I _think_ this is a data quality issue. TL;DR: * PYSEC-2023-121 and GHSA-5c9c-6x87-f9vm are aliases of one another * PYSEC-2023-121 has no fix, but GHSA-5c9c-6x87-f9vm _does_ (`>= 1.5.4`) Ref: https://osv.dev/vulnerability/GHSA-5c9c-6x87-f9vm I can look into a data tweak for the above.