chore(deps): update dependency sqlalchemy to v1.4.20 #53
Security Report
You have successfully remediated 4 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-52804Path to dependency file: /data-files/benchmarks/bm_tornado_http/requirements.txt Path to vulnerable library: /data-files/benchmarks/bm_tornado_http/requirements.txt Dependency Hierarchy: -> ❌ tornado-6.1-cp38-cp38-manylinux2010_x86_64.whl (Vulnerable Library) |
High | 7.5 | tornado-6.1-cp38-cp38-manylinux2010_x86_64.whl | Upgrade to version: tornado - 6.4.2 | None |
CVE-2023-28370Path to dependency file: /data-files/benchmarks/bm_tornado_http/requirements.txt Path to vulnerable library: /data-files/benchmarks/bm_tornado_http/requirements.txt Dependency Hierarchy: -> ❌ tornado-6.1-cp38-cp38-manylinux2010_x86_64.whl (Vulnerable Library) |
Medium | 6.1 | tornado-6.1-cp38-cp38-manylinux2010_x86_64.whl | Upgrade to version: tornado - 6.3.2 | None |
WS-2023-0296Path to dependency file: /data-files/benchmarks/bm_tornado_http/requirements.txt Path to vulnerable library: /data-files/benchmarks/bm_tornado_http/requirements.txt Dependency Hierarchy: -> ❌ tornado-6.1-cp38-cp38-manylinux2010_x86_64.whl (Vulnerable Library) |
Medium | 5.6 | tornado-6.1-cp38-cp38-manylinux2010_x86_64.whl | Upgrade to version: tornado - 6.3.3 | None |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-28370 | tornado-6.1-cp37-cp37m-manylinux2010_x86_64.whl |
CVE-2024-5569 | zipp-3.11.0-py3-none-any.whl |
WS-2023-0296 | tornado-6.1-cp37-cp37m-manylinux2010_x86_64.whl |
CVE-2024-52804 | tornado-6.1-cp37-cp37m-manylinux2010_x86_64.whl |
Base branch total remaining vulnerabilities: 39
Base branch commit: null
Total libraries scanned: 39
Scan token: 9303fab02a684c218689f4a50481834a