You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A high severity vulnerability is detected by Snyk in ciscoconfparse package due to pyroma@4.1 › wheel@0.30.0.
Could you review the dependency and bump the version (I think that the latest is still vulnerable) or try to pin the wheel package in version 0.38.0? Thanks in advance.
Regards.
The text was updated successfully, but these errors were encountered:
This technically is not a ciscoconfparse vulnerability. The wheel package is not unique to ciscoconfparse.
I don't think this CVE matters much for ciscoconfparse, but the latest git HEAD commit hash (79ef365dad5aa3ac047a3b71d7aa68ec1a60221a) has upgraded package dependencies... we need wheel > 0.38.0 to fix CVE-2022-40898.
Version 1.7.2 will include the modified requirements.txt to manually upgrade the wheel package version.
A high severity vulnerability is detected by Snyk in
ciscoconfparse
package due topyroma@4.1 › wheel@0.30.0
.Could you review the dependency and bump the version (I think that the latest is still vulnerable) or try to pin the wheel package in version
0.38.0
? Thanks in advance.Regards.
The text was updated successfully, but these errors were encountered: