Skip to content

Maintenance: pyproject.toml and poetry.lock dependency versions appear at odds #5437

Closed
@availity-droo

Description

@availity-droo

Why is this needed?

In the process of developing and deploying a solution utilizing aws-lambda-powertools, we discovered our SCA scanner was noticing pydantic CVE-2024-3772 due to version 2.0.3 being installed when using conda. I noticed the poetry.lock file references 2.9.1 of pydantic, however, and was curious if that discrepancy was intentional.

I am aware the vulnerable method validate_email is not being called from the CVE, but it is always nicer to have a clean vulnerability scan and avoid creating waivers/mitigations for findings.

Which area does this relate to?

Other

Solution

Update the pyproject.toml dependency list to reflect those currently locked via poetry.

Acknowledgment

Metadata

Metadata

Labels

Type

No type

Projects

Status

Shipped

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions