Skip to content

awsebcli has vulnerable requirements

0

Hi,

The packages required by awsebcli contain 2 vulnerabilities:
requests: CVE-2018-18074
urllib3: CVE-2018-20060

Both vulnerabilities have been fixed in their respective packages, but can't be upgraded in an environment with awsebcli due to outdated requirements in awsebcli. Is there any timeframe or policy on when/if these things are monitored and fixed?

Many thanks!

asked 7 years ago303 views
4 Answers
0
Accepted Answer

Thanks for your patience. 3.14.9 is out and contains the upgrade.

Yes, "safety" is quite nice. Thanks for the recommendation.

Rahul.

AWS
answered 7 years ago
0

Hi krovski,

Thanks for reporting the problem to us. I'll schedule a release for sometime next week with updated dependencies.

Thanks,
Rahul.

AWS
answered 7 years ago
0

Great, thanks!

btw: I strongly suggest to use https://github.com/pyupio/safety to do these checks on a regular basis.

answered 7 years ago
0

Thanks!!!

answered 7 years ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.