Skip to content

Snyk reporting a vulnerability in anyio < 4.4.0 #2653

Closed Answered by agronholm
voltagex asked this question in Q&A
Discussion options

You must be logged in to vote

It was a bug, but not a vulnerability. I don't know why it's being reported as such. And as Starlette isn't capping AnyIO in a way to prevent v4.4.0 from being installed, except for the test suite, I don't see a problem.

Replies: 1 comment 2 replies

Comment options

Kludex
Jul 26, 2024
Maintainer Sponsor

You must be logged in to vote
2 replies
@agronholm
Comment options

Answer selected by Kludex
@agronholm
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants