You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This package has a dependency on future, which has a recently disclosed vulnerability. The project is dead, so there likely won't be a fix. The only fix right now is to remove the dependency entirely.
Yeah random people can't push to master, but you could open a pull request for review. I would be open to removing Python2 support so this future dependency is no longer required.
This package has a dependency on
future
, which has a recently disclosed vulnerability. The project is dead, so there likely won't be a fix. The only fix right now is to remove the dependency entirely.https://www.mend.io/vulnerability-database/CVE-2022-40899
https://nvd.nist.gov/vuln/detail/CVE-2022-40899
PythonCharmers/python-future#612
PythonCharmers/python-future#610
I attempted to do this myself but was denied access trying to push a branch to remote.
The text was updated successfully, but these errors were encountered: