Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address reported old vulnerable versions: upgrade packages #611

Open
sashakames opened this issue Feb 27, 2024 · 1 comment
Open

Address reported old vulnerable versions: upgrade packages #611

sashakames opened this issue Feb 27, 2024 · 1 comment

Comments

@sashakames
Copy link
Collaborator

root@esgfmeta-test-v4:docker exec -it -u root metagrid_local_django /bin/bash
root@2184f178b41a:/app# pip-audit
Found 6 known vulnerabilities in 5 packages
Name Version ID Fix Versions


cryptography 42.0.0 GHSA-9v9h-cgj8-h64p 42.0.2
cryptography 42.0.0 GHSA-6vqw-3v5j-54x4 42.0.4
django 4.2.7 PYSEC-2024-28 3.2.24,4.2.10,5.0.2
ecdsa 0.18.0 GHSA-wj6h-64fc-37mp
pip 23.0.1 PYSEC-2023-228 23.3
setuptools 58.1.0 PYSEC-2022-43012 65.5.1

@sashakames
Copy link
Collaborator Author

@downiec If these are trivial updates perhaps we include in #592

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant