[Snyk] Security upgrade urllib3 from 1.26.20 to 2.6.0#185
[Snyk] Security upgrade urllib3 from 1.26.20 to 2.6.0#185
Conversation
The following vulnerabilities are fixed by pinning transitive dependencies: - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192442 - https://snyk.io/vuln/SNYK-PYTHON-URLLIB3-14192443
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
|
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
|
There was a problem hiding this comment.
Important
Looks good to me! 👍
Reviewed everything up to 09734bb in 24 seconds. Click for details.
- Reviewed
9lines of code in1files - Skipped
0files when reviewing. - Skipped posting
1draft comments. View those below. - Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
1. requirements-master-docker-extras.txt:5
- Draft comment:
Consider pinning urllib3 to an exact version (e.g., urllib3==2.6.0) instead of using a lower-bound (>=2.6.0) to avoid potential issues with unexpected major updates. Also, verify that dependent libraries (like requests) remain compatible with the v2.x series. - Reason this comment was not posted:
Confidence changes required:50%<= threshold50%None
Workflow ID: wflow_M5qrxTHJ5Gwo9qXc
You can customize by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.
Snyk has created this PR to fix 2 vulnerabilities in the pip dependencies of this project.
Snyk changed the following file(s):
requirements-master-docker-extras.txtImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling
Important
Upgrade
urllib3to>=2.6.0inrequirements-master-docker-extras.txtto fix security vulnerabilities.urllib3to>=2.6.0inrequirements-master-docker-extras.txtto fix security vulnerabilities.twistedrequireszope-interface, which is not installed.requestsrequiresurllib3, which is not installed.This description was created by
for 09734bb. You can customize this summary. It will automatically update as commits are pushed.