Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vdk-control-cli: address vulnerability in python dependency #1470

Merged
merged 4 commits into from
Jan 3, 2023

Conversation

antoniivanov
Copy link
Collaborator

Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in package_index. This has been patched in version 65.5.1.

See https://github.com/vmware/versatile-data-kit/security/dependabot/5

Python Packaging Authority (PyPA)'s setuptools is a library designed to facilitate packaging Python projects. Setuptools version 65.5.0 and earlier could allow remote attackers to cause a denial of service by fetching malicious HTML from a PyPI package or custom PackageIndex page due to a vulnerable Regular Expression in package_index. This has been patched in version 65.5.1.


See https://github.com/vmware/versatile-data-kit/security/dependabot/5
@ivakoleva ivakoleva enabled auto-merge (squash) January 3, 2023 09:35
@ivakoleva ivakoleva merged commit 28178c6 into main Jan 3, 2023
@ivakoleva ivakoleva deleted the person/aivanov/vdk-control-cli-dep branch January 3, 2023 09:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants