Skip to content

[Vulnerability] Upgrade packages to resolve security vulnerability #355

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 15 commits into
base: main
Choose a base branch
from

Conversation

raghu017
Copy link
Contributor

Vulnerability updates

  • Bump aiohttp from 3.8.4 to 3.8.5 - aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser
  • Bump certifi from 2023.5.7 to 2023.7.22 - Removal of e-Tugra root certificate
  • Bump cryptography from 41.0.1 to 41.0.3 - cryptography mishandles SSH certificates
  • Bump langchain from 0.0.188 to 0.0.264 - langchain Code Injection vulnerability

Enhancement

raghu017 and others added 8 commits July 12, 2023 15:02
[Enhancement] Upgrade Uvicorn for graceful shutdown timeout
Vulnerability updates - Langchain, aiohttp, certifi, cryptography
Bumps [gitpython](https://github.com/gitpython-developers/GitPython) from 3.1.31 to 3.1.32.
- [Release notes](https://github.com/gitpython-developers/GitPython/releases)
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES)
- [Commits](gitpython-developers/GitPython@3.1.31...3.1.32)

---
updated-dependencies:
- dependency-name: gitpython
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@vicondoa
Copy link

@isafulf will you review please? Also, what do you think about installing dependabot on this? I can send out a PR for it if you'd like.

vicondoa and others added 7 commits August 30, 2023 08:56
Bumps [cryptography](https://github.com/pyca/cryptography) from 41.0.3 to 41.0.4.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@41.0.3...41.0.4)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gitpython](https://github.com/gitpython-developers/GitPython) from 3.1.32 to 3.1.35.
- [Release notes](https://github.com/gitpython-developers/GitPython/releases)
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES)
- [Commits](gitpython-developers/GitPython@3.1.32...3.1.35)

---
updated-dependencies:
- dependency-name: gitpython
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [urllib3](https://github.com/urllib3/urllib3) from 1.26.16 to 1.26.17.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@1.26.16...1.26.17)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants