apple / apple/music-feed-examples
CVE-2024-35195 mitigation
- Dominant language
- Java
- Stars
- 30
- Forks
- 6
- PR merge metrics
- No merged PRs in 30d
Description
Dear Apple support team,
I'm trying to migrate from the EPF to the new Apple Music Feed, but got a warning about a CVE. Is it safe?
`peter@Peters-MBP-2 python_example % python3 -m pip install -r requirements.txt`
```
WARNING: The candidate selected for download or install is a yanked version: 'requests' candidate (version 2.32.0 at https://files.pythonhosted.org/packages/24/e8/09e8d662a9675a4e4f5dd7a8e6127b463a091d2703ed931a64aa66d00065/requests-2.32.0-py3-none-any.whl (from https://pypi.org/simple/requests/) (requires-python:>=3.8))
Reason for being yanked: Yanked due to conflicts with CVE-2024-35195 mitigation
```
Also, please can a backup of the EPF be made available on [archive.org](archive.org) before it is removed? See case number 102547259945 from kiwiburkim@icloud.com.
Best regards,
peterburk
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with python_example/requirements.txt and reproduce the warning using the `python3 -m pip install -r requirements.txt` command shown in the issue. Determine whether this repository is expected to address the requests/CVE warning, and clarify how the separate EPF archive request relates to the project. Done criteria are not defined by the issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100