Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade dependencies with security releases #2526

Closed
volans- opened this issue Oct 18, 2018 · 1 comment
Closed

Upgrade dependencies with security releases #2526

volans- opened this issue Oct 18, 2018 · 1 comment
Labels
status: accepted This issue has been accepted for implementation type: bug A confirmed report of unexpected behavior in the application

Comments

@volans-
Copy link

volans- commented Oct 18, 2018

GitHub is reporting that 2 of the fixed version dependencies of Netbox have security upgrades and both are marked as high severity by GitHub.

  • Paramiko (CVE-2018-1000805)
    Vulnerable versions: >= 2.4.0, < 2.4.2
    Patched version: 2.4.2

  • pycryptodome (CVE-2018-15560)
    Vulnerable versions: < 3.6.6
    Patched version: 3.6.6

In both cases the requirements.txt file is forcing the exact version and doesn't allow for an easier upgrade.
Take into consideration also the possibility to relax a bit those requirements to allow for patch version upgrades at least.

@jeremystretch jeremystretch added type: bug A confirmed report of unexpected behavior in the application status: accepted This issue has been accepted for implementation labels Oct 22, 2018
@jeremystretch
Copy link
Member

Thank you for the heads up!

@lock lock bot locked as resolved and limited conversation to collaborators Jan 17, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
status: accepted This issue has been accepted for implementation type: bug A confirmed report of unexpected behavior in the application
Projects
None yet
Development

No branches or pull requests

2 participants