newfs / gobotany-app

Deployable code for the Go Botany application
9 stars 8 forks source link

Two dependencies have known vulnerabilities #696

Closed jnga closed 5 years ago

jnga commented 6 years ago

GitHub now detects and reports on versions of dependencies which have known security vulnerabilities, in this case: gunicorn (0.17.2) and tablib (0.9.11). Upgrade these.

jnga commented 6 years ago

Tablib is only used in the Admin data upload feature for Partner sites. Gunicorn is used on Heroku. Tested upgrades locally. Not tested in Heroku Dev yet.