Skip to content

Add radial search feature to main branch (#1617)

Mend for GitHub.com / WhiteSource Security Check failed Apr 17, 2024 in 5m 29s

Security Report

The Security Check found 5 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2024-23334

Path to dependency file: /benchmarks/osb/requirements.txt

Path to vulnerable library: /benchmarks/osb/requirements.txt

Dependency Hierarchy:

-> ❌ aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

High 7.5 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Upgrade to version: aiohttp - 3.9.2 #1437
CVE-2024-23829

Path to dependency file: /benchmarks/osb/requirements.txt

Path to vulnerable library: /benchmarks/osb/requirements.txt

Dependency Hierarchy:

-> ❌ aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 6.5 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Upgrade to version: aiohttp - 3.9.2 #1438
CVE-2023-49082

Path to dependency file: /benchmarks/osb/requirements.txt

Path to vulnerable library: /benchmarks/osb/requirements.txt

Dependency Hierarchy:

-> ❌ aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Upgrade to version: aiohttp - 3.9.0 #1329
CVE-2023-49081

Path to dependency file: /benchmarks/osb/requirements.txt

Path to vulnerable library: /benchmarks/osb/requirements.txt

Dependency Hierarchy:

-> ❌ aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.3 aiohttp-3.8.6-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Upgrade to version: aiohttp - 3.9.0 #1330
CVE-2021-34141

Path to dependency file: /benchmarks/osb/requirements.txt

Path to vulnerable library: /benchmarks/osb/requirements.txt,/benchmarks/perf-tool/requirements.txt

Dependency Hierarchy:

-> ❌ numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl (Vulnerable Library)

Medium 5.3 numpy-1.21.6-cp37-cp37m-manylinux_2_12_x86_64.manylinux2010_x86_64.whl Upgrade to version: numpy - 1.22.0 #281

Total libraries scanned: 171
Scan token: b92e03821b764ce2ae07f0a35f1d8b0e