Skip to content

chore(deps): update dependency aiohttp to v3.12.14

5d9c380
Select commit
Loading
Failed to load commit list.
Open

chore(deps): update dependency aiohttp to v3.12.14 #9

chore(deps): update dependency aiohttp to v3.12.14
5d9c380
Select commit
Loading
Failed to load commit list.
Staging - WhiteSource for GitHub.com / Mend Security Check failed Mar 31, 2026 in 14m 2s

Security Report

❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle,CocoaPods. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

gradle

/tmp/ws-scm/AutoGPT/classic/frontend/android/build.gradle

Step Level Description Details
Preparing the project for scan ⚠Warn One or more of the installations failed failed running mend init script (mendDeps):
NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED

FAILURE: Build failed with an exception.

* Where:
Settings file '/tmp/ws-scm/AutoGPT/classic/frontend/android/settings.gradle' line: 6

* What went wrong:
A problem occurred evaluating settings 'andro...

pip

/tmp/ws-scm/AutoGPT/classic/benchmark/agbenchmark/challenges/verticals/code/6_battleship/artifacts_in/product_requirements.txt

Step Level Description Details
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: /tmp/ws-ua_20260331221024_SBSBRI/cmd_OCRYYY/20260331221100/QTKGCE_script.sh
    Error lines:
    [ERROR: Invalid requirement: 'Specifications for Battleship': Expected semicolon (after name with no version specifier) or end, Specifications for Battleship, ^ (from line 1 of /tmp/ws-scm/AutoGPT/classic/benchmark/agbenchmark/challenges/verticals/co...
  • pip install command failed, trying to install dependencies one by one
  • Failed to parse the following dependencies: *[Players take turns calling out a row and column, attempting to name a square containing one of the opponent's ships., The Grid: Each player's grid is a 10x10 grid, identified by rows (using numbers 1-10) and columns (using letters A-J)., Each ship occupies contiguous squares on the grid, arranged either horizontally or vertically., At the start of t...
  • Failed to execute command: /tmp/ws-ua_20260331221024_SBSBRI/cmd_OCRYYY/20260331221103/TLISQA_script.sh
    Error lines:
    [ERROR: Could not find a version that satisfies the requirement Specifications (from versions: none), ERROR: No matching distribution found for Specifications]
    Output lines:
    [Looking in links: /tmp/ws-ua_20260331221024_SBSBRI/python_AFGKZQ/20260331221026/1]
  • Failed to get hierarchy tree, trying to collect a flat list (which may only contain partial results)

/tmp/ws-scm/AutoGPT/classic/original_autogpt

Step Level Description Details
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: /tmp/ws-ua_20260331221024_SBSBRI/cmd_OCRYYY/20260331221111/XHUOQT_script.sh
    Error lines:
    [ERROR: Package 'agpt' requires a different Python: 3.9.25 not in '<4.0,>=3.10']
    Output lines:
    [Looking in links: /tmp/ws-ua_20260331221024_SBSBRI/python_AFGKZQ/20260331221026, Processing ./., Installing build dependencies: started, Installing build dependencies:...
  • Failed to get hierarchy tree, trying to collect a flat list (which may only contain partial results)

/tmp/ws-scm/AutoGPT/classic/original_autogpt/autogpt/app

Step Level Description Details
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: /tmp/ws-ua_20260331221024_SBSBRI/cmd_OCRYYY/20260331221122/CXKHMS_script.sh
    Error lines:
    [ error: subprocess-exited-with-error, � Getting requirements to build wheel did not run successfully., � exit code: 1, ��> [17 lines of output], Traceback (most recent call last):, File "/tmp/ws-ua_20260331221024_SBSBRI/python_AFGKZQ/2026033122...
  • Failed to get hierarchy tree, trying to collect a flat list (which may only contain partial results)

poetry

/tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml

Step Level Description Details
Preparing the project for scan ⚠Warn One or more of the installations failed poetry install --no-root failed with exit code 1 for manifest "/tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml". output:
The currently activated Python version 3.9.25 is not supported by the project (^3.10).
Trying to find and use a compatible version.
Using python3.13 (3.13.11)
Creating virtualenv autogpt-forge-Eq_saOJk-py3.13 in /home/wss-scanner/.cache/pypoetry/virtualenvs
Installing depen...
Resolving the project ⚠Warn Failed to build the dependency tree, fallback was used in the scan, results may be incomplete Error occurred while parsing the poetry show --tree command on the /tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml file

/tmp/ws-scm/AutoGPT/classic/original_autogpt/pyproject.toml

Step Level Description Details
Resolving the project ⚠Warn Failed to build the dependency tree, fallback was used in the scan, results may be incomplete Error occurred while parsing the poetry show --tree command on the /tmp/ws-scm/AutoGPT/classic/original_autogpt/pyproject.toml file

5 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:
Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2026-0994

Dependency Hierarchy:

-> chromadb-0.4.22-py3-none-any.whl (Root Library)

   -> onnxruntime-1.17.1-cp310-cp310-macosx_11_0_universal2.whl

     -> ❌ protobuf-4.25.2-cp310-abi3-win32.whl (Vulnerable Library)

High 8.6 Transitive protobuf-4.25.2-cp310-abi3-win32.whl chromadb-0.4.22-py3-none-any.whl None
CVE-2025-67221

Dependency Hierarchy:

-> duckduckgo_search-6.1.7-py3-none-any.whl (Root Library)

   -> ❌ orjson-3.10.5-cp38-none-win32.whl (Vulnerable Library)

High 7.5 Transitive orjson-3.10.5-cp38-none-win32.whl duckduckgo_search-6.1.7-py3-none-any.whl None
CVE-2025-4565

Dependency Hierarchy:

-> chromadb-0.4.22-py3-none-any.whl (Root Library)

   -> onnxruntime-1.17.1-cp310-cp310-macosx_11_0_universal2.whl

     -> ❌ protobuf-4.25.2-cp310-abi3-win32.whl (Vulnerable Library)

High 7.5 Transitive protobuf-4.25.2-cp310-abi3-win32.whl chromadb-0.4.22-py3-none-any.whl Transitive 4.25.8 None
CVE-2024-53981

Dependency Hierarchy:

-> ❌ python_multipart-0.0.7.tar.gz (Vulnerable Library)

High 7.5 Direct python_multipart-0.0.7.tar.gz python_multipart-0.0.7.tar.gz python-multipart - 0.0.18,python-multipart - 0.0.18 None
CVE-2021-33430

Dependency Hierarchy:

-> ❌ numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl (Vulnerable Library)

Medium 5.3 Direct numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl None

Base branch total remaining vulnerabilities: 91
Base branch commit: b74c8d4152d600b0a70b423a8ee2d3fcd7737272


Total libraries scanned: 991

Scan token: 0c3bfc5acbbb4a2aac280bd4f7912559