Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade requests dependency? #28

Closed
bdewilde opened this issue Jul 9, 2024 · 3 comments
Closed

upgrade requests dependency? #28

bdewilde opened this issue Jul 9, 2024 · 3 comments

Comments

@bdewilde
Copy link

bdewilde commented Jul 9, 2024

Hi! The version of requests pinned in your lockfile, v2.31.0, has a CVE against it that has since been patched:

CVE-2024-35195

Would it be possible to bump this dependency to v2.32.0, to mitigate the CVE / placate the automated system complaining about the CVE? :) No worries if not, the severity is only "medium", and it doesn't look as if you're actually running afoul of the vulnerability.

@ReubenFrankel
Copy link
Contributor

ReubenFrankel commented Jul 9, 2024

Hi @bdewilde, this tap still supports Python 3.7 and requests>2.31.0 no longer supports it, which is why this hasn't been updated yet. Long overdue, so can maybe take a look later this week. 👍

Related: #25

@bdewilde
Copy link
Author

bdewilde commented Jul 9, 2024

Sounds good, thanks @ReubenFrankel !

@ReubenFrankel
Copy link
Contributor

This should now be resolved by #29 and 012a2b2. Give it a go and let me know if you have any issues. @bdewilde

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants