mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
CodeAnt/Aikido SCA flagged the pinned FLOORS, not the installed versions (which
already satisfy these):
- Flask >=3.0.3 -> >=3.1.3: 3.1.3 patches CVE-2026-27205 (session-cache info
disclosure — __contains__/__len__ didn't mark the session accessed, so the
Vary:Cookie header was omitted and a shared cache could serve one user's
response to another). Installed is already 3.1.3; this tightens the floor.
- pytest >=8.0 -> >=9.0.3 (dev-only): 9.0.3 patches CVE-2025-71176 (predictable
/tmp/pytest-of-{user} tmpdir → TOCTOU local priv-esc/DoS). Never ships in the
appliance; installed is already 9.1.1.
paramiko CVE-2026-44405 (SHA-1 in rsakey, CVSS 3.4 LOW) HELD — its only fix is the
5.0.0 major, too risky for an SSH-heavy app vs a low cosmetic-crypto finding; Nico's call.
Verified: app factory imports on Flask 3.1.3, /health 200, 18/18 tests green.
7 lines
342 B
Plaintext
7 lines
342 B
Plaintext
# Dev / test-only dependencies (NOT needed at runtime — do not ship in the appliance).
|
|
# Install: pip install -r requirements-dev.txt
|
|
# Run: python -m pytest
|
|
# NS Jul 2026 — >=9.0.3 patches CVE-2025-71176 (insecure /tmp/pytest-of-{user} tmpdir,
|
|
# TOCTOU local priv-esc/DoS). Dev/CI-only; never ships in the appliance.
|
|
pytest>=9.0.3
|