Ouranosinc / Magpie

AuthN/AuthZ services
https://pavics-magpie.readthedocs.io
Apache License 2.0
1 stars 5 forks source link

[Security] Update `sqlalchemy_utils` #523

Open fmigneault opened 2 years ago

fmigneault commented 2 years ago

Dependency sqlalchemy_utils<0.38 is reported as vulnerability by safety (ignored via pyup: ignore in requirements). There is however no version (at this date) that resolves the reported vulnerability.

+==============================================================================+

 REPORT 

  Safety v2.1.1 is scanning for Vulnerabilities...
  Scanning dependencies in your files:

  -> /home/francis/dev/magpie/requirements.txt
  -> /home/francis/dev/magpie/requirements-dev.txt
  -> /home/francis/dev/magpie/requirements-doc.txt
  -> /home/francis/dev/magpie/requirements-sys.txt

  Using non-commercial database
  Found and scanned 14 packages
  Timestamp 2022-09-02 15:52:16
  0 vulnerabilities found
  1 vulnerability ignored

+==============================================================================+
 VULNERABILITIES FOUND 
+==============================================================================+

-> Vulnerability found in sqlalchemy-utils version 0.37.9
   Vulnerability ID: 42194
   This vulnerability is being ignored.
   For more information, please visit
   https://pyup.io/vulnerabilities/PVE-2021-42194/42194/

 Scan was completed. 0 vulnerabilities were found. 1 vulnerability from 1 
 package was ignored. 

+==============================================================================+
fmigneault commented 1 year ago

Still no update: https://github.com/kvesteri/sqlalchemy-utils/issues/166 https://github.com/kvesteri/sqlalchemy-utils/issues/556 https://data.safetycli.com/vulnerabilities/PVE-2021-42194/42194

Leave ignored for now. No real impact for use case of this repository.