Skip to content

Conversation

@luisfponce
Copy link
Owner

No description provided.

@luisfponce
Copy link
Owner Author

the PR met spectations.

snyk scan correctly:

Tested 41 dependencies for known issues, found 2 issues, 4 vulnerable paths.


Issues to fix by upgrading dependencies:

  Pin starlette@0.46.2 to starlette@0.49.1 to fix
  ✗ Allocation of Resources Without Limits or Throttling [Medium Severity][https://security.snyk.io/vuln/SNYK-PYTHON-STARLETTE-10874054] in starlette@0.46.2
    introduced by fastapi@0.115.14 > starlette@0.46.2 and 1 other path(s)
  ✗ Regular Expression Denial of Service (ReDoS) (new) [High Severity][https://security.snyk.io/vuln/SNYK-PYTHON-STARLETTE-13733964] in starlette@0.46.2
    introduced by fastapi@0.115.14 > starlette@0.46.2 and 1 other path(s)



Organization:      luisfponce
Package manager:   pip
Target file:       requirements.txt
Project name:      workspace
Open source:       no
Project path:      /github/workspace
Licenses:          enabled

Report generated and upload correctly:

Artifact download URL: https://github.com/luisfponce/web_api_knowledge/actions/runs/19117757173/artifacts/4480233844

@luisfponce luisfponce merged commit 3261458 into main Nov 5, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants