Skip to content

Fix Dependabot alert on python-dotenv for N2T and Resolver #1010

@jsjiang

Description

@jsjiang

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback #34

https://github.com/CDLUC3/N2T/security/dependabot/34

Upgrade python-dotenv to fix 1 Dependabot alert in requirements.txt
Upgrade python-dotenv to version 1.2.2 or later.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions