Update dependency idna to v3 - #10
dev-mend-for-github-com[bot] wants to merge 1 commit into
Security Report
You have successfully remediated 37 vulnerabilities, but introduced 36 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2020-14343Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/20260909124741/PyYAML-3.13.tar.gz Dependency Hierarchy: -> ❌ PyYAML-3.13.tar.gz (Vulnerable Library) |
9.8 | Direct PyYAML-3.13.tar.gz |
PyYAML-3.13.tar.gz | pyyaml - 5.4 | #6 | |
CVE-2026-34516Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.13.4 | None | |
CVE-2026-34515Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.13.4 | None | |
CVE-2025-69229Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2025-69228Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2025-69227Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2025-69223Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2024-30251Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.9.4 | None | |
CVE-2025-27516Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/Jinja2-2.10.dist-info Dependency Hierarchy: -> ❌ Jinja2-2.10-py2.py3-none-any.whl (Vulnerable Library) |
7.3 | Direct Jinja2-2.10-py2.py3-none-any.whl |
Jinja2-2.10-py2.py3-none-any.whl | jinja2 - 3.1.6 | #7 | |
CVE-2023-49081Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
7.2 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.9.0 | None | |
CVE-2026-69244Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
6.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.14.3 | None | |
CVE-2025-69230Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
6.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2025-69224Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
6.5 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2024-27306Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
6.1 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.9.4 | None | |
CVE-2026-59881Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.14.2 | None | |
CVE-2026-45409Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/idna-3.7.dist-info Dependency Hierarchy: -> ❌ idna-3.7-py3-none-any.whl (Vulnerable Library) |
5.3 | Direct idna-3.7-py3-none-any.whl |
idna-3.7-py3-none-any.whl | idna - 3.15 | None | |
CVE-2026-34520Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.4 | None | |
CVE-2026-34519Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.4 | None | |
CVE-2026-34518Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.4 | None | |
CVE-2026-34517Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | Upgrade to version aiohttp - 3.13.4 or greater | None | |
CVE-2026-34514Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.13.4 | None | |
CVE-2026-34513Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | Upgrade to version aiohttp - 3.13.4 or greater | None | |
CVE-2026-22815Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | Upgrade to version aiohttp - 3.13.4 or greater | None | |
CVE-2025-69226Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2025-69225Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.13.3 | None | |
CVE-2025-53643Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.12.14 | None | |
CVE-2024-52304Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.10.11 | None | |
CVE-2023-49082Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | aiohttp - 3.9.0 | None | |
CVE-2023-47627Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.8.6 | None | |
CVE-2023-37276Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
5.3 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.8.5 | None | |
CVE-2020-28493Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/Jinja2-2.10.dist-info Dependency Hierarchy: -> ❌ Jinja2-2.10-py2.py3-none-any.whl (Vulnerable Library) |
5.3 | Direct Jinja2-2.10-py2.py3-none-any.whl |
Jinja2-2.10-py2.py3-none-any.whl | 2.11.3 | #7 | |
CVE-2026-54279Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
4.7 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.14.1 | None | |
CVE-2026-34525Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
4.0 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | Upgrade to version aiohttp - 3.13.4 or greater | None | |
CVE-2026-69243Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
3.7 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.14.2 | None | |
CVE-2023-47641Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
3.4 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.8.0 | None | |
CVE-2021-21330Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260909124740_REVVCE/python_WKYHCU/202609091247411/env/lib/python3.10/site-packages/aiohttp-3.5.3.dist-info Dependency Hierarchy: -> ❌ aiohttp-3.5.3.tar.gz (Vulnerable Library) |
3.1 | Direct aiohttp-3.5.3.tar.gz |
aiohttp-3.5.3.tar.gz | 3.7.4 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2026-69243 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-47273 | setuptools-68.0.0-py3-none-any.whl |
| CVE-2026-34518 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-34515 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69225 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2023-47627 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69230 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-53643 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2023-49081 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69228 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69223 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-34514 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-54279 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2024-30251 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-34517 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69226 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69229 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-69244 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2024-27306 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-45409 | idna-2.8-py2.py3-none-any.whl |
| CVE-2026-34525 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-22815 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69227 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2023-37276 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2025-69224 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2024-3651 | idna-2.8-py2.py3-none-any.whl |
| CVE-2021-21330 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2024-52304 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-34520 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-59890 | setuptools-68.0.0-py3-none-any.whl |
| CVE-2026-59881 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2023-47641 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2024-6345 | setuptools-68.0.0-py3-none-any.whl |
| CVE-2026-34516 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2023-49082 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-34513 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
| CVE-2026-34519 | aiohttp-3.5.3-cp37-cp37m-manylinux1_x86_64.whl |
Base branch total remaining vulnerabilities: 45
Base branch commit: null
Total libraries scanned: 22
Scan token: 9b5c80770a70424aa37cc31ca75dbb35