Skip to content

chore(deps): update dependency google-cloud-logging to v3.11.3

7b213a3
Select commit
Loading
Failed to load commit list.
Open

chore(deps): update dependency google-cloud-logging to v3.11.3 #5

chore(deps): update dependency google-cloud-logging to v3.11.3
7b213a3
Select commit
Loading
Failed to load commit list.
Staging - WhiteSource for GitHub.com / Mend Security Check failed Mar 30, 2026 in 12m 39s

Security Report

❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle,CocoaPods. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

gradle

/tmp/ws-scm/AutoGPT/classic/frontend/android/build.gradle

Step Level Description Details
Preparing the project for scan ⚠Warn One or more of the installations failed failed running mend init script (mendDeps):
NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED

FAILURE: Build failed with an exception.

* Where:
Settings file '/tmp/ws-scm/AutoGPT/classic/frontend/android/settings.gradle' line: 6

* What went wrong:
A problem occurred evaluating settings 'andro...

pip

/tmp/ws-scm/AutoGPT/classic/benchmark/agbenchmark/challenges/verticals/code/6_battleship/artifacts_in/product_requirements.txt

Step Level Description Details
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: /tmp/ws-ua_20260330231235_ZCIGUJ/cmd_HSYIMN/20260330231302/ZBEFSO_script.sh
    Error lines:
    [ERROR: Invalid requirement: 'Specifications for Battleship': Expected semicolon (after name with no version specifier) or end, Specifications for Battleship, ^ (from line 1 of /tmp/ws-scm/AutoGPT/classic/benchmark/agbenchmark/challenges/verticals/co...
  • pip install command failed, trying to install dependencies one by one
  • Failed to parse the following dependencies: *[Players take turns calling out a row and column, attempting to name a square containing one of the opponent's ships., The Grid: Each player's grid is a 10x10 grid, identified by rows (using numbers 1-10) and columns (using letters A-J)., Each ship occupies contiguous squares on the grid, arranged either horizontally or vertically., At the start of t...
  • Failed to execute command: /tmp/ws-ua_20260330231235_ZCIGUJ/cmd_HSYIMN/20260330231305/IPZDGI_script.sh
    Error lines:
    [ERROR: Could not find a version that satisfies the requirement Specifications (from versions: none), ERROR: No matching distribution found for Specifications]
    Output lines:
    [Looking in links: /tmp/ws-ua_20260330231235_ZCIGUJ/python_TUKMOJ/20260330231238/1]
  • Failed to get hierarchy tree, trying to collect a flat list (which may only contain partial results)

/tmp/ws-scm/AutoGPT/classic/original_autogpt

Step Level Description Details
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: /tmp/ws-ua_20260330231235_ZCIGUJ/cmd_HSYIMN/20260330231312/VSUWLT_script.sh
    Error lines:
    [ERROR: Package 'agpt' requires a different Python: 3.9.25 not in '<4.0,>=3.10']
    Output lines:
    [Looking in links: /tmp/ws-ua_20260330231235_ZCIGUJ/python_TUKMOJ/20260330231238, Processing ./., Installing build dependencies: started, Installing build dependencies:...
  • Failed to get hierarchy tree, trying to collect a flat list (which may only contain partial results)

/tmp/ws-scm/AutoGPT/classic/original_autogpt/autogpt/app

Step Level Description Details
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: /tmp/ws-ua_20260330231235_ZCIGUJ/cmd_HSYIMN/20260330231322/ZWUWNB_script.sh
    Error lines:
    [ error: subprocess-exited-with-error, � Getting requirements to build wheel did not run successfully., � exit code: 1, ��> [17 lines of output], Traceback (most recent call last):, File "/tmp/ws-ua_20260330231235_ZCIGUJ/python_TUKMOJ/2026033023...
  • Failed to get hierarchy tree, trying to collect a flat list (which may only contain partial results)

