Skip to content

Conversation

@AlessandroPomponio
Copy link
Member

Context

These annotations seem to prevent mypy from running

@AlessandroPomponio AlessandroPomponio marked this pull request as draft January 7, 2026 14:14
auto-merge was automatically disabled January 7, 2026 14:14

Pull request was converted to draft

@DRL-NextGen
Copy link
Member

DRL-NextGen commented Jan 7, 2026

Checks Summary

Last run: 2026-01-08T13:12:28.157Z

Code Risk Analyzer vulnerability scan found 6 vulnerabilities:

Severity Identifier Package Details Fix
🔷 Medium CVE-2025-50182 urllib3
urllib3 does not control redirects in browsers and Node.jsGHSA-48p4-8xcf-vxj5

urllib3:2.3.0->kubernetes:34.1.0
2.5.0
🔷 Medium CVE-2025-50181 urllib3
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiationGHSA-pq67-6m6q-mj2v

urllib3:2.3.0->kubernetes:34.1.0
2.5.0
◻ Unknown CVE-2025-53000 nbconvert
nbconvert has an uncontrolled search path that leads to unauthorized code execution on WindowsGHSA-xm59-rqc7-hhvf

nbconvert:7.16.6->ado-core:1.3.2
>7.16.6
◻ Unknown CVE-2025-66471 urllib3
urllib3 streaming API improperly handles highly compressed dataGHSA-2xpw-w6gg-jr37

urllib3:2.3.0->kubernetes:34.1.0
2.6.0
◻ Unknown CVE-2025-66418 urllib3
urllib3 allows an unbounded number of links in the decompression chainGHSA-gm62-xv2j-4w53

urllib3:2.3.0->kubernetes:34.1.0
2.6.0
◻ Unknown CVE-2026-21441 urllib3
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)GHSA-38jv-5279-wg99

urllib3:2.3.0->kubernetes:34.1.0
2.6.3

Mend Unified Agent vulnerability scan found 1 vulnerabilities:

Severity Identifier Package Details Fix
🔺 High CVE-2025-53000 nbconvert-7.16.6-py3-none-any.whl
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja...The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and including 7.16.6 on Windows have a vulnerability in which converting a notebook containing SVG output to a PDF results in unauthorized code execution. Specifically, a third party can create a "inkscape.bat" file that defines a Windows batch script, capable of arbitrary code execution. When a user runs "jupyter nbconvert --to pdf" on a notebook containing SVG output to a PDF on a Windows platform from this directory, the "inkscape.bat" file is run unexpectedly. As of time of publication, no known patches exist.
Not Available

@AlessandroPomponio AlessandroPomponio force-pushed the ap_20260107_update_annotations branch from 6531ead to d3b800f Compare January 8, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants