Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update GH workflows, bump Dockerfile base image, update Kustomize resources, bump Django and dependencies #438

Merged
merged 14 commits into from
Dec 12, 2024

Conversation

ropable
Copy link
Member

@ropable ropable commented Dec 12, 2024

No description provided.

@ropable ropable self-assigned this Dec 12, 2024
Copy link

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
pypi/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +98 780 MB
pypi/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +28 83 MB
pypi/[email protected] environment, eval, filesystem, network, shell, unsafe 0 1.53 MB azure-sdk, microsoft
pypi/[email protected] environment, eval, filesystem, network 0 5.27 MB azure-sdk, microsoft
pypi/[email protected] environment, eval, filesystem 0 770 kB Ousret
pypi/[email protected] environment, eval, filesystem, network, shell, unsafe +4 20.6 MB reaperhulk
pypi/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +4 10.1 MB
pypi/[email protected] environment, eval, filesystem, network, shell, unsafe +4 52.8 MB felixx, nessita, sarahboyce, ...1 more
pypi/[email protected] environment, filesystem 0 373 kB asottile, ckuehl
pypi/[email protected] unsafe Transitive: environment, eval, filesystem, network, shell +4 10.2 MB gweis
pypi/[email protected] None 0 0 B
pypi/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +4 10.1 MB
pypi/[email protected] environment, eval, filesystem, shell 0 2.47 MB brettcannon, dstufft, pf_moore, ...1 more
pypi/[email protected] environment, eval, filesystem, network, shell, unsafe +90 770 MB
pypi/[email protected] filesystem Transitive: environment, eval, network, shell, unsafe +4 10.2 MB piro
pypi/[email protected] environment, eval, filesystem, unsafe +16 5.14 MB ptmcg
pypi/[email protected] environment, eval, filesystem, network 0 6.91 MB RedisLabs, cisk
pypi/[email protected] environment, eval, filesystem, network, shell, unsafe 0 477 kB Lukasa, graffatcolmingov, nateprewitt
pypi/[email protected] filesystem 0 110 kB s2e
pypi/[email protected] None 0 0 B
pypi/[email protected] environment, filesystem 0 134 kB gutworth
pypi/[email protected] eval, filesystem, unsafe 0 517 kB facelessuser
pypi/[email protected] filesystem, shell 0 367 kB aalbrecht
pypi/[email protected] environment, eval Transitive: filesystem, network, shell, unsafe +94 779 MB 15r10nk, alexmojaki
pypi/[email protected] environment, eval, filesystem, shell, unsafe 0 718 kB Jonathan.Frederic, Kyle.Kelley, Sylvain.Corlay, ...9 more
pypi/[email protected] network Transitive: environment, eval, filesystem, shell, unsafe +4 10.2 MB typesense
pypi/[email protected] environment, eval, filesystem, shell, unsafe 0 422 kB JelleZijlstra, guido, hauntsaninja, ...3 more
pypi/[email protected] filesystem Transitive: environment, eval, network, shell, unsafe +4 10.7 MB belopolsky, pganssle
pypi/[email protected] environment, filesystem, network, shell Transitive: eval, unsafe +4 10.2 MB agronholm, regebro
pypi/[email protected] filesystem, shell, unsafe 0 960 kB avian, bbangert
pypi/[email protected] environment, eval, filesystem, network, shell, unsafe 0 1.29 MB SethMichaelLarson, shazow
pypi/[email protected] filesystem Transitive: environment, eval, network, shell, unsafe +8 11.9 MB Nusnus, ask, auvipy, ...1 more
pypi/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +4 10.1 MB
pypi/[email protected] environment, filesystem, network, shell Transitive: eval, unsafe +24 73.8 MB jquast
pypi/[email protected] network 0 91.9 kB ashley_felton_dpaw
pypi/[email protected] environment, filesystem, network Transitive: eval, shell, unsafe +4 10.2 MB AdamChainz, evansd
pypi/[email protected] environment, eval, filesystem 0 81.7 kB drekin
pypi/[email protected] environment, eval, filesystem, shell 0 1.09 MB jmcnamara
pypi/[email protected] filesystem, network, shell 0 226 kB martinblech

🚮 Removed packages: pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected], pypi/[email protected]

View full report↗︎

Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Possible typosquat attack pypi/[email protected] ⚠︎

View full report↗︎

Next steps

What is a typosquat?

Package name is similar to other popular packages and may not be the package you want.

Use care when consuming similarly named packages and ensure that you did not intend to consume a different package. Malicious packages often publish using similar names as existing popular packages.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/[email protected] or ignore all packages with @SocketSecurity ignore-all

@ropable ropable merged commit 881b9a3 into dbca-wa:master Dec 12, 2024
10 checks passed
@ropable
Copy link
Member Author

ropable commented Dec 12, 2024

@SocketSecurity ignore pypi/[email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant