GSA / data.gov

Main repository for the data.gov service
https://data.gov
Other
587 stars 91 forks source link

[Snyk] Update Flask #4303

Open nickumia-reisys opened 1 year ago

nickumia-reisys commented 1 year ago

_Please keep any sensitive details in Google Drive._

Date of report: 5/8/2023 Severity: High Due date: 6/8/2023

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

Failing Snyk Scans:

Reference:

hkdctol commented 1 year ago

Can't do until completing CKAN 2.10 most likely

nickumia-reisys commented 1 year ago

Related to

nickumia-reisys commented 1 year ago

Blocked by CKAN releasing compatibility changes to core code. See PR for details:

nickumia-reisys commented 11 months ago

See comment

btylerburton commented 11 months ago

Conversation with CKAN core team on release schedule. No new developments, but at least they are aware that we are awaiting these fixes.

https://github.com/ckan/ckan/discussions/6381