You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Memgraph version gqlalchemy = ">=1.4.1,<2.0.0" Environment Python 3.11, memgraph running the memgraph/memgraph-mage docker image
Describe the bug
The python docker package is being required as a dependency which is dragging in the pywin32 library which currently has CVE's open against the version imported see:
CVE-2021-32559 in case the GitHub one is not available to you
To Reproduce Steps to reproduce the behavior:
install the library, run any SAST, or DAST tool
Expected behavior That a system running on Linux would not be importing the pywin32 library and if required it would be pinned to versions that don't have CVE's
Logs N/A
Additional context is the python docker package really a requirement or can it be made optional?
The text was updated successfully, but these errors were encountered:
Thank you @matroscoe for opening the issue. We will work on the release at the end of the next week and update the necessary dependencies. Stay tuned :)
Memgraph version gqlalchemy = ">=1.4.1,<2.0.0"
Environment Python 3.11, memgraph running the memgraph/memgraph-mage docker image
Describe the bug
The python
docker
package is being required as a dependency which is dragging in thepywin32
library which currently has CVE's open against the version imported see:To Reproduce Steps to reproduce the behavior:
Expected behavior That a system running on Linux would not be importing the pywin32 library and if required it would be pinned to versions that don't have CVE's
Logs N/A
Additional context is the python
docker
package really a requirement or can it be made optional?The text was updated successfully, but these errors were encountered: