pytexas / pytexas-discord-bot

Discord bot for the PyTexas Discord
1 stars 0 forks source link

Update dependencies #12

Closed dijital20 closed 2 months ago

dijital20 commented 2 months ago

Changes

github-actions[bot] commented 2 months ago

Dependency Review

The following issues were found:

See the Details below.

License Issues

requirements.txt

PackageVersionLicenseIssue Type
aiohttp3.10.3NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 4.*.* :green_circle: 7.2
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Maintained:green_circle: 79 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Fuzzing:warning: 0project is not fuzzed
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Security-Policy:green_circle: 9security policy file detected
Pinned-Dependencies:green_circle: 4dependency not pinned by hash detected -- score normalized to 4
Packaging:green_circle: 10packaging workflow detected
SAST:green_circle: 10SAST tool is run on all commits
Vulnerabilities:green_circle: 91 existing vulnerabilities detected
actions/actions/dependency-review-action 4.*.* :green_circle: 7.2
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Maintained:green_circle: 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases:warning: -1no releases found
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Packaging:warning: -1packaging workflow not detected
Security-Policy:green_circle: 9security policy file detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 1dependency not pinned by hash detected -- score normalized to 1
Fuzzing:warning: 0project is not fuzzed
SAST:green_circle: 9SAST tool detected but not run on all commits
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
pip/aiohappyeyeballs 2.3.5 UnknownUnknown
pip/aiohttp 3.10.3 :green_circle: 6.7
Details
CheckScoreReason
Code-Review:green_circle: 3Found 4/12 approved changesets -- score normalized to 3
Maintained:green_circle: 1030 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 9license file detected
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:green_circle: 10project is fuzzed
Signed-Releases:warning: 11 out of the last 5 releases have a total of 1 signed artifacts.
Security-Policy:green_circle: 10security policy file detected
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Packaging:green_circle: 10packaging workflow detected
SAST:green_circle: 8SAST tool detected but not run on all commits
pip/attrs 24.2.0 :green_circle: 7.4
Details
CheckScoreReason
Code-Review:warning: 0Found 2/29 approved changesets -- score normalized to 0
Maintained:green_circle: 1030 commit(s) and 19 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices:green_circle: 5badge detected: Passing
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Security-Policy:green_circle: 10security policy file detected
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
Packaging:green_circle: 10packaging workflow detected
SAST:green_circle: 7SAST tool detected but not run on all commits
pip/certifi 2024.7.4 :green_circle: 6.5
Details
CheckScoreReason
Code-Review:warning: 0Found 0/2 approved changesets -- score normalized to 0
Maintained:green_circle: 810 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Signed-Releases:warning: -1no releases found
License:green_circle: 9license file detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Security-Policy:green_circle: 10security policy file detected
Pinned-Dependencies:green_circle: 5dependency not pinned by hash detected -- score normalized to 5
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Branch-Protection:green_circle: 3branch protection is not maximal on development and all release branches
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
Packaging:green_circle: 10packaging workflow detected
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
pip/discord-py 2.4.0 :green_circle: 4.8
Details
CheckScoreReason
Code-Review:green_circle: 6Found 18/30 approved changesets -- score normalized to 6
Maintained:green_circle: 1030 commit(s) and 9 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 8binaries present in source code
Branch-Protection:warning: 0branch protection not enabled on development/release branches
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Security-Policy:warning: 0security policy file not detected
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing:warning: 0project is not fuzzed
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
pip/idna 3.7 :green_circle: 6.7
Details
CheckScoreReason
Binary-Artifacts:green_circle: 10no binaries found in the repo
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
CI-Tests:green_circle: 1011 out of 11 merged PRs checked by a CI test -- score normalized to 10
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Code-Review:green_circle: 3found 11 unreviewed changesets out of 16 -- score normalized to 3
Contributors:green_circle: 1041 different organizations found -- score normalized to 10
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Dependency-Update-Tool:warning: 0no update tool detected
Fuzzing:green_circle: 10project is fuzzed
License:green_circle: 10license file detected
Maintained:green_circle: 67 commit(s) out of 30 and 1 issue activity out of 30 found in the last 90 days -- score normalized to 6
Packaging:warning: -1no published package detected
Pinned-Dependencies:warning: -1internal error: internal error: unable to determine OS for job:
SAST:green_circle: 4SAST tool is not run on all commits -- score normalized to 4
Security-Policy:green_circle: 10security policy file detected
Signed-Releases:warning: 00 out of 1 artifacts are signed or have provenance
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Vulnerabilities:green_circle: 10no vulnerabilities detected
pip/requests 2.32.3 :green_circle: 8.6
Details
CheckScoreReason
Maintained:green_circle: 1022 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10
Code-Review:green_circle: 10all changesets reviewed
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases:warning: 0Project has not signed or included provenance with any releases.
Packaging:warning: -1packaging workflow not detected
Security-Policy:green_circle: 10security policy file detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Pinned-Dependencies:green_circle: 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing:green_circle: 10project is fuzzed
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
SAST:green_circle: 10SAST tool is run on all commits
pip/urllib3 2.2.2 :green_circle: 9.1
Details
CheckScoreReason
Binary-Artifacts:green_circle: 10no binaries found in the repo
Branch-Protection:green_circle: 5branch protection is not maximal on development and all release branches
CI-Tests:green_circle: 1029 out of 29 merged PRs checked by a CI test -- score normalized to 10
CII-Best-Practices:green_circle: 5badge detected: Passing
Code-Review:green_circle: 9Found 21/22 approved changesets -- score normalized to 9
Contributors:green_circle: 10project has 106 contributing companies or organizations
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Dependency-Update-Tool:green_circle: 10update tool detected
Fuzzing:green_circle: 10project is fuzzed
License:green_circle: 10license file detected
Maintained:green_circle: 1023 commit(s) and 15 issue activity found in the last 90 days -- score normalized to 10
Packaging:green_circle: 10packaging workflow detected
Pinned-Dependencies:green_circle: 5dependency not pinned by hash detected -- score normalized to 5
SAST:green_circle: 10SAST tool is run on all commits
Security-Policy:green_circle: 10security policy file detected
Signed-Releases:green_circle: 84 out of the last 5 releases have a total of 4 signed artifacts.
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Vulnerabilities:green_circle: 100 existing vulnerabilities detected

Scanned Manifest Files

.github/workflows/check.yml
  • actions/checkout@4.*.*
  • actions/dependency-review-action@4.*.*
requirements.txt
  • aiohttp@3.9.3
  • idna@3.6
  • requests@2.31.0
  • urllib3@2.2.1
  • certifi@2024.2.2
  • aiohappyeyeballs@2.3.5
  • aiohttp@3.10.3
  • attrs@24.2.0
  • certifi@2024.7.4
  • discord-py@2.4.0
  • idna@3.7
  • requests@2.32.3
  • urllib3@2.2.2
  • async-timeout@4.0.3
  • attrs@23.2.0
  • discord-py@2.3.2