
    
    > [!IMPORTANT]
    >
    > - Check the changes in this PR to ensure they won't cause issues with
    your project.
    > - Max score is 1000. Note that the real score may have changed since
    the PR was raised.
    > - This PR was automatically created by Snyk using the credentials of a
    real user.
    > - Some vulnerabilities couldn't be fully fixed and so Snyk will still
    find them when the project is tested again. This may be because the
    vulnerability existed within more than one direct dependency, but not
    all of the affected dependencies could be upgraded.
    
    ---
    
    **Note:** _You are seeing this because you or someone else with access
    to this repository has authorized Snyk to open fix PRs._
    
    For more information: <img
    src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI0YjA4ODZlOS1hYjA4LTRjYmUtYmUzOS01NjM1YTM3MGJkNDciLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjRiMDg4NmU5LWFiMDgtNGNiZS1iZTM5LTU2MzVhMzcwYmQ0NyJ9fQ=="
    width="0" height="0"/>
    🧐 [View latest project
    report](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr)
    📜 [Customise PR
    templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates)
    🛠 [Adjust project
    settings](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings)
    📚 [Read about Snyk's upgrade
    logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities)
    
    ---
    
    **Learn how to fix vulnerabilities with free interactive lessons:**
    
    🦉 [Denial of Service
    (DoS)](https://learn.snyk.io/lesson/redos/?loc&#x3D;fix-pr)
    🦉 [Directory
    Traversal](https://learn.snyk.io/lesson/directory-traversal/?loc&#x3D;fix-pr)
    🦉 [SQL
    Injection](https://learn.snyk.io/lesson/sql-injection/?loc&#x3D;fix-pr)
    🦉 [More lessons are available in Snyk
    Learn](https://learn.snyk.io/?loc&#x3D;fix-pr)
    
    [//]: #
    'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"django","from":"3.2.25","to":"4.2.16"},{"name":"sqlparse","from":"0.4.4","to":"0.5.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7435780","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7436273","priority_score":529,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Timing
    Attack"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7436514","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Directory
    Traversal"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7436646","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7642790","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7642791","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7642813","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Uncontrolled
    Resource Consumption"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7642814","priority_score":559,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"SQL
    Injection"},{"exploit_maturity":"No Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886958","priority_score":601,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.3","score":315},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Improper
    Check for Unusual or Exceptional Conditions"},{"exploit_maturity":"No
    Known
    Exploit","id":"SNYK-PYTHON-DJANGO-7886959","priority_score":631,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.9","score":345},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Denial
    of Service (DoS)"},{"exploit_maturity":"Proof of
    Concept","id":"SNYK-PYTHON-SQLPARSE-6615674","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof
    of
    Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled
    Recursion"}],"prId":"4b0886e9-ab08-4cbe-be39-5635a370bd47","prPublicId":"4b0886e9-ab08-4cbe-be39-5635a370bd47","packageManager":"pip","priorityScoreList":[559,529,559,559,559,559,559,559,601,631,696],"projectPublicId":"d094c9a8-e306-4733-ad3f-06eef1488691","projectUrl":"https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["pr-warning-shown","priorityScore"],"type":"auto","upgrade":[],"vulns":["SNYK-PYTHON-DJANGO-7435780","SNYK-PYTHON-DJANGO-7436273","SNYK-PYTHON-DJANGO-7436514","SNYK-PYTHON-DJANGO-7436646","SNYK-PYTHON-DJANGO-7642790","SNYK-PYTHON-DJANGO-7642791","SNYK-PYTHON-DJANGO-7642813","SNYK-PYTHON-DJANGO-7642814","SNYK-PYTHON-DJANGO-7886958","SNYK-PYTHON-DJANGO-7886959","SNYK-PYTHON-SQLPARSE-6615674"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'
    Bbjj88h authored Sep 17, 2024
    Configuration menu
    Copy the full SHA
    8c0020d View commit details
    Browse the repository at this point in the history
  2. fix: requirements.txt to reduce vulnerabilities

