Skip to content

Bump Python mkdocs tool dependency to address CVE-2019-10906#3379

Merged
rnorth merged 2 commits intotestcontainers:masterfrom
artamonovkirill:security/CVE-2019-10906
Oct 31, 2020
Merged

Bump Python mkdocs tool dependency to address CVE-2019-10906#3379
rnorth merged 2 commits intotestcontainers:masterfrom
artamonovkirill:security/CVE-2019-10906

Conversation

@artamonovkirill
Copy link
Copy Markdown
Contributor

A dependabot alert raised by GitHub on my fork of this repo: https://github.com/artamonovkirill/testcontainers-java/network/alert/Pipfile.lock/Jinja2/open

I'm not a security expert to answer whether this vulnerability is a threat to the project, so my approach is - if it's a matter of a simple version bump - to fix such security warnings to have an uncluttered view when more severe vulnerabilities are reported.

@rnorth rnorth changed the title security: CVE-2019-10906 Bump python mkdocs tool dependency to address CVE-2019-10906 Oct 31, 2020
@rnorth rnorth changed the title Bump python mkdocs tool dependency to address CVE-2019-10906 Bump Python mkdocs tool dependency to address CVE-2019-10906 Oct 31, 2020
Copy link
Copy Markdown
Member

@rnorth rnorth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This shouldn't be a problem at all, but let's bump the version anyway to clear the warnings. Thanks @artamonovkirill

@rnorth rnorth merged commit 8d1a723 into testcontainers:master Oct 31, 2020
@artamonovkirill artamonovkirill deleted the security/CVE-2019-10906 branch November 2, 2020 07:31
@artamonovkirill artamonovkirill mentioned this pull request Nov 2, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants