Skip to content

Commit

Permalink
[Snyk] Security upgrade certifi from 2023.7.22 to 2024.7.4 (#268)
Browse files Browse the repository at this point in the history
<p>This PR was automatically created by Snyk using the credentials of a
real user.</p><br
/>![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

### Snyk has created this PR to fix 1 vulnerabilities in the pip
dependencies of this project.

#### Snyk changed the following file(s):

- `requirements.txt`



<details>
<summary>⚠️ <b>Warning</b></summary>
```
virtualenv 20.26.3 has requirement platformdirs<5,>=3.9.1, but you have platformdirs 2.5.1.
virtualenv 20.26.3 has requirement distlib<1,>=0.3.7, but you have distlib 0.3.5.
virtualenv 20.26.3 has requirement filelock<4,>=3.12.2, but you have filelock 3.8.0.
flake8 4.0.1 has requirement importlib-metadata<4.3; python_version < "3.8", but you have importlib-metadata 6.7.0.

```
</details>





---

> [!IMPORTANT]
>
> - Check the changes in this PR to ensure they won't cause issues with
your project.
> - Max score is 1000. Note that the real score may have changed since
the PR was raised.
> - This PR was automatically created by Snyk using the credentials of a
real user.
> - Some vulnerabilities couldn't be fully fixed and so Snyk will still
find them when the project is tested again. This may be because the
vulnerability existed within more than one direct dependency, but not
all of the affected dependencies could be upgraded.

---

**Note:** _You are seeing this because you or someone else with access
to this repository has authorized Snyk to open fix PRs._

For more information: <img
src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI5MzdlZGRhMy02NGY0LTQwMmItODY5NS0xYWY0YzMyNTljY2YiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjkzN2VkZGEzLTY0ZjQtNDAyYi04Njk1LTFhZjRjMzI1OWNjZiJ9fQ=="
width="0" height="0"/>
🧐 [View latest project
report](https://app.snyk.io/org/calvinsixfeetup.com/project/4d495fc3-4887-4272-afb1-7a29b3658635?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr)
📜 [Customise PR
templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates)
🛠 [Adjust project
settings](https://app.snyk.io/org/calvinsixfeetup.com/project/4d495fc3-4887-4272-afb1-7a29b3658635?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;fix-pr/settings)
📚 [Read about Snyk's upgrade
logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities)

---

**Learn how to fix vulnerabilities with free interactive lessons:**

🦉 [Learn about vulnerability in an interactive lesson of Snyk
Learn.](https://learn.snyk.io/?loc&#x3D;fix-pr)

[//]: #
'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"certifi","from":"2023.7.22","to":"2024.7.4"}],"env":"prod","issuesToFix":[{"exploit_maturity":"No
Known
Exploit","id":"SNYK-PYTHON-CERTIFI-7430173","priority_score":591,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.1","score":305},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Insufficient
Verification of Data Authenticity"},{"exploit_maturity":"No Known
Exploit","id":"SNYK-PYTHON-CERTIFI-7430173","priority_score":591,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.1","score":305},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Insufficient
Verification of Data Authenticity"},{"exploit_maturity":"No Known
Exploit","id":"SNYK-PYTHON-CERTIFI-7430173","priority_score":591,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.1","score":305},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Insufficient
Verification of Data Authenticity"},{"exploit_maturity":"No Known
Exploit","id":"SNYK-PYTHON-CERTIFI-7430173","priority_score":591,"priority_score_factors":[{"type":"freshness","label":true,"score":71},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.1","score":305},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Insufficient
Verification of Data
Authenticity"}],"prId":"937edda3-64f4-402b-8695-1af4c3259ccf","prPublicId":"937edda3-64f4-402b-8695-1af4c3259ccf","packageManager":"pip","priorityScoreList":[591],"projectPublicId":"4d495fc3-4887-4272-afb1-7a29b3658635","projectUrl":"https://app.snyk.io/org/calvinsixfeetup.com/project/4d495fc3-4887-4272-afb1-7a29b3658635?utm_source=github&utm_medium=referral&page=fix-pr","prType":"fix","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["updated-fix-title","pr-warning-shown","priorityScore"],"type":"auto","upgrade":[],"vulns":["SNYK-PYTHON-CERTIFI-7430173"],"patch":[],"isBreakingChange":false,"remediationStrategy":"vuln"}'

Co-authored-by: snyk-bot <snyk-bot@snyk.io>
  • Loading branch information
clshaw01 and snyk-bot authored Jul 15, 2024
1 parent 513a1cd commit d0cc847
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ black==22.1.0 \
--hash=sha256:f5660feab44c2e3cb24b2419b998846cbb01c23c7fe645fee45087efa3da2d61 \
--hash=sha256:fdb8754b453fb15fad3f72cd9cad3e16776f0964d67cf30ebcbf10327a3777a3
# via -r requirements.in
certifi==2023.7.22 \
certifi==2024.7.4 \
--hash=sha256:539cc1d13202e33ca466e88b2807e29f4c13049d6d87031a3c110744495cb082 \
--hash=sha256:92d6037539857d8206b8f6ae472e8b77db8058fec5937a1ef3f54304089edbb9
# via requests
Expand Down

0 comments on commit d0cc847

Please # to comment.