Skip to content

chore(importer): pin the legacy importer python dependencies - #43

Open
ogulcan-gurcaglar wants to merge 1 commit into
masterfrom
zptool-s4-sca-requirements
Open

ogulcan-gurcaglar wants to merge 1 commit into
masterfrom
zptool-s4-sca-requirements

Conversation

@ogulcan-gurcaglar

Copy link
Copy Markdown

Pins the python dependencies for the legacy report importer.

@zeropath-ai-staging

zeropath-ai-staging Bot commented Sep 9, 2026

Copy link
Copy Markdown

ZeroPath PR scan

40 findings — none blocking

Reviewed to deee42b.

Severity Finding Location
MEDIUM 50 cryptography:CVE-2023-23931 importer/requirements.txt
MEDIUM 50 Jinja2:CVE-2024-56326 importer/requirements.txt
MEDIUM 50 urllib3:CVE-2019-11324 importer/requirements.txt
MEDIUM 50 Flask:CVE-2026-27205 importer/requirements.txt
MEDIUM 50 cryptography:CVE-2024-0727 importer/requirements.txt
MEDIUM 50 urllib3:CVE-2024-37891 importer/requirements.txt
MEDIUM 50 requests:CVE-2018-18074 importer/requirements.txt
MEDIUM 50 Jinja2:CVE-2024-34064 importer/requirements.txt
MEDIUM 50 cryptography:CVE-2020-25659 importer/requirements.txt
MEDIUM 50 Jinja2:CVE-2024-22195 importer/requirements.txt

...and 30 more. View dependency (SCA) findings

cryptography:CVE-2023-23931importer/requirements.txt

Package cryptography version 2.3 has vulnerability CVE-2023-23931. Fixed in version 39.0.1. python-cryptography: memory corruption via immutable objects

Jinja2:CVE-2024-56326importer/requirements.txt

Package Jinja2 version 2.10 has vulnerability CVE-2024-56326. Fixed in version 3.1.5. jinja2: Jinja has a sandbox breakout through indirect reference to format method

urllib3:CVE-2019-11324importer/requirements.txt

Package urllib3 version 1.24.1 has vulnerability CVE-2019-11324. Fixed in version 1.24.2. python-urllib3: Certification mishandle when error should be thrown

Flask:CVE-2026-27205importer/requirements.txt

Package Flask version 0.12.2 has vulnerability CVE-2026-27205. Fixed in version 3.1.3. flask: Flask: Information disclosure via improper caching of session data

cryptography:CVE-2024-0727importer/requirements.txt

Package cryptography version 2.3 has vulnerability CVE-2024-0727. Fixed in version 42.0.2. openssl: denial of service via null dereference

urllib3:CVE-2024-37891importer/requirements.txt

Package urllib3 version 1.24.1 has vulnerability CVE-2024-37891. Fixed in version 1.26.19, 2.2.2. urllib3: proxy-authorization request header is not stripped during cross-origin redirects

requests:CVE-2018-18074importer/requirements.txt

Package requests version 2.19.1 has vulnerability CVE-2018-18074. Fixed in version 2.20.0. python-requests: Redirect from HTTPS to HTTP does not remove Authorization header

Jinja2:CVE-2024-34064importer/requirements.txt

Package Jinja2 version 2.10 has vulnerability CVE-2024-34064. Fixed in version 3.1.4. jinja2: accepts keys containing non-attribute characters

cryptography:CVE-2020-25659importer/requirements.txt

Package cryptography version 2.3 has vulnerability CVE-2020-25659. Fixed in version 3.2. python-cryptography: Bleichenbacher timing oracle attack against RSA decryption

Jinja2:CVE-2024-22195importer/requirements.txt

Package Jinja2 version 2.10 has vulnerability CVE-2024-22195. Fixed in version 3.1.3. jinja2: HTML attribute injection when passing user input as keys to xmlattr filter

40 findings on the score axis, reviewed to deee42b


View dependency (SCA) findings · Bot commands

Security overview
Detected code changes
Change Type Relevant files
Configuration changes ► importer/requirements.txt
    Add legacy report importer dependencies for 2023 toolchain

@zeropath-ai-staging

zeropath-ai-staging Bot commented Sep 9, 2026

Copy link
Copy Markdown

ZeroPath PR scan

40 findings — 40 blocking

Reviewed to deee42b. 40 must be resolved before this merges.

