Update GitPython to 3.1.58 to address security vulnerabilities - #66
Closed
amazon-q-developer[bot] wants to merge 1 commit into
Closed
Update GitPython to 3.1.58 to address security vulnerabilities#66amazon-q-developer[bot] wants to merge 1 commit into
amazon-q-developer[bot] wants to merge 1 commit into
Conversation
Author
|
Resolves Issue #65 |
|
Contributor
|
Superseded by the reviewed and released GitPython floor update in #79 (now published in extended-data 8.5.4). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Updates GitPython minimum version from 3.1.54 to 3.1.58 to address nine GitHub Dependabot security advisories (6 high severity, 3 medium severity).
Changes
packages/extended-data/pyproject.tomlto requiregitpython>=3.1.58Security Context
All reported Dependabot advisories list fixed versions at or below 3.1.58. This change raises the minimum required version to ensure no vulnerable versions can be installed.
Testing
The declared validation suite should be run via CI:
Lockfile Update Required
After approval, the lockfile should be updated with:
Notes