afrl-rq / OpenUxAS

Project for multi-UAV cooperative decision making
Other
53 stars 25 forks source link

check uxas Build-automation module failure on CI #118

Closed VVCAS-Sean closed 4 months ago

VVCAS-Sean commented 4 months ago

Named module fails with following report:

Vulnerability found in pip version 24.0 Vulnerability ID: 67599 Affected spec: >=0 ADVISORY: DISPUTED An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra- index-url securely. CVE-2018-20225 For more information about this vulnerability, visit https://data.safetycli.com/v/67599/97c To ignore this vulnerability, use PyUp vulnerability id 67599 in safety’s ignore command-line argument or add the ignore to your safety policy file.

+==============================================================================+ REMEDIATIONS

1 vulnerability was reported in 1 package. For detailed remediation & fix recommendations, upgrade to a commercial license.

+==============================================================================+

Scan was completed. 1 vulnerability was reported.

+==============================================================================+