Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Update sqlalchemy_utils #523

Open
fmigneault opened this issue Sep 2, 2022 · 1 comment
Open

[Security] Update sqlalchemy_utils #523

fmigneault opened this issue Sep 2, 2022 · 1 comment
Labels
security New security features or failing AuthN/AuthZ conditions

Comments

@fmigneault
Copy link
Collaborator

Dependency sqlalchemy_utils<0.38 is reported as vulnerability by safety (ignored via pyup: ignore in requirements).
There is however no version (at this date) that resolves the reported vulnerability.

+==============================================================================+

 REPORT 

  Safety v2.1.1 is scanning for Vulnerabilities...
  Scanning dependencies in your files:

  -> /home/francis/dev/magpie/requirements.txt
  -> /home/francis/dev/magpie/requirements-dev.txt
  -> /home/francis/dev/magpie/requirements-doc.txt
  -> /home/francis/dev/magpie/requirements-sys.txt

  Using non-commercial database
  Found and scanned 14 packages
  Timestamp 2022-09-02 15:52:16
  0 vulnerabilities found
  1 vulnerability ignored

+==============================================================================+
 VULNERABILITIES FOUND 
+==============================================================================+

-> Vulnerability found in sqlalchemy-utils version 0.37.9
   Vulnerability ID: 42194
   This vulnerability is being ignored.
   For more information, please visit
   https://pyup.io/vulnerabilities/PVE-2021-42194/42194/

 Scan was completed. 0 vulnerabilities were found. 1 vulnerability from 1 
 package was ignored. 

+==============================================================================+
@fmigneault fmigneault added the security New security features or failing AuthN/AuthZ conditions label Sep 2, 2022
@fmigneault
Copy link
Collaborator Author

Still no update:
kvesteri/sqlalchemy-utils#166
kvesteri/sqlalchemy-utils#556
https://data.safetycli.com/vulnerabilities/PVE-2021-42194/42194

Leave ignored for now.
No real impact for use case of this repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security New security features or failing AuthN/AuthZ conditions
Projects
None yet
Development

No branches or pull requests

1 participant