    The following vulnerabilities are fixed by pinning transitive dependencies:
    - https://snyk.io/vuln/SNYK-PYTHON-SQLPARSE-6615674
    snyk-bot committed Sep 17, 2024
    Configuration menu
    Copy the full SHA
    e2b6eff View commit details
    Browse the repository at this point in the history

Commits on Sep 19, 2024

  1. [Snyk] Security upgrade sqlparse from 0.4.4 to 0.5.0 (#9)

    ![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
    
    ### Snyk has created this PR to fix 1 vulnerabilities in the pip
    dependencies of this project.
    
    #### Snyk changed the following file(s):
    
    - `requirements.txt`
    
    
    
    <details>
    <summary>⚠️ <b>Warning</b></summary>
    
    ```
    xml2rfc 3.23.1 requires platformdirs, which is not installed.
    xml2rfc 3.23.1 requires configargparse, which is not installed.
    xml2rfc 3.23.1 requires google-i18n-address, which is not installed.
    xml2rfc 3.23.1 requires intervaltree, which is not installed.
    xml2rfc 3.23.1 requires jinja2, which is not installed.
    xml2rfc 3.23.1 requires pycountry, which is not installed.
    xml2rfc 3.23.1 has requirement lxml<5.0.0,>=4.9.0, but you have lxml 5.3.0.
    scout-apm 2.26.1 has requirement urllib3[secure]<2; python_version >= "3.5", but you have urllib3 2.0.7.
    pydantic-settings 2.0.3 has requirement pydantic>=2.0.1, but you have pydantic 1.10.18.
    celery 5.3.0 requires kombu, which is not installed.
    ```
    
    </details>
    
    
    
    
    
    ---
    
    > [!IMPORTANT]
    >
    > - Check the changes in this PR to ensure they won't cause issues with
    your project.
    > - Max score is 1000. Note that the real score may have changed since
    the PR was raised.
    > - This PR was automatically created by Snyk using the credentials of a
    real user.
    > - Some vulnerabilities couldn't be fully fixed and so Snyk will still
    find them when the project is tested again. This may be because the
    vulnerability existed within more than one direct dependency, but not
    all of the affected dependencies could be upgraded.
    
    ---
    
    **Note:** _You are seeing this because you or someone else with access
    to this repository has authorized Snyk to open fix PRs._
    
    For more information: <img
    src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiIxZmY2NWIyOC0zZWJhLTRkMmYtODVlNC02Mjg4NTJmMjNkZTkiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjFmZjY1YjI4LTNlYmEtNGQyZi04NWU0LTYyODg1MmYyM2RlOSJ9fQ=="
    width="0" height="0"/>
    🧐 [View latest project
    report](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr)
    📜 [Customise PR
    templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates)
    🛠 [Adjust project
    settings](https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings)
    📚 [Read about Snyk's upgrade
    logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities)
    
    ---
    
    **Learn how to fix vulnerabilities with free interactive lessons:**
    
    🦉 [Learn about vulnerability in an interactive lesson of Snyk
    Learn.](https://learn.snyk.io/?loc&#x3D;fix-pr)
    
    [//]: #
    'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"sqlparse","from":"0.4.4","to":"0.5.0"}],"env":"prod","issuesToFix":[{"exploit_maturity":"Proof
    of
    Concept","id":"SNYK-PYTHON-SQLPARSE-6615674","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof
    of
    Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Uncontrolled
    Recursion"}],"prId":"1ff65b28-3eba-4d2f-85e4-628852f23de9","prPublicId":"1ff65b28-3eba-4d2f-85e4-628852f23de9","packageManager":"pip","priorityScoreList":[696],"projectPublicId":"d094c9a8-e306-4733-ad3f-06eef1488691","projectUrl":"https://app.snyk.io/org/bjacentah/project/d094c9a8-e306-4733-ad3f-06eef1488691?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","pr-warning-shown","priorityScore"],"type":"auto","upgrade":[],"vulns":["SNYK-PYTHON-SQLPARSE-6615674"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'
    Bbjj88h authored Sep 19, 2024
    Configuration menu
    Copy the full SHA
    f024ef2 View commit details
    Browse the repository at this point in the history
Loading