Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Context
The onfido-python generated library has been introducing a vulnerability in my codebase since June 17, as the urllib3 dependency for onfido-python is pinned at < 2.1.0. The vulnerability affects all 2x versions <=2.2.1.
CVE: GHSA-34jh-p97f-mpxf.
I looked through this codebase history and generated the python client lib locally. I don't think the pin to < 2.1.0 was necessary, or are there any breaking changes that affect the client lib generation.
Changes
Remove the < 2.1.0 version pin for urllib3 in the python client generator.