Bump json and wiremock version to fix CVEs #2533
Merged
Mend for GitHub.com / WhiteSource Security Check
failed
Mar 1, 2024 in 2m 43s
Security Report
2 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2023-26112Path to dependency file: /sql-cli Path to vulnerable library: /sql-cli Dependency Hierarchy: -> ❌ configobj-5.0.8-py2.py3-none-any.whl (Vulnerable Library) |
Medium | 5.9 | configobj-5.0.8-py2.py3-none-any.whl | None | |
CVE-2022-40896Path to dependency file: /sql-cli Path to vulnerable library: /sql-cli Dependency Hierarchy: -> ❌ Pygments-2.11.1-py3-none-any.whl (Vulnerable Library) |
Medium | 5.5 | Pygments-2.11.1-py3-none-any.whl | Upgrade to version: pygments - 2.15.0 | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: cddffc611a21b415a45964508cc6b7e959c70211
Total libraries scanned: 35
Scan token: fe42eae9ff3c44f4aafecd913c4104d9
Loading