Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Update Flask #4303

Open
1 task
nickumia-reisys opened this issue May 8, 2023 · 6 comments
Open
1 task

[Snyk] Update Flask #4303

nickumia-reisys opened this issue May 8, 2023 · 6 comments
Labels
bug Software defect or bug CKAN 2.11 Issues addressed by CKAN 2.11 compliance Relating to security compliance or documentation

Comments

@nickumia-reisys
Copy link
Contributor

Please keep any sensitive details in Google Drive.

Date of report: 5/8/2023
Severity: High
Due date: 6/8/2023

Due date is based on severity and described in RA-5. 15-days for Critical, 30-days for High, and 90-days for Moderate and lower.

  • Analysis has been performed and an issue has been linked to address other occurrences for this class of vulnerability* (link)

* When a finding is identified, we create two issues. One to address the specific instance identified in the report. The other is to identify and address all other occurrences of this vulnerability within the application.

Brief description

Failing Snyk Scans:

Reference:

@hkdctol
Copy link
Contributor

hkdctol commented May 11, 2023

Can't do until completing CKAN 2.10 most likely

@nickumia-reisys
Copy link
Contributor Author

Related to

@nickumia-reisys
Copy link
Contributor Author

Blocked by CKAN releasing compatibility changes to core code. See PR for details:

@nickumia-reisys
Copy link
Contributor Author

@btylerburton
Copy link
Contributor

Conversation with CKAN core team on release schedule. No new developments, but at least they are aware that we are awaiting these fixes.

ckan/ckan#6381

@FuhuXia
Copy link
Member

FuhuXia commented Sep 17, 2024

CKAN 2.11.0 fixes ths issue with Flask==3.0.3 in the requirements.txt.

@btylerburton btylerburton added CKAN 2.11 Issues addressed by CKAN 2.11 and removed CKAN 2.10 labels Sep 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Software defect or bug CKAN 2.11 Issues addressed by CKAN 2.11 compliance Relating to security compliance or documentation
Projects
Status: 📡 Blocked
Development

No branches or pull requests

5 participants