Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch critical and high severity security vulnerabilities in dependencies #128

Open
wants to merge 38 commits into
base: main
Choose a base branch
from

Conversation

arpitjain099
Copy link

@arpitjain099 arpitjain099 commented Oct 20, 2024

Purpose

This PR fixes critical and high severity security vulnerabilities in dependencies which can also be imported in people cloning and using this repo - so it's important that these vulnerabilities are fixed on time.

You can find details about these changes here -
https://github.com/arpitjain099/openai/pulls?q=is%3Apr+is%3Aclosed+label%3Adependencies

Does this introduce a breaking change?

[ ] Yes
[X] No

Pull Request Type

Security vulnerability patch

[ ] Bugfix
[ ] Feature
[ ] Code style update (formatting, local variables)
[ ] Refactoring (no functional changes, no api changes)
[ ] Documentation content changes
[X] Other... Please describe: Fixing crit

How to Test

  • Get the code
git clone [repo-address]
cd [repo-name]
git checkout [branch-name]
npm install
  • Test the code

What to Check

Verify that the following are valid

  • ...

Other Information

dependabot bot and others added 30 commits October 20, 2024 03:14
Bumps the pip group with 1 update in the /End_to_end_Solutions/AOAISearchDemo/app directory: [azure-identity](https://github.com/Azure/azure-sdk-for-python).


Updates `azure-identity` from 1.13.0b3 to 1.16.1
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-python/blob/main/doc/esrp_release.md)
- [Commits](Azure/azure-sdk-for-python@azure-identity_1.13.0b3...azure-identity_1.16.1)

---
updated-dependencies:
- dependency-name: azure-identity
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the pip group with 1 update in the /End_to_end_Solutions/AOAISearchDemo/app directory: [langchain](https://github.com/langchain-ai/langchain).


Updates `langchain` from 0.0.139 to 0.2.10
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@v0.0.139...langchain==0.2.10)

---
updated-dependencies:
- dependency-name: langchain
  dependency-type: direct:production
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
…utions/AOAISearchDemo/app/pip-c2c2e90543

Bump azure-identity from 1.13.0b3 to 1.16.1 in /End_to_end_Solutions/AOAISearchDemo/app in the pip group across 1 directory
…utions/AOAISearchDemo/app/pip-99c25bc862

Bump langchain from 0.0.139 to 0.2.10 in /End_to_end_Solutions/AOAISearchDemo/app in the pip group across 1 directory
---
updated-dependencies:
- dependency-name: aiohttp
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [langchain](https://github.com/langchain-ai/langchain) from 0.0.329 to 0.2.10.
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@v0.0.329...langchain==0.2.10)

---
updated-dependencies:
- dependency-name: langchain
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.0.2 to 3.1.3.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.0.2...3.1.3)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…o_end_Solutions/AOAISearchDemo/app/frontend/dompurify-3.1.3

Bump dompurify from 3.0.2 to 3.1.3 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
…utions/AOAISearchDemo/notebooks/langchain-0.2.10

Bump langchain from 0.0.329 to 0.2.10 in /End_to_end_Solutions/AOAISearchDemo/notebooks
…utions/AOAIVirtualAssistant/src/notebooks/aiohttp-3.10.2

Bump aiohttp from 3.8.4 to 3.10.2 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [pillow](https://github.com/python-pillow/Pillow) from 10.2.0 to 10.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@10.2.0...10.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [idna](https://github.com/kjd/idna) from 3.4 to 3.7.
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.rst)
- [Commits](kjd/idna@v3.4...v3.7)

---
updated-dependencies:
- dependency-name: idna
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…utions/AOAIVirtualAssistant/src/notebooks/idna-3.7

Bump idna from 3.4 to 3.7 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
…utions/AOAIVirtualAssistant/src/notebooks/pillow-10.3.0

Bump pillow from 10.2.0 to 10.3.0 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) from 7.20.13 to 7.25.7.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.25.7/packages/babel-traverse)

---
updated-dependencies:
- dependency-name: "@babel/traverse"
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [flask](https://github.com/pallets/flask) from 2.2.2 to 2.2.5.
- [Release notes](https://github.com/pallets/flask/releases)
- [Changelog](https://github.com/pallets/flask/blob/main/CHANGES.rst)
- [Commits](pallets/flask@2.2.2...2.2.5)

---
updated-dependencies:
- dependency-name: flask
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fonttools](https://github.com/fonttools/fonttools) from 4.39.0 to 4.43.0.
- [Release notes](https://github.com/fonttools/fonttools/releases)
- [Changelog](https://github.com/fonttools/fonttools/blob/main/NEWS.rst)
- [Commits](fonttools/fonttools@4.39.0...4.43.0)

---
updated-dependencies:
- dependency-name: fonttools
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…utions/AOAISearchDemo/app/flask-2.2.5

Bump flask from 2.2.2 to 2.2.5 in /End_to_end_Solutions/AOAISearchDemo/app
…lutions/AOAIVirtualAssistant/src/notebooks/fonttools-4.43.0

Bump fonttools from 4.39.0 to 4.43.0 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [black](https://github.com/psf/black) from 23.1.0 to 24.3.0.
- [Release notes](https://github.com/psf/black/releases)
- [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)
- [Commits](psf/black@23.1.0...24.3.0)

---
updated-dependencies:
- dependency-name: black
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…o_end_Solutions/AOAISearchDemo/app/frontend/babel/traverse-7.25.7

Bump @babel/traverse from 7.20.13 to 7.25.7 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
…lutions/AOAIVirtualAssistant/src/notebooks/black-24.3.0

Bump black from 23.1.0 to 24.3.0 in /End_to_end_Solutions/AOAIVirtualAssistant/src/notebooks
Bumps [rollup](https://github.com/rollup/rollup) from 3.20.6 to 3.29.5.
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v3.20.6...v3.29.5)

---
updated-dependencies:
- dependency-name: rollup
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
arpitjain099 and others added 5 commits October 20, 2024 12:35
…to_end_Solutions/AOAISearchDemo/app/frontend/rollup-3.29.5

Bump rollup from 3.20.6 to 3.29.5 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 4.2.2 to 4.5.5.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v4.5.5/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v4.5.5/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [azure-identity](https://github.com/Azure/azure-sdk-for-python) from 1.12.0 to 1.16.1.
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Changelog](https://github.com/Azure/azure-sdk-for-python/blob/main/doc/esrp_release.md)
- [Commits](Azure/azure-sdk-for-python@azure-identity_1.12.0...azure-identity_1.16.1)

---
updated-dependencies:
- dependency-name: azure-identity
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…lutions/AOAISearchDemo/notebooks/azure-identity-1.16.1

Bump azure-identity from 1.12.0 to 1.16.1 in /End_to_end_Solutions/AOAISearchDemo/notebooks
…to_end_Solutions/AOAISearchDemo/app/frontend/vite-4.5.5

Bump vite from 4.2.2 to 4.5.5 in /End_to_end_Solutions/AOAISearchDemo/app/frontend
@arpitjain099
Copy link
Author

Please review @kristapratico @luisquintanilla @colombod

arpitjain099 and others added 3 commits October 20, 2024 12:54
…tion

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
…tion

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Fix code scanning alert no. 44: Information exposure through an exception
@arpitjain099
Copy link
Author

Hi @kristapratico @luisquintanilla @colombod
Please review this PR when you can. Thank you!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant