[rosedu-admins] [rosedu/rosedu-people] One of your dependencies may have a security vulnerability

Victor Ciurel victor.ciurel at rosedu.org
Fri Jul 13 13:07:54 EEST 2018


rosedu-people is kinda broken and backlogged for now. Probabil va fi 
reînceput de la zero, dacă vom determina că are sens.

Victor

On 13.07.2018 08:30, Mihai Maruseac wrote:
> Guys... am mai primit câteva notificări de același tip, see 
> https://s19.postimg.cc/i5kv4c6xv/Screenshot_from_2018-07-12_22-28-57.png
> 
> On Thu, Jul 12, 2018 at 11:34 AM, Mihai Maruseac 
> <mihai.maruseac at gmail.com <mailto:mihai.maruseac at gmail.com>> wrote:
> 
>     Cine se ocupă de ROSEdu people acum?
> 
>     ---------- Forwarded message ----------
>     From: *GitHub* <notifications at github.com
>     <mailto:notifications at github.com>>
>     Date: Thu, Jul 12, 2018 at 7:49 AM
>     Subject: [rosedu/rosedu-people] One of your dependencies may have a
>     security vulnerability
>     To: rosedu/rosedu-people <rosedu-people at noreply.github.com
>     <mailto:rosedu-people at noreply.github.com>>
>     Cc: Security alert <security_alert at noreply.github.com
>     <mailto:security_alert at noreply.github.com>>
> 
> 
>     __
>     	
>     We found a potential security vulnerabilty in one of your dependencies
>     GitHub <https://github.com> 	Sign in <https://github.com/login>
> 
>     *mihaimaruseac,*
> 
>     We found a potential security vulnerability in a repository for
>     which you have been granted security alert access.
> 
>     @rosedu 	rosedu/rosedu-people <https://github.com/rosedu/rosedu-people>
>     Known *moderate severity* security vulnerability detected in |Pillow
>     < 3.3.2| defined in |requirements.txt|
>     <https://github.com/rosedu/rosedu-people/blob/master/requirements.txt>.
>     |requirements.txt|
>     <https://github.com/rosedu/rosedu-people/blob/master/requirements.txt>
>     update suggested: |Pillow ~> 3.3.2|.
>     Always verify the validity and compatibility of suggestions with
>     your codebase.
> 
>     Review vulnerable dependency
>     <https://github.com/rosedu/rosedu-people/network/dependencies>
> 
>     ------------------------------------------------------------------------
> 
>     Only users who have been assigned access to security alerts will
>     receive these notifications.
> 
>     __Unsubscribe__
>     <https://github.com/notifications/unsubscribe-vulnerability/AATuf8AwkICZk2y9BJX1zfVWVUg1Y1qSks5uF2HegaJpZM4VNAuM>
>     · Email preferences <https://github.com/settings/emails> · Terms
>     <https://help.github.com/articles/github-terms-of-service/> ·
>     Privacy <https://help.github.com/articles/github-privacy-policy/> ·
>     Sign into GitHub <https://github.com/login>
> 
>     GitHub, Inc.
>     88 Colin P Kelly Jr St.
>     San Francisco, CA 94107
>     <https://maps.google.com/?q=88+Colin+P+Kelly+Jr+St.%0D%0A+++++++++++++++++++++++++++++San+Francisco,+CA+94107&entry=gmail&source=g>
> 
>     	
> 
> 
> 
> 
>     -- 
>     Mihai Maruseac (MM)
>     "If you can't solve a problem, then there's an easier problem you
>     can solve: find it." -- George Polya
> 
> 
> 
> 
> -- 
> Mihai Maruseac (MM)
> "If you can't solve a problem, then there's an easier problem you can 
> solve: find it." -- George Polya


More information about the rosedu-admins mailing list