Skip to content

[BUG] Need to support version urllib3 without vulnerability #172

@afandusibmcom

Description

@afandusibmcom

Description
detect-secrets 0.13.1+ibm.62.dss depends on urllib3<2.0.0 which has vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2025-50182 Medium 5.3 urllib3-1.26.20-py2.py3-none-any.whl Upgrade to version: https://github.com/urllib3/urllib3.git - 2.5.0 None
CVE-2025-50181 Medium 5.3 urllib3-1.26.20-py2.py3-none-any.whl Upgrade to version: https://github.com/urllib3/urllib3.git - 2.5.0 None

Impact
This makes my code using this module is non-compliant

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions