-
Notifications
You must be signed in to change notification settings - Fork 14.5k
Open
Labels
Milestone
Description
An automated security scan of 18.1.0-rc2 complained about the following dependencies:
- llvm/utils/git/requirements.txt
- gitpython==3.1.32 CVE-2023-40590 CVE-2023-41040 CVE-2024-22190
- cryptography==41.0.3 CVE-2023-4807CVE-2023-49083 CVE-2023-50782
- urllib3==1.26.12 CVE-2023-43804 CVE-2023-45803
- requests==2.28.1 CVE-2023-32681
- third-party/benchmark/requirements.txt
- numpy==1.19.4 CVE-2021-34141 CVE-2021-41495 CVE-2021-41496
- pandas==1.1.5 CVE-2020-13091
- scipy==1.5.4 CVE-2018-1999024
- mlir/utils/vscode/package-lock.json
- semver:7.3.7 CVE-2022-25883
- minimatch Sonatype CWE 1333
- llvm/docs/requirements.txt
- sphinx-bootstrap-theme==0.8.1 CVE-2019-11358 CVE-2020-11023 CVE-2020-23064 CVE-2020-11022
This is the follow-up from #64417 for the 18.1.0 release
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Needs Fix