Skip to content

Anasdevs/SIH-SBOM-

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

43 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Overview

This report provides an overview of the Python backend application and its dependencies, including their versions and package URLs.

Application Details

Dependencies

The following dependencies were found for the Python backend application:

  1. asgiref

  2. build

  3. cachecontrol

  4. certifi

    • Version: 2022.12.7
    • Package URL: pkg:pypi/certifi@2022.12.7
    • Vulnerabilities:
      • [CVE-2023-37920] CWE-345: Insufficient Verification of Data Authenticity (CVSS score: 9.8)
      • Description: Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. Sonatype's research suggests that this CVE's details differ from those defined at NVD. See here for details.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages