Skip to content

Update dependency zipp to v3.19.1

420c626
Select commit
Loading
Failed to load commit list.
Open

Update dependency zipp to v3.19.1 #32

Update dependency zipp to v3.19.1
420c626
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check failed Sep 9, 2025 in 1m 26s

Security Report

You have successfully remediated 14 vulnerabilities, but introduced 12 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2023-4807

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.8 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl None
CVE-2024-6119

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl None
CVE-2024-26130

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: cryptography - 42.0.4 None
CVE-2023-50782

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: cryptography - 42.0.0 None
CVE-2023-38325

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.5 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: cryptography - 41.0.2 None
CVE-2023-0286

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

High 7.4 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: openssl-3.0.8;cryptography - 39.0.1;openssl-src - 111.25.0+1.1.1t,300.0.12+3.0.8 None
CVE-2023-2650

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

Medium 6.5 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: OpenSSL_1_1_1u,openssl-3.0.9,openssl-3.1.1, cryptography - 41.0.0 None
CVE-2024-3772

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/pydantic-1.10.4.dist-info

Dependency Hierarchy:

-> ❌ pydantic-1.10.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library)

Medium 5.9 pydantic-1.10.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Upgrade to version: Pydantic - 1.10.13,2.4.0 None
CVE-2023-49083

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

Medium 5.9 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: cryptography - 41.0.6 None
CVE-2024-0727

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

Medium 5.5 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: cryptography - 42.0.2 None
CVE-2023-3446

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

Medium 5.3 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl None
CVE-2023-23931

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20250909182438_AAXQTK/python_TMKXGT/202509091824391/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info

Dependency Hierarchy:

-> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library)

Medium 4.8 cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl Upgrade to version: cryptography - 39.0.1 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2023-38325 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2024-0727 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2023-3446 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2023-4807 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2023-0286 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2023-2650 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2023-50782 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2024-5569 zipp-3.12.0-py3-none-any.whl
CVE-2024-3772 pydantic-1.10.4-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-50182 urllib3-1.26.14-py2.py3-none-any.whl
CVE-2024-26130 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2024-6119 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2023-49083 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl
CVE-2023-23931 cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl

Base branch total remaining vulnerabilities: 36
Base branch commit: null


Total libraries scanned: 27

Scan token: 80e510cfc2944d61bcd2afb411af1a01