Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump Python mkdocs tool dependency to address CVE-2019-10906 #3379

Merged
merged 2 commits into from
Oct 31, 2020
Merged

Bump Python mkdocs tool dependency to address CVE-2019-10906 #3379

merged 2 commits into from
Oct 31, 2020

Conversation

artamonovkirill
Copy link
Contributor

A dependabot alert raised by GitHub on my fork of this repo: https://github.com/artamonovkirill/testcontainers-java/network/alert/Pipfile.lock/Jinja2/open

I'm not a security expert to answer whether this vulnerability is a threat to the project, so my approach is - if it's a matter of a simple version bump - to fix such security warnings to have an uncluttered view when more severe vulnerabilities are reported.

@rnorth rnorth changed the title security: CVE-2019-10906 Bump python mkdocs tool dependency to address CVE-2019-10906 Oct 31, 2020
@rnorth rnorth changed the title Bump python mkdocs tool dependency to address CVE-2019-10906 Bump Python mkdocs tool dependency to address CVE-2019-10906 Oct 31, 2020
Copy link
Member

@rnorth rnorth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This shouldn't be a problem at all, but let's bump the version anyway to clear the warnings. Thanks @artamonovkirill

@rnorth rnorth merged commit 8d1a723 into testcontainers:master Oct 31, 2020
@artamonovkirill artamonovkirill deleted the security/CVE-2019-10906 branch November 2, 2020 07:31
@artamonovkirill artamonovkirill mentioned this pull request Nov 2, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants