Numpy==1.21.3 Denial of Service (DoS) & NULL Pointer Dereference & Buffer Overflow
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 25/100
Research direction
Start by checking the package dependency metadata and confirming whether requirements.txt is intentionally absent, then compare the declared NumPy constraint with the three linked Snyk advisories. Done means determining whether databricks-sql-python brings in numpy==1.21.3 and documenting or making the dependency change needed to resolve the reported vulnerabilities.
Written by the indexing model from the issue text.
Description
Synk security scan is giving Denial of Service (DoS) & NULL Pointer Dereference & Buffer Overflow to numpy==1.21.3 version.
I couldn't locate requirements.txt file for databricks-sql-python package. Is the version >=1.21.3?
This package is identified as one that depends on this specific Numpy version.
- Dominant language
- Python
- Stars
- 233
- Forks
- 152
- Avg merge
- 21h 5m
- Merged PRs (30d)
- 10
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from databricks/databricks-sql-python
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100