chore(deps): update dependency slack-sdk to v3.34.0 #226
Mend Bolt for GitHub / WhiteSource Security Check
failed
Dec 18, 2024 in 2m 15s
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-32731Path to dependency file: /slackbot/requirements.txt Path to vulnerable library: /tmp/ws-ua_20241218004134_TCBFKU/python_JJNOXY/202412180041371/env/lib/python3.8/site-packages/grpcio-1.53.0.dist-info Dependency Hierarchy: -> ❌ grpcio-1.53.0-cp38-cp38-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
High | 7.4 | grpcio-1.53.0-cp38-cp38-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Upgrade to version: grpc - 1.53.1,1.54.2, grpcio - 1.53.1,1.54.2 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-6345 | setuptools-68.0.0-py3-none-any.whl |
Base branch total remaining vulnerabilities: 11
Base branch commit: 05710b03bf16716a4188e013cc219855440149c1
Total libraries scanned: 37
Scan token: 229e45276ce0406e9a730e8e437dcc43
Loading