materialscloud-org / optimade-maker

Tools for making OPTIMADE APIs from various formats of structural data (e.g. an archive of CIF files).
MIT License
3 stars 0 forks source link

Possibly affected by pymatgen CVE #49

Closed ml-evs closed 8 months ago

ml-evs commented 9 months ago

Details: https://github.com/materialsproject/pymatgen/security/advisories/GHSA-vgv8-5cpj-qj2f

I will release and backport the update to optimade-python-tools, at which point this package should also be upgraded.

ml-evs commented 9 months ago

On (immediate) seconds thoughts, we actually use ASE for cif parsing so perhaps this isn't a big deal (and indeed optimade does not use the CIF parser in pymatgen).