apple / apple/music-feed-examples

CVE-2024-35195 mitigation

Open
#2 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
30
Forks
6
PR merge metrics
No merged PRs in 30d

Description

Dear Apple support team,

I'm trying to migrate from the EPF to the new Apple Music Feed, but got a warning about a CVE. Is it safe?

`peter@Peters-MBP-2 python_example % python3 -m pip install -r requirements.txt`

```
WARNING: The candidate selected for download or install is a yanked version: 'requests' candidate (version 2.32.0 at https://files.pythonhosted.org/packages/24/e8/09e8d662a9675a4e4f5dd7a8e6127b463a091d2703ed931a64aa66d00065/requests-2.32.0-py3-none-any.whl (from https://pypi.org/simple/requests/) (requires-python:>=3.8))
Reason for being yanked: Yanked due to conflicts with CVE-2024-35195 mitigation

```

Also, please can a backup of the EPF be made available on [archive.org](archive.org) before it is removed? See case number 102547259945 from kiwiburkim@icloud.com.

Best regards,
peterburk

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with python_example/requirements.txt and reproduce the warning using the `python3 -m pip install -r requirements.txt` command shown in the issue. Determine whether this repository is expected to address the requests/CVE warning, and clarify how the separate EPF archive request relates to the project. Done criteria are not defined by the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.