Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix vulnerability in Gitpython #4005

Closed
wants to merge 2 commits into from
Closed

Fix vulnerability in Gitpython #4005

wants to merge 2 commits into from

Conversation

noklam
Copy link
Contributor

@noklam noklam commented Jul 11, 2024

Description

image

Synk report

https://www.cve.org/CVERecord?id=CVE-2023-40267

Development notes

  • bump Gitpython

Developer Certificate of Origin

We need all contributions to comply with the Developer Certificate of Origin (DCO). All commits must be signed off by including a Signed-off-by line in the commit message. See our wiki for guidance.

If your PR is blocked due to unsigned commits, then you must follow the instructions under "Rebase the branch" on the GitHub Checks page for your PR. This will retroactively add the sign-off to all unsigned commits and allow the DCO check to pass.

Checklist

  • Read the contributing guidelines
  • Signed off each commit with a Developer Certificate of Origin (DCO)
  • Opened this PR as a 'Draft Pull Request' if it is work-in-progress
  • Updated the documentation to reflect the code changes
  • Added a description of this change in the RELEASE.md file
  • Added tests to cover my changes
  • Checked if this change will affect Kedro-Viz, and if so, communicated that with the Viz team

@noklam noklam requested a review from merelcht as a code owner July 11, 2024 12:37
@noklam
Copy link
Contributor Author

noklam commented Jul 11, 2024

The conflict is caused by:
kedro 0.19.6 depends on gitpython>=3.1.32
kedro[test] 0.19.6 depends on gitpython>=3.1.32
trufflehog 2.2.1 depends on GitPython==3.0.6
kedro 0.19.6 depends on gitpython>=3.1.32
kedro[test] 0.19.6 depends on gitpython>=3.1.32
trufflehog 2.2.0 depends on GitPython==3.0.6
kedro 0.19.6 depends on gitpython>=3.1.32
kedro[test] 0.19.6 depends on gitpython>=3.1.32
trufflehog 2.1.13 depends on GitPython==3.0.6
kedro 0.19.6 depends on gitpython>=3.1.32
kedro[test] 0.19.6 depends on gitpython>=3.1.32
trufflehog 2.1.11 depends on GitPython==3.0.6
kedro 0.19.6 depends on gitpython>=3.1.32
kedro[test] 0.19.6 depends on gitpython>=3.1.32
trufflehog 2.1.1 depends on GitPython==2.1.1
kedro 0.19.6 depends on gitpython>=3.1.32
kedro[test] 0.19.6 depends on gitpython>=3.1.32
trufflehog 2.1.0 depends on GitPython==2.1.1

Trufflehog stop releaseing Python Package years ago, they still have a pre-commit docker version maybe we should use this instead.
https://docs.trufflesecurity.com/pre-commit-hooks

@merelcht
Copy link
Member

Trufflehog stop releaseing Python Package years ago, they still have a pre-commit docker version maybe we should use this instead. https://docs.trufflesecurity.com/pre-commit-hooks

Yes, let's replace it!

@merelcht
Copy link
Member

@noklam Can this PR be closed?

@noklam noklam closed this Oct 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants