peopledoc / mlvtools

Public repository for versioning machine learning data
Other
42 stars 7 forks source link

Fix Jinja2 CVE #40

Closed sbracaloni closed 5 years ago

sbracaloni commented 5 years ago

There is a CVE with Jinja2 for version under: 2.10.1

Add the constraint Jinja2>=2.10.1 in the setup.cfg file to fix this issue. See: https://nvd.nist.gov/vuln/detail/CVE-2019-10906