Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade cryptography from 3.2.1 to 42.0.8 #207

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

fix: requirements.txt to reduce vulnerabilities

fb33ef5
Select commit
Loading
Failed to load commit list.
Open

[Snyk] Security upgrade cryptography from 3.2.1 to 42.0.8 #207

fix: requirements.txt to reduce vulnerabilities
fb33ef5
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Jun 17, 2024 in 5m 35s

Security Report

You have successfully remediated 10 vulnerabilities, but introduced 14 new vulnerabilities in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2021-41945

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ httpx-0.16.1-py3-none-any.whl (Vulnerable Library)

Critical 9.1 httpx-0.16.1-py3-none-any.whl Upgrade to version: httpx - 0.23.0 None
CVE-2021-32677

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ fastapi-0.61.1-py3-none-any.whl (Vulnerable Library)

High 8.1 fastapi-0.61.1-py3-none-any.whl Upgrade to version: fastapi - 0.65.2 None
WS-2023-0037

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ starlette-0.13.6-py3-none-any.whl (Vulnerable Library)

High 7.5 starlette-0.13.6-py3-none-any.whl Upgrade to version: starlette - 0.25.0 None
CVE-2024-34069

Path to dependency file: /tmp/ws-scm/mergify-engine

Path to vulnerable library: /tmp/ws-scm/mergify-engine

Dependency Hierarchy:

-> ❌ Werkzeug-2.2.3-py3-none-any.whl (Vulnerable Library)

High 7.5 Werkzeug-2.2.3-py3-none-any.whl Upgrade to version: Werkzeug - 3.0.3 None
CVE-2023-46136

Path to dependency file: /tmp/ws-scm/mergify-engine

Path to vulnerable library: /tmp/ws-scm/mergify-engine

Dependency Hierarchy:

-> ❌ Werkzeug-2.2.3-py3-none-any.whl (Vulnerable Library)

High 7.5 Werkzeug-2.2.3-py3-none-any.whl Upgrade to version: werkzeug - 2.3.8,3.0.1 None
CVE-2023-30798

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ starlette-0.13.6-py3-none-any.whl (Vulnerable Library)

High 7.5 starlette-0.13.6-py3-none-any.whl Upgrade to version: starlette - 0.25.0 None
CVE-2023-29159

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ starlette-0.13.6-py3-none-any.whl (Vulnerable Library)

High 7.5 starlette-0.13.6-py3-none-any.whl Upgrade to version: starlette - 0.27.0 None
CVE-2021-29510

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ pydantic-1.6.1-cp37-cp37m-manylinux2014_x86_64.whl (Vulnerable Library)

High 7.5 pydantic-1.6.1-cp37-cp37m-manylinux2014_x86_64.whl Upgrade to version: v1.6.2,v1.7.4,v1.8.2 None
CVE-2024-1135

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ gunicorn-20.0.4-py2.py3-none-any.whl (Vulnerable Library)

High 7.4 gunicorn-20.0.4-py2.py3-none-any.whl Upgrade to version: gunicorn - 20.0.1 None
CVE-2023-32681

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ requests-2.24.0-py2.py3-none-any.whl (Vulnerable Library)

Medium 6.1 requests-2.24.0-py2.py3-none-any.whl Upgrade to version: requests -2.31.0 None
CVE-2021-33880

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ websockets-8.1-cp37-cp37m-manylinux2010_x86_64.whl (Vulnerable Library)

Medium 5.9 websockets-8.1-cp37-cp37m-manylinux2010_x86_64.whl Upgrade to version: websockets - 9.1 None
CVE-2024-35195

Path to dependency file: /tmp/ws-scm/mergify-engine

Path to vulnerable library: /tmp/ws-scm/mergify-engine

Dependency Hierarchy:

-> ❌ requests-2.31.0-py3-none-any.whl (Vulnerable Library)

Medium 5.6 requests-2.31.0-py3-none-any.whl Upgrade to version: requests - 2.32.2 None
CVE-2024-35195

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ requests-2.24.0-py2.py3-none-any.whl (Vulnerable Library)

Medium 5.6 requests-2.24.0-py2.py3-none-any.whl Upgrade to version: requests - 2.32.2 None
WS-2023-0138

Path to dependency file: /requirements.txt

Path to vulnerable library: /requirements.txt

Dependency Hierarchy:

-> ❌ starlette-0.13.6-py3-none-any.whl (Vulnerable Library)

Low 3.7 starlette-0.13.6-py3-none-any.whl Upgrade to version: starlette - 0.27.0 None

✔️ Remediated vulnerabilities:

CVE Vulnerable Library
CVE-2023-2650 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2023-0286 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2020-14422 ipaddress-1.0.23-py2.py3-none-any.whl
CVE-2023-49083 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2023-23931 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2023-3446 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2020-36242 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2023-4807 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2023-38325 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl
CVE-2023-50782 cryptography-3.2.1-cp27-cp27mu-manylinux2010_x86_64.whl

Base branch total remaining vulnerabilities: 26
Base branch commit: null


Total libraries scanned: 100

Scan token: 9649c48932664255ac257771841b2e3d