arch icon indicating copy to clipboard operation
arch copied to clipboard

[Snyk] Security upgrade mistune from 0.8.4 to 2.0.3

Open snyk-bot opened this issue 1 year ago • 1 comments

Snyk has created this PR to fix one or more vulnerable packages in the `pip` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • doc/requirements.txt
⚠️ Warning
Sphinx 1.8.6 has requirement docutils<0.18,>=0.11, but you have docutils 0.18.1.
notebook 5.7.15 requires terminado, which is not installed.
nbformat 4.4.0 requires jsonschema, which is not installed.
nbconvert 5.6.1 has requirement mistune<2,>=0.8.1, but you have mistune 2.0.3.
jupyter 1.0.0 requires qtconsole, which is not installed.
Jinja2 2.11.3 requires MarkupSafe, which is not installed.
ipython 5.10.0 requires simplegeneric, which is not installed.

Vulnerabilities that will be fixed

By pinning:
Severity Issue Upgrade Breaking Change Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-PYTHON-MISTUNE-2940625
mistune:
0.8.4 -> 2.0.3
No No Known Exploit

Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

snyk-bot avatar Sep 05 '22 08:09 snyk-bot

Codecov Report

Base: 99.42% // Head: 99.42% // No change to project coverage :thumbsup:

Coverage data is based on head (81b7852) compared to base (00dbf50). Patch has no changes to coverable lines.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #615   +/-   ##
=======================================
  Coverage   99.42%   99.42%           
=======================================
  Files          75       75           
  Lines       15442    15442           
  Branches     1432     1432           
=======================================
  Hits        15353    15353           
  Misses         63       63           
  Partials       26       26           

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

:umbrella: View full report at Codecov.
:loudspeaker: Do you have feedback about the report comment? Let us know in this issue.

codecov[bot] avatar Sep 05 '22 08:09 codecov[bot]