CyberSource / CyberSource/cybersource-rest-client-python

pyOpenSSL and Cryptography

Open
#118 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
24
Forks
42
Avg merge
29m
Merged PRs (30d)
1

Description

Can you please update these in the setup.py and other bits as needed since they're pinned to vulnerable versions?

You can see the advisories here:

https://security.snyk.io/vuln/SNYK-PYTHON-PYOPENSSL-7161590
https://security.snyk.io/vuln/SNYK-PYTHON-CRYPTOGRAPHY-7161587

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading setup.py and the two linked Snyk advisories to identify the vulnerable pyOpenSSL and cryptography pins. Update the dependency declarations and any other affected project metadata, then verify that no vulnerable versions remain.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.