Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/requirements.txt
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
fastapi==0.6.4
fastapi==0.140.13

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ—„οΈ Data Integrity & Integration | 🟠 Major | ⚑ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu
fd -t f '^(setup\.py|requirements\.txt)$' .
rg -n 'open\(["'\'']requirements\.txt|REQUIREMENTS|fastapi==' .

Repository: salimfadhley/dockerized_python_playground

Length of output: 441


🏁 Script executed:

#!/bin/bash
set -eu
cat -n src/setup.py
printf '\nOther package metadata files:\n'
fd -t f '^(setup\.cfg|tox\.ini|pyproject\.toml|README\.md)$' .
rg -n 'distutils|setup\(|name\s*=|version\s*=|fastapi|requirements\.txt|requirements' .

Repository: salimfadhley/dockerized_python_playground

Length of output: 2179


Resolve requirements.txt relative to src/setup.py.

src/setup.py reads "requirements.txt" from the current working directory, but the pin is in src/requirements.txt. Running the package build from the repo root makes REQUIREMENTS empty and silently drops fastapi==0.140.13; load it with os.path.join(PROJECT_ROOT, "requirements.txt") and add coverage for the root package-build cwd.

🧰 Tools
πŸͺ› OSV Scanner (2.4.0)

[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2022-42992)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2023-137)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2023-161)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2023-165)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2024-4)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2026-2161)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2026-2162)


[CRITICAL] 1-1: gitpython 3.1.9: undefined

(PYSEC-2026-2163)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

(GHSA-2f96-g7mh-g2hx)


[CRITICAL] 1-1: gitpython 3.1.9: Untrusted search path under some conditions on Windows allows arbitrary code execution

(GHSA-2mqj-m65w-jghx)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

(GHSA-3rp5-jjmw-4wv2)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

(GHSA-6p8h-3wgx-97gf)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository

(GHSA-7545-fcxq-7j24)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

(GHSA-94p4-4cq8-9g67)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: command injection via unguarded Git options in Repo.archive(), git.ls_remote(), and arbitrary file overwrite via Repo.iter_commits() / Repo.blame()

(GHSA-956x-8gvw-wg5v)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython blind local file inclusion

(GHSA-cwvm-v4w8-q58c)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

(GHSA-fjr4-x663-mwxc)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython vulnerable to Remote Code Execution due to improper user input validation

(GHSA-hcpj-qp55-gfph)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath

(GHSA-mv93-w799-cj2w)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython vulnerable to remote code execution due to insufficient sanitization of input arguments

(GHSA-pr76-5cm5-w9cj)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

(GHSA-r9mr-m37c-5fr3)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

(GHSA-rwj8-pgh3-r573)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

(GHSA-v87r-6q3f-2j67)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython untrusted search path on Windows systems leading to arbitrary code execution

(GHSA-wfm5-v35h-vwf4)


[CRITICAL] 1-1: gitpython 3.1.9: GitPython: Unsafe option check validates multi_options before shlex.split transformation

(GHSA-x2qx-6953-8485)


[HIGH] 1-1: uvicorn 0.4.6: undefined

(PYSEC-2020-150)


[HIGH] 1-1: uvicorn 0.4.6: undefined

(PYSEC-2020-151)


[HIGH] 1-1: uvicorn 0.4.6: Log injection in uvicorn

(GHSA-33c7-2mpw-hg34)


[HIGH] 1-1: uvicorn 0.4.6: HTTP response splitting in uvicorn

(GHSA-f97h-2pfx-f59f)

πŸ€– Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/requirements.txt` at line 1, Update the requirements loading in
src/setup.py to resolve requirements.txt relative to PROJECT_ROOT rather than
the current working directory, preserving the fastapi pin during root-directory
builds. Add coverage for running the package build from the repository root and
verify that REQUIREMENTS includes fastapi==0.140.13.

gitpython
uvicorn==0.4.6