Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DOS vulnerability in dependencies #3513

Open
JimMadge opened this issue Jan 30, 2024 · 0 comments
Open

DOS vulnerability in dependencies #3513

JimMadge opened this issue Jan 30, 2024 · 0 comments
Labels
infrastructure For all issues related to book infrastructure

Comments

@JimMadge
Copy link
Member

The package markdown-it-py < 2.2.0 has a local denial of service vulnerability.
There are two dependabot alerts.

These suggest the package cannot be updated because it comes from an external dependency (https://github.com/the-turing-way/pathways).
That seems a little odd though because that package requires markdown-it-py ~= 3.0.
It also requires Python >= 3.10 so I'm not quite sure what is going on.

markdown-it-py is pinned to 1.1.0 in requirements.txt.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
infrastructure For all issues related to book infrastructure
Projects
Status: No status
Development

No branches or pull requests

1 participant