Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SecOps: Security issues found with grPC lib #306

Closed
cristian-rincon opened this issue Oct 2, 2023 · 5 comments
Closed

SecOps: Security issues found with grPC lib #306

cristian-rincon opened this issue Oct 2, 2023 · 5 comments

Comments

@cristian-rincon
Copy link
Contributor

Hi,

I'm using Blackduck to get insights about security issues with FOSS libs we are about to use, and we've found this issues after installing your lib:

Vulnerability CVE-2023-32732 found in grPC lib
Vulnerability CVE-2023-32731 found in grPC lib
Vulnerability CVE-2023-1428 found in grPC lib

Do you have any workaround or planned work to fix them?

Thanks in advance

@cristian-rincon
Copy link
Contributor Author

Adding @dggarciam to seek this issue

@adriangb
Copy link
Owner

adriangb commented Oct 2, 2023

It's an upstream issue: grpc/grpc#31492

@adriangb
Copy link
Owner

adriangb commented Oct 2, 2023

I just made a new release removing the pin. FWIW it also only ever applied to M1 macs.

@adriangb adriangb closed this as completed Oct 2, 2023
@cristian-rincon
Copy link
Contributor Author

Hi, I just wanted to let you know that your Release pipeline failed. https://github.com/adriangb/scikeras/blob/master/pyproject.toml

as a result of that, your fix was not published to the Pypi.

@adriangb
Copy link
Owner

adriangb commented Oct 2, 2023

I am aware

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants