Skip to content

Conversation

@cycode-security
Copy link

Cycode Vulnerable Dependencies Update

This pull request updates the following manifest file:

File Path Number of packages to update
buildscripts/cost_model/requirements.txt 1

📂 buildscripts/cost_model/requirements.txt

1 package will be updated to resolve vulnerabilities:

Package Name Current Version Updated Version
pillow 10.0.1 10.2.0

pandas==2.1.1
patsy==0.5.3
Pillow==10.0.1
Pillow==10.2.0
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Security vulnerabilities found in newly introduced dependency.

Ecosystem PyPI
Dependency pillow
Dependency Paths pillow 10.2.0
Direct Dependency Yes

The following vulnerabilities were introduced:

GHSA CVE Severity Fixed Version
GHSA-44wm-f244-xhp3 CVE-2024-28219 HIGH 10.3.0

Highest fixed version: 10.3.0

Description

Detects when new vulnerabilities affect your dependencies.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_ignore_manifest_here <reason> Applies to this manifest in this request only
#cycode_ignore_package_everywhere <reason> Applies to this manifest for this package for all requests in your repository
#cycode_ignore_package_here <reason> Applies to this manifest for this package in this request only
#cycode_vulnerable_package_fix_this_violation Fix this violation via a commit to this branch

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant