Skip to content

Conversation

@hermanschaaf
Copy link

@hermanschaaf hermanschaaf commented Nov 28, 2024

What

Upgrades pickle to version 3.3.0

Why

There is a known Arbitrary Code Execution vulnerability in versions lower than 3.3.0: https://security.snyk.io/vuln/SNYK-PYTHON-JSONPICKLE-8136229.

Type of change

Select multiple if applicable.

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause a breaking change)
  • Tests (adds or updates tests)
  • Documentation (adds or updates documentation)
  • Refactor (style improvements, performance improvements, code refactoring)
  • Revert (reverts a commit)
  • CI/Build (adds or updates a script, change in external dependencies)

Dependency Change

If a new dependency is being added, please ensure that it adheres to the following guideline https://github.com/apimatic/apimatic-codegen/wiki/Policy-of-adding-new-dependencies-in-the-core-libraries

Breaking change

If the PR is introducing a breaking change, please ensure that it adheres to the following guideline https://github.com/apimatic/apimatic-codegen/wiki/Guidelines-for-maintaining-core-libraries

Testing

List the steps that were taken to test the changes

Checklist

  • My code follows the coding conventions
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added new unit tests (I'm relying on existing automated tests to catch if this breaks anything.)

@sonarqubecloud
Copy link

@mrafnadeem-apimatic
Copy link
Contributor

mrafnadeem-apimatic commented Dec 11, 2024

@hermanschaaf Thank you for opening this PR. This dependency has been updated in this PR and released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants