Skip to content

Dependabot alert sent out 10 days after initial advisory publish - why? #73218

Answered by shelbyc
sn0opy asked this question in Code Security
Discussion options

You must be logged in to vote

👋 Hi @sn0opy, on October 17, the advisory was originally published and alerts were generated for urllib3 with the vulnerable version ranges <= 1.26.17 and >= 2.0.0, <= 2.0.6. On October 26, the vulnerable version ranges were changed to < 1.26.18 and >= 2.0.0, < 2.0.7 to match those in the PYSEC advisory for GHSA-g4mx-q9vg-27p4 and new alerts were generated. Hope this helps!

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by sn0opy
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependabot Code Security Build security into your GitHub workflow with features to keep your codebase secure Question
2 participants