poetry

/tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml

Step Level Description Details
Preparing the project for scan ⚠Warn One or more of the installations failed poetry install --no-root failed with exit code 1 for manifest "/tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml". output:
The currently activated Python version 3.9.25 is not supported by the project (^3.10).
Trying to find and use a compatible version.
Using python3.13 (3.13.11)
Creating virtualenv autogpt-forge-Eq_saOJk-py3.13 in /home/wss-scanner/.cache/pypoetry/virtualenvs
Installing depen...
Resolving the project ⚠Warn Failed to build the dependency tree, fallback was used in the scan, results may be incomplete Error occurred while parsing the poetry show --tree command on the /tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml file

/tmp/ws-scm/AutoGPT/classic/original_autogpt/pyproject.toml

Step Level Description Details
Resolving the project ⚠Warn Failed to build the dependency tree, fallback was used in the scan, results may be incomplete Error occurred while parsing the poetry show --tree command on the /tmp/ws-scm/AutoGPT/classic/original_autogpt/pyproject.toml file

You have successfully remediated 6 vulnerabilities, but introduced 11 new vulnerabilities in this branch.

❌ New vulnerabilities:
Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2025-69223

Dependency Hierarchy:

-> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

High 7.5 Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl None
CVE-2025-69223

Dependency Hierarchy:

-> supabase-2.7.4-py3-none-any.whl (Root Library)

   -> realtime-2.0.2-py3-none-any.whl

     -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

High 7.5 Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl supabase-2.7.4-py3-none-any.whl None
CVE-2025-67221

Dependency Hierarchy:

-> duckduckgo_search-6.1.7-py3-none-any.whl (Root Library)

   -> ❌ orjson-3.10.5-cp38-none-win32.whl (Vulnerable Library)

High 7.5 Transitive orjson-3.10.5-cp38-none-win32.whl duckduckgo_search-6.1.7-py3-none-any.whl None
CVE-2024-53981

Dependency Hierarchy:

-> ❌ python_multipart-0.0.7.tar.gz (Vulnerable Library)

High 7.5 Direct python_multipart-0.0.7.tar.gz python_multipart-0.0.7.tar.gz python-multipart - 0.0.18,python-multipart - 0.0.18 None
CVE-2025-69224

Dependency Hierarchy:

-> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

Medium 6.5 Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl None
CVE-2025-69224

Dependency Hierarchy:

-> supabase-2.7.4-py3-none-any.whl (Root Library)

   -> realtime-2.0.2-py3-none-any.whl

     -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

Medium 6.5 Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl supabase-2.7.4-py3-none-any.whl None
CVE-2025-69226

Dependency Hierarchy:

-> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

Medium 5.3 Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl None
CVE-2025-69226

Dependency Hierarchy:

-> supabase-2.7.4-py3-none-any.whl (Root Library)

   -> realtime-2.0.2-py3-none-any.whl

     -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

Medium 5.3 Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl supabase-2.7.4-py3-none-any.whl None
CVE-2025-53643

Dependency Hierarchy:

-> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

Medium 5.3 Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl 3.12.14 None
CVE-2025-53643

Dependency Hierarchy:

-> supabase-2.7.4-py3-none-any.whl (Root Library)

   -> realtime-2.0.2-py3-none-any.whl

     -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library)

Medium 5.3 Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl supabase-2.7.4-py3-none-any.whl Transitive 3.12.14 None
CVE-2021-33430

Dependency Hierarchy:

-> ❌ numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl (Vulnerable Library)

Medium 5.3 Direct numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-53643 aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-69226 aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-69223 aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2025-69224 aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
CVE-2026-0994 protobuf-5.28.0-cp38-abi3-manylinux2014_x86_64.whl
CVE-2025-4565 protobuf-5.28.0-cp38-abi3-manylinux2014_x86_64.whl

Base branch total remaining vulnerabilities: 91
Base branch commit: b74c8d4152d600b0a70b423a8ee2d3fcd7737272


Total libraries scanned: 986

Scan token: 0698510590d845dfabd3cc5889c3d907