Skip to content

fix some security issues reported by scorecard#349

Merged
ocaisa merged 29 commits into
EESSI:developfrom
trz42:fix_security_issues
Nov 6, 2025
Merged

fix some security issues reported by scorecard#349
ocaisa merged 29 commits into
EESSI:developfrom
trz42:fix_security_issues

Conversation

@trz42
Copy link
Copy Markdown
Contributor

@trz42 trz42 commented Nov 6, 2025

  • GHSA-3ww4-gg4f-jr7f fixed with cryptography >= 42.0.0, see https://osv.dev/vulnerability/GHSA-3ww4-gg4f-jr7f
  • GHSA-9v9h-cgj8-h64p fixed with cryptography >= 42.0.2, see https://osv.dev/vulnerability/GHSA-9v9h-cgj8-h64p
  • PYSEC-2021-62 / GHSA-hggm-jpg3-v476 fixed with either of the above changes
  • PYSEC-2017-8 / GHSA-q3cj-2r34-2cwc fixed with either of the above changes
  • GHSA-3f84-rpwh-47g6 fixed with waitress >= 3.0.1, see https://osv.dev/vulnerability/GHSA-3f84-rpwh-47g6
  • GHSA-4f7p-27jc-3c36 fixed with the above
  • GHSA-j7j6-7hfx-5522 fixed with the above
  • GHSA-968f-66r5-5v74 fixed with the above
  • GHSA-g2xc-35jw-c63p fixed with the above
  • GHSA-m5ff-3wj3-8ph4 fixed with the above
  • GHSA-pg36-wpm5-g57p fixed with the above
  • PYSEC-2020-155 fixed with the above
  • pinning versions of pytest and pytest-cov for tests CI
    • this also required pinning dependencies and creating a requirements-lock.txt file in the workflow directory

Copy link
Copy Markdown
Member

@ocaisa ocaisa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@trz42 trz42 marked this pull request as draft November 6, 2025 15:43
@trz42
Copy link
Copy Markdown
Contributor Author

trz42 commented Nov 6, 2025

LGTM

Sorry, still working on it.

Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
Comment thread .github/workflows/tests.yaml Fixed
@trz42 trz42 marked this pull request as ready for review November 6, 2025 18:30
@trz42
Copy link
Copy Markdown
Contributor Author

trz42 commented Nov 6, 2025

Now, this should be ready for review. May not solve all issues, but should be a step forward.

@trz42 trz42 requested a review from ocaisa November 6, 2025 18:31
@trz42 trz42 changed the title fix security issues reported by scorecard fix some security issues reported by scorecard Nov 6, 2025
Copy link
Copy Markdown
Member

@ocaisa ocaisa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ha, smells like a workaround!

@ocaisa ocaisa merged commit 030c450 into EESSI:develop Nov 6, 2025
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants