Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive for scrapy Vulnerability #2365

Open
Matthew-Grayson opened this issue Nov 3, 2023 · 1 comment
Open

False Positive for scrapy Vulnerability #2365

Matthew-Grayson opened this issue Nov 3, 2023 · 1 comment

Comments

@Matthew-Grayson
Copy link

An update to your vulnerability database on 18 Sep 2023 causes the latest version of scrapy (2.11.0) to be flagged by mistake. Your code scanning tool cites a 2017 CVE that hasn't been updated since September 2017.

CVE-2017-14158
Safety Entry
PyPa Advisory Database Entry

@harlekeyn
Copy link

Hi @Matthew-Grayson. We've re-examined this vulnerability and have found no evidence of a remedy being applied. Should you have any information regarding a fix, please provide the specifics. Until then, we must retain this vulnerability in our database.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants