Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability in Upstream Dependency (ecdsa) #218

Closed
rkelley-eab opened this issue Jan 29, 2024 · 0 comments · Fixed by #220
Closed

Security Vulnerability in Upstream Dependency (ecdsa) #218

rkelley-eab opened this issue Jan 29, 2024 · 0 comments · Fixed by #220

Comments

@rkelley-eab
Copy link

Hi there --

In a monthly automated scan, a dependency of this library showed a security vulnerability.

Tracing the dependency tree, it looks like pycognito -> python-jose[cryptography] -> ecdsa. Normally I would look to the source of the issue for a fix, but it seems that:

It's particularly unfortunate since python-jose claims that the library in question isn't even in use for python-jose[cryptography]. Alas, for reporting reasons, my team will need to address it regardless.

I was hoping you could provide me some clarity on whether or not you intend to address the vulnerability within the scope of this library.

Thank you for reading, and thank you for your contributions to OSS!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant