mend-for-github-com[bot]

Results 1661 issues of mend-for-github-com[bot]

Vulnerable Library - dask_ml-2024.4.4-py3-none-any.whl Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20250423134520_RSTRUL/python_EXEDNB/20250423134523/urllib3-2.4.0-py3-none-any.whl ## Vulnerabilities | Vulnerability | Severity | CVSS | Dependency | Type | Fixed in (dask_ml...

Mend: dependency security vulnerability

Vulnerable Library - nbformat-5.10.4-py3-none-any.whl Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20250423134520_RSTRUL/python_EXEDNB/20250423134523/jupyter_core-5.7.2-py3-none-any.whl ## Vulnerabilities | Vulnerability | Severity | CVSS | Dependency | Type | Fixed in (nbformat...

Mend: dependency security vulnerability

Vulnerable Library - tornado-6.4.2-cp38-abi3-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_17_x86_64.manylinux2014_x86_64.whl Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed. Library home page: https://files.pythonhosted.org/packages/22/55/b78a464de78051a30599ceb6983b01d8f732e6f69bf37b4ed07f642ac0fc/tornado-6.4.2-cp38-abi3-manylinux_2_5_x86_64.manylinux1_x86_64.manylinux_2_17_x86_64.manylinux2014_x86_64.whl Path to dependency file: /requirements.txt Path to vulnerable...

Mend: dependency security vulnerability

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [react](https://react.dev/) ([source](https://redirect.github.com/facebook/react/tree/HEAD/packages/react)) | dependencies | major | [`^15.3.2` -> `^16.5.0`](https://renovatebot.com/diffs/npm/react/15.3.2/16.5.0) | By merging...

security fix

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [express](https://expressjs.com/) ([source](https://redirect.github.com/expressjs/express)) | dependencies | minor | [`^4.14.1` -> `^4.21.1`](https://renovatebot.com/diffs/npm/express/4.14.1/4.21.1) | By merging...

security fix

Vulnerable Library - opentok/opentok-v4.14.2 ## Vulnerabilities | Vulnerability | Severity | CVSS | Exploit Maturity | EPSS | Dependency | Type | Fixed in (opentok/opentok-v4.14.2 version) | Remediation Possible** |...

Mend: dependency security vulnerability

Vulnerable Library - netty-codec-http-4.1.119.Final.jar Library home page: https://netty.io/ Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.119.Final/23196984df6083cc39bef22a54c6cf5b157f3824/netty-codec-http-4.1.119.Final.jar ## Vulnerabilities | Vulnerability | Severity | CVSS | Exploit Maturity |...

Mend: dependency security vulnerability

Vulnerable Library - netty-handler-4.1.119.Final.jar Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec/4.1.119.Final/337ca8e8c3ef23925e02d56347b414d7616d1d02/netty-codec-4.1.119.Final.jar ## Vulnerabilities | Vulnerability | Severity | CVSS | Exploit Maturity | EPSS | Dependency |...

Mend: dependency security vulnerability

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [io.netty:netty-codec-http](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | dependencies | patch | `4.1.119.Final` -> `4.1.125.Final` | By merging...

security fix

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [opentok](https://redirect.github.com/opentok/opentok-node) | dependencies | minor | [`2.10.0` -> `2.17.0`](https://renovatebot.com/diffs/npm/opentok/2.10.0/2.17.0) | By merging this...

security fix