[Closed without merge] 5058 upgrade GitPython from 3.1.0 to 3.1.27 #5103
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary (required)
When checking snyk https://app.snyk.io/org/fecgov/project/a95ea997-b012-4b3b-a026-2fdbe6ac0398, get gitPython-Regular Expression Denial of Service (ReDoS) vulnerability
Required reviewers
0ne developer
Impacted areas of the application
api
How to test
snyk test --file=requirements.txt
, you will see gitpython warning.pip install -r requirements.txt
pip freeze
make sure gitpython=3.1.27, make sure install new version gitpythonsnyk test --file=requirements.txt
, gitpython issue remove.