Skip to content

SEC-32: updating python dependencies #2

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open

SEC-32: updating python dependencies #2

wants to merge 1 commit into from

Conversation

Shasheen8
Copy link

Hello,

This PR focus on fixing 17 High SCA Vulnerabilities.
Refer to the Linear Ticket

numpy==1.22.0
opencv-python==4.4.0.42
numpy==1.26.4
opencv-python==4.8.1

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Risk: [email protected] has 1 vulnerability

Severity: High 🚨
Status: Open 🔴

Suggested reviewers 🧐: @Shasheen8

Take action by replying with an [arnica] command 💬

Actions

Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.

To acknowledge the finding as a valid code risk:

[arnica] ack <acknowledge additional details>

To dismiss the risk with a reason:

[arnica] dismiss <fp|accept|capacity> <dismissal reason>

Examples

  • [arnica] ack This is a valid risk and im looking into it

  • [arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive)

  • [arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system

  • [arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint

Arnica Notion documentation:
https://www.notion.so/together-docs/Arnica-1e5b878aad1a80318f00ce58a061a463

numpy==1.22.0
opencv-python==4.4.0.42
numpy==1.26.4
opencv-python==4.8.1

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Risk: [email protected] has 1 vulnerability

Severity: High 🚨
Status: Open 🔴

Suggested reviewers 🧐: @Shasheen8

Take action by replying with an [arnica] command 💬

Actions

Use [arnica] or [a] to interact with the Arnica bot to acknowledge or dismiss code risks.

To acknowledge the finding as a valid code risk:

[arnica] ack <acknowledge additional details>

To dismiss the risk with a reason:

[arnica] dismiss <fp|accept|capacity> <dismissal reason>

Examples

  • [arnica] ack This is a valid risk and im looking into it

  • [arnica] dismiss fp Dismissed - Risk Not Accurate: (i.e. False Positive)

  • [arnica] dismiss accept Dismiss - Risk Accepted: Allow the risk to exist in the system

  • [arnica] dismiss capacity Dismiss - No Capacity: This will need to wait for a future sprint

Arnica Notion documentation:
https://www.notion.so/together-docs/Arnica-1e5b878aad1a80318f00ce58a061a463

@Shasheen8 Shasheen8 requested a review from dac-together June 19, 2025 00:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant