Update dependency certifi to v2023 #17
Open
Mend for GitHub.com / WhiteSource Security Check
failed
Jan 10, 2024 in 1m 20s
Security Report
You have successfully remediated 2 vulnerabilities, but introduced 2 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-38325Path to dependency file: /requirements.txt Path to vulnerable library: /requirements.txt Dependency Hierarchy: -> ❌ cryptography-2.9.2-cp35-abi3-manylinux2010_x86_64.whl (Vulnerable Library) |
High | 7.5 | cryptography-2.9.2-cp35-abi3-manylinux2010_x86_64.whl | Upgrade to version: cryptography - 41.0.2 | None |
CVE-2023-32731Path to dependency file: /requirements.txt Path to vulnerable library: /requirements.txt Dependency Hierarchy: -> ❌ grpcio-1.30.0-cp37-cp37m-manylinux2010_x86_64.whl (Vulnerable Library) |
High | 7.5 | grpcio-1.30.0-cp37-cp37m-manylinux2010_x86_64.whl | Upgrade to version: grpc- 1.53.0;grpcio- 1.53.0;io.grpc:grpc-protobuf:1.53.0 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2022-23491 | certifi-2020.4.5.2-py2.py3-none-any.whl |
CVE-2023-37920 | certifi-2020.4.5.2-py2.py3-none-any.whl |
Base branch total remaining vulnerabilities: 28
Base branch commit: null
Total libraries scanned: 103
Scan token: 630fe6852d47443dbbb18857528c13a4
Loading