DigitalTrustCenter / sectxt

security.txt parser and validator
European Union Public License 1.2
17 stars 6 forks source link

Publish patched PGPy on PyPI #80

Open bwbroersma opened 2 weeks ago

bwbroersma commented 2 weeks ago

Maybe you can publish https://github.com/SecurityInnovation/PGPy/pull/467/commits/09014c72b4557dd1254cf68a32e50f78515f5f32 on PyPI (under a new name, e.g. PGPy-gh467) and use that as requirement, so the version from PyPI is not vulnerable?

mxsasha commented 5 days ago

Or, remove the pgpy dependency completely and issue a new release. The current version of sectxt on pypi is now vulnerable for a trivial DoS that has been easily triggered by accident and is publicly documented.