Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable dependencies #22

Open
notexactlyawe opened this issue Oct 16, 2018 · 0 comments
Open

Vulnerable dependencies #22

notexactlyawe opened this issue Oct 16, 2018 · 0 comments
Labels
good first issue Good for newcomers

Comments

@notexactlyawe
Copy link
Collaborator

GitHub has warned us that we have vulnerable dependencies. This is OK right now as this is not deployed anywhere, but we should update the versions of these dependencies before using this.

flask needs to be updated to >= 0.12.3

pycrypto needs to be updated apparently, but GitHub provides no fix. I'd be happy if someone could convince me that it doesn't affect us.

You can update these by updating requirements.txt with the appropriate version, but please make sure the application still works on the new versions! In your PR I'd like to see evidence of running the tests and screenshots of the application working.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

1 participant