PegaProx_project-pegaprox/requirements-dev.txt
mkellermann97 cc435bd6ba security(deps): raise Flask floor to 3.1.3 (CVE-2026-27205) + pytest to 9.0.3 (CVE-2025-71176)
CodeAnt/Aikido SCA flagged the pinned FLOORS, not the installed versions (which
already satisfy these):
- Flask >=3.0.3 -> >=3.1.3: 3.1.3 patches CVE-2026-27205 (session-cache info
  disclosure — __contains__/__len__ didn't mark the session accessed, so the
  Vary:Cookie header was omitted and a shared cache could serve one user's
  response to another). Installed is already 3.1.3; this tightens the floor.
- pytest >=8.0 -> >=9.0.3 (dev-only): 9.0.3 patches CVE-2025-71176 (predictable
  /tmp/pytest-of-{user} tmpdir → TOCTOU local priv-esc/DoS). Never ships in the
  appliance; installed is already 9.1.1.
paramiko CVE-2026-44405 (SHA-1 in rsakey, CVSS 3.4 LOW) HELD — its only fix is the
5.0.0 major, too risky for an SSH-heavy app vs a low cosmetic-crypto finding; Nico's call.
Verified: app factory imports on Flask 3.1.3, /health 200, 18/18 tests green.
2026-07-13 09:44:25 +02:00

7 lines
342 B
Plaintext

# Dev / test-only dependencies (NOT needed at runtime — do not ship in the appliance).
# Install: pip install -r requirements-dev.txt
# Run: python -m pytest
# NS Jul 2026 — >=9.0.3 patches CVE-2025-71176 (insecure /tmp/pytest-of-{user} tmpdir,
# TOCTOU local priv-esc/DoS). Dev/CI-only; never ships in the appliance.
pytest>=9.0.3