Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wazuh-QA Dependant-bot suggests to merge Cryptography bump PR from 3.3.2 to 41.0.6 #5273

Open
3 tasks
pro-akim opened this issue Apr 19, 2024 · 1 comment · May be fixed by #4730
Open
3 tasks

Wazuh-QA Dependant-bot suggests to merge Cryptography bump PR from 3.3.2 to 41.0.6 #5273

pro-akim opened this issue Apr 19, 2024 · 1 comment · May be fixed by #4730
Labels
level/task Task issue qa_known Issues that are already known by the QA team type/maintenance

Comments

@pro-akim
Copy link
Member

pro-akim commented Apr 19, 2024

Alert in Wazuh-QA Dependant-bot was found:

image

It seems that by merging the mentioned PR, cryptography vulnerabilities will disappear

image

  • Analyze the convenience of its implementation
  • Evaluate risks
  • merge if it is correct
@rauldpm
Copy link
Member

rauldpm commented Apr 22, 2024

The bot created the original PR on Nov 28, 2023, this issue has not been worked on in a long time, we need to work on it but we have other issues with higher priorities, I propose adding the issue to the qa_known label and address it in the future

@rauldpm rauldpm added the qa_known Issues that are already known by the QA team label Apr 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
level/task Task issue qa_known Issues that are already known by the QA team type/maintenance
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants