πŸ”’ [IBM OSPO Security Notification] β€” IBM/processmining

Open
#29 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
jupyter-notebook, python
Domain
security

Research direction

Start by locating the repository's Python dependency manifests and reviewing the listed certifi, urllib3, aiohttp, requests, idna, pytest, and tqdm versions. Update dependencies to the patched versions shown, then verify the security alerts are cleared; the issue states it closes automatically when all alerts are resolved.

Written by the indexing model from the issue text.

Description

security

πŸ”’ [IBM OSPO Security Notification] β€” IBM/processmining

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β€”
they will never trigger warnings or archiving.

πŸ’‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β†’ Advanced Security β†’ Dependabot security updates β†’ Enable.

πŸ“– New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @Tissandier

Dependabot Alerts
Severity CVE/GHSA Package Affected Patched Deadline Fix PR
🟠 high CVE-2023-37920 certifi >= 2015.4.28, < 2023.7.22 2023.7.22 2026-10-20 β€”
🟠 high CVE-2023-43804 urllib3 < 1.26.17 1.26.17 2026-10-20 β€”
🟠 high CVE-2024-23334 aiohttp >= 1.0.5, < 3.9.2 3.9.2 2026-10-20 β€”
🟠 high CVE-2024-30251 aiohttp < 3.9.4 3.9.4 2026-10-20 β€”
🟠 high CVE-2026-44431 urllib3 >= 1.23, < 2.7.0 2.7.0 2026-10-19 β€”
🟠 high CVE-2026-69244 aiohttp <= 3.14.2 3.14.3 2026-10-19 β€”
🟑 medium CVE-2022-23491 certifi >= 2017.11.05, < 2022.12.07 2022.12.07 2026-12-19 β€”
🟑 medium CVE-2023-32681 requests >= 2.3.0, < 2.31.0 2.31.0 2026-12-19 β€”
🟑 medium CVE-2023-37276 aiohttp <= 3.8.4 3.8.5 2026-12-19 β€”
🟑 medium CVE-2023-45803 urllib3 >= 0, < 1.26.18 1.26.18 2026-12-19 β€”
🟑 medium CVE-2023-47627 aiohttp < 3.8.6 3.8.6 2026-12-19 β€”
🟑 medium GHSA-pjjw-qhg8-p2p9 aiohttp < 3.8.6 3.8.6 2026-12-19 β€”
🟑 medium CVE-2023-49082 aiohttp < 3.9.0 3.9.0 2026-12-19 β€”
🟑 medium CVE-2023-49081 aiohttp < 3.9.0 3.9.0 2026-12-19 β€”
🟑 medium CVE-2024-23829 aiohttp < 3.9.2 3.9.2 2026-12-19 β€”
🟑 medium CVE-2024-3651 idna < 3.7 3.7 2026-12-19 β€”
🟑 medium CVE-2024-27306 aiohttp < 3.9.4 3.9.4 2026-12-19 β€”
🟑 medium CVE-2024-35195 requests < 2.32.0 2.32.0 2026-12-19 β€”
🟑 medium CVE-2024-37891 urllib3 < 1.26.19 1.26.19 2026-12-19 β€”
🟑 medium CVE-2024-52304 aiohttp <= 3.10.10 3.10.11 2026-12-19 β€”
🟑 medium CVE-2026-25645 requests < 2.33.0 2.33.0 2026-12-18 β€”
🟑 medium CVE-2026-22815 aiohttp <= 3.13.3 3.13.4 2026-12-18 β€”
🟑 medium CVE-2026-34515 aiohttp <= 3.13.3 3.13.4 2026-12-18 β€”
🟑 medium CVE-2026-34516 aiohttp <= 3.13.3 3.13.4 2026-12-18 β€”
🟑 medium CVE-2026-34525 aiohttp <= 3.13.3 3.13.4 2026-12-18 β€”
🟑 medium CVE-2025-71176 pytest < 9.0.3 9.0.3 2026-12-18 β€”
🟑 medium CVE-2026-45409 idna < 3.15 3.15 2026-12-18 β€”
🟑 medium CVE-2026-34993 aiohttp < 3.14.0 3.14.0 2026-12-18 β€”
🟑 medium CVE-2026-47265 aiohttp < 3.14.0 3.14.0 2026-12-18 β€”
🟑 medium CVE-2026-54278 aiohttp <= 3.14.0 3.14.1 2026-12-18 β€”
🟑 medium CVE-2026-54276 aiohttp <= 3.14.0 3.14.1 2026-12-18 β€”
🟑 medium CVE-2026-54274 aiohttp <= 3.14.0 3.14.1 2026-12-18 β€”
🟑 medium CVE-2026-54273 aiohttp <= 3.14.0 3.14.1 2026-12-18 β€”
🟑 medium CVE-2026-54277 aiohttp <= 3.14.0 3.14.1 2026-12-18 β€”
🟑 medium CVE-2026-59881 aiohttp <= 3.14.1 3.14.2 2026-12-18 β€”
🟑 medium CVE-2026-69243 aiohttp <= 3.14.1 3.14.2 2026-12-18 β€”
πŸ”΅ low CVE-2021-21330 aiohttp < 3.7.4 3.7.4 β€” β€”
πŸ”΅ low CVE-2023-47641 aiohttp < 3.8.0 3.8.0 β€” β€”
πŸ”΅ low CVE-2024-34062 tqdm >= 4.4.0, < 4.66.3 4.66.3 β€” β€”
πŸ”΅ low CVE-2026-34513 aiohttp <= 3.13.3 3.13.4 β€” β€”
πŸ”΅ low CVE-2026-34514 aiohttp <= 3.13.3 3.13.4 β€” β€”
πŸ”΅ low CVE-2026-34518 aiohttp <= 3.13.3 3.13.4 β€” β€”
πŸ”΅ low CVE-2026-34517 aiohttp <= 3.13.3 3.13.4 β€” β€”
πŸ”΅ low CVE-2026-34519 aiohttp <= 3.13.3 3.13.4 β€” β€”
πŸ”΅ low CVE-2026-34520 aiohttp <= 3.13.3 3.13.4 β€” β€”
πŸ”΅ low CVE-2026-50269 aiohttp <= 3.13.5 3.14.0 β€” β€”
πŸ”΅ low CVE-2026-54279 aiohttp <= 3.14.0 3.14.1 β€” β€”
πŸ”΅ low CVE-2026-54280 aiohttp <= 3.14.0 3.14.1 β€” β€”
πŸ”΅ low CVE-2026-54275 aiohttp <= 3.14.0 3.14.1 β€” β€”
Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Dominant language
Jupyter Notebook
Stars
29
Forks
11
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up β€” it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from IBM/processmining

All issues in IBM/processmining

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.