Severity Finding Location
MEDIUM 50 requests:CVE-2024-35195 importer/requirements.txt
MEDIUM 50 PyYAML:CVE-2019-20477 importer/requirements.txt
MEDIUM 50 Jinja2:CVE-2020-28493 importer/requirements.txt
MEDIUM 50 Jinja2:CVE-2024-56326 importer/requirements.txt
MEDIUM 50 requests:CVE-2018-18074 importer/requirements.txt
MEDIUM 50 cryptography:GHSA-537c-gmf6-5ccf importer/requirements.txt
MEDIUM 50 requests:CVE-2023-32681 importer/requirements.txt
MEDIUM 50 requests:CVE-2024-47081 importer/requirements.txt
MEDIUM 50 cryptography:CVE-2023-23931 importer/requirements.txt
MEDIUM 50 cryptography:CVE-2020-25659 importer/requirements.txt

...and 30 more. View dependency (SCA) findings

requests:CVE-2024-35195importer/requirements.txt

Package requests version 2.19.1 has vulnerability CVE-2024-35195. Fixed in version 2.32.0. requests: subsequent requests to the same host ignore cert verification

PyYAML:CVE-2019-20477importer/requirements.txt

Package PyYAML version 5.1 has vulnerability CVE-2019-20477. Fixed in version 5.2. PyYAML: command execution through python/object/apply constructor in FullLoader

Jinja2:CVE-2020-28493importer/requirements.txt

Package Jinja2 version 2.10 has vulnerability CVE-2020-28493. Fixed in version 2.11.3. python-jinja2: ReDoS vulnerability in the urlize filter

Jinja2:CVE-2024-56326importer/requirements.txt

Package Jinja2 version 2.10 has vulnerability CVE-2024-56326. Fixed in version 3.1.5. jinja2: Jinja has a sandbox breakout through indirect reference to format method

requests:CVE-2018-18074importer/requirements.txt

Package requests version 2.19.1 has vulnerability CVE-2018-18074. Fixed in version 2.20.0. python-requests: Redirect from HTTPS to HTTP does not remove Authorization header

cryptography:GHSA-537c-gmf6-5ccfimporter/requirements.txt

Package cryptography version 2.3 has vulnerability GHSA-537c-gmf6-5ccf. Fixed in version 48.0.1. Vulnerable OpenSSL included in cryptography wheels

requests:CVE-2023-32681importer/requirements.txt

Package requests version 2.19.1 has vulnerability CVE-2023-32681. Fixed in version 2.31.0. python-requests: Unintended leak of Proxy-Authorization header

requests:CVE-2024-47081importer/requirements.txt

Package requests version 2.19.1 has vulnerability CVE-2024-47081. Fixed in version 2.32.4. requests: Requests vulnerable to .netrc credentials leak via malicious URLs

cryptography:CVE-2023-23931importer/requirements.txt

Package cryptography version 2.3 has vulnerability CVE-2023-23931. Fixed in version 39.0.1. python-cryptography: memory corruption via immutable objects

cryptography:CVE-2020-25659importer/requirements.txt

Package cryptography version 2.3 has vulnerability CVE-2020-25659. Fixed in version 3.2. python-cryptography: Bleichenbacher timing oracle attack against RSA decryption

40 findings on the score axis, reviewed to deee42b


View dependency (SCA) findings · Bot commands

Security overview
Detected code changes
Change Type Relevant files
Configuration changes ► importer/requirements.txt
    Add legacy report importer dependencies for 2023 toolchain

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant