Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump dependencies to resolve CVES #55

Closed
s7clarke10 opened this issue Sep 2, 2024 · 1 comment · Fixed by #56
Closed

Bump dependencies to resolve CVES #55

s7clarke10 opened this issue Sep 2, 2024 · 1 comment · Fixed by #56

Comments

@s7clarke10
Copy link
Contributor

s7clarke10 commented Sep 2, 2024

Hi @jlloyd-widen ,

Looking at dependabot securities, the cryptography and certifi need to be bumped to resolve several CVES that have been raised on them.

It is probably best to bump the Meltano SDK at the same time.

Issue:
I tried a poetry update to bring in the latest dependencies with a view of raising a PR for this. It looks however that the dependencies update doesn't appear to finish in the poetry resolver. A poetry update command spins and never completes.

I don't know if you have had this issue before? Are you able to patch the pyproject.yaml and re-generated a poetry.lock file resolving these issues please?

I'm not sure if you have enable dependabot securities on your Repo but it is probably a good idea so there is visibility of vulnerabilities in the poetry.lock file.

Thanka
Steve

@s7clarke10
Copy link
Contributor Author

Thank you @jlloyd-widen for quickly resolving this. Much appreciate 👏.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant