diff --git a/techstack.md b/techstack.md index db4b725..db4117e 100644 --- a/techstack.md +++ b/techstack.md @@ -7,6 +7,7 @@ kclhi/jupyter is built on the following main stack: - [JavaScript](https://developer.mozilla.org/en-US/docs/Web/JavaScript) – Languages - [Python](https://www.python.org) – Languages - [TypeScript](http://www.typescriptlang.org) – Languages +- [.NET](http://www.microsoft.com/net/) – Frameworks (Full Stack) - [MySQL](http://www.mysql.com) – Databases - [Neo4j](http://www.neo4j.com/) – Graph Databases - [RabbitMQ](http://www.rabbitmq.com/) – Message Queue @@ -27,6 +28,7 @@ kclhi/jupyter is built on the following main stack: - JavaScript [JavaScript](https://developer.mozilla.org/en-US/docs/Web/JavaScript) – Languages - Python [Python](https://www.python.org) – Languages - TypeScript [TypeScript](http://www.typescriptlang.org) – Languages +- .NET [.NET](http://www.microsoft.com/net/) – Frameworks (Full Stack) - MySQL [MySQL](http://www.mysql.com) – Databases - Neo4j [Neo4j](http://www.neo4j.com/) – Graph Databases - RabbitMQ [RabbitMQ](http://www.rabbitmq.com/) – Message Queue @@ -44,7 +46,7 @@ Full tech stack [here](/techstack.md) # Tech Stack File ![](https://img.stackshare.io/repo.svg "repo") [kclhi/jupyter](https://github.com/kclhi/jupyter)![](https://img.stackshare.io/public_badge.svg "public")

-|34
Tools used|02/11/24
Report generated| +|36
Tools used|06/09/24
Report generated| |------|------| @@ -85,6 +87,19 @@ Full tech stack [here](/techstack.md) +## Frameworks (1) + + + + +
+ .NET +
+ .NET +
+ +
+ ## Data (3)
@@ -114,7 +129,7 @@ Full tech stack [here](/techstack.md)
-## DevOps (6) +## DevOps (7) + +
Docker @@ -148,6 +163,14 @@ Full tech stack [here](/techstack.md) + NuGet +
+ NuGet +
+ +
PyPI
@@ -197,21 +220,21 @@ Full tech stack [here](/techstack.md) |:------|:------|:------|:------|:------|:------| |[GitPython](https://pypi.org/project/GitPython)|v3.1.3|06/12/20|Martin Chapman |BSD-3-Clause|[CVE-2023-40267](https://github.com/advisories/GHSA-pr76-5cm5-w9cj) (Critical)
[CVE-2024-22190](https://github.com/advisories/GHSA-2mqj-m65w-jghx) (High)
[CVE-2022-24439](https://github.com/advisories/GHSA-hcpj-qp55-gfph) (High)
[CVE-2023-41040](https://github.com/advisories/GHSA-cwvm-v4w8-q58c) (Moderate)| |[certifi](https://pypi.org/project/certifi)|v2020.4.5|06/11/20|Martin Chapman |MPL-2.0|[CVE-2023-37920](https://github.com/advisories/GHSA-xqr8-7jwr-rhp7) (High)
[CVE-2022-23491](https://github.com/advisories/GHSA-43fp-rhv2-5gv8) (Moderate)| +|[starlette](https://pypi.org/project/starlette)|v0.13.4|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2024-24762](https://github.com/advisories/GHSA-2jv5-9r88-3w3p) (High)
[](https://github.com/advisories/GHSA-93gm-qmq6-w238) (High)
[CVE-2023-30798](https://github.com/advisories/GHSA-3qj8-93xh-pwh2) (High)
[](https://github.com/advisories/GHSA-74m5-2c7w-9w3x) (Moderate)| +|[urllib3](https://pypi.org/project/urllib3)|v1.25.9|06/11/20|Martin Chapman |MIT|[CVE-2021-33503](https://github.com/advisories/GHSA-q2q7-5pp4-w6pg) (High)
[CVE-2023-45803](https://github.com/advisories/GHSA-g4mx-q9vg-27p4) (Moderate)
[CVE-2023-43804](https://github.com/advisories/GHSA-v845-jxx5-vc9f) (Moderate)| +|[idna](https://pypi.org/project/idna)|v2.9|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2024-3651](https://github.com/advisories/GHSA-jjg7-2v4v-x38h) (Moderate)| +|[requests](https://pypi.org/project/requests)|v2.23.0|06/11/20|Martin Chapman |Apache-2.0|[CVE-2024-35195](https://github.com/advisories/GHSA-9wx4-h78v-vm56) (Moderate)
[CVE-2023-32681](https://github.com/advisories/GHSA-j8r2-6x86-q33q) (Moderate)| +|[websockets](https://pypi.org/project/websockets)|v8.1|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2021-33880](https://github.com/advisories/GHSA-8ch4-58qp-g3mp) (Moderate)| |[chardet](https://pypi.org/project/chardet)|v3.0.4|06/11/20|Martin Chapman |LGPL-2.1|N/A| |[click](https://pypi.org/project/click)|v7.1.2|06/11/20|Martin Chapman |BSD-3-Clause|N/A| |[gitdb](https://pypi.org/project/gitdb)|v4.0.5|06/12/20|Martin Chapman |BSD-3-Clause|N/A| |[h11](https://pypi.org/project/h11)|v0.9.0|06/11/20|Martin Chapman |MIT|N/A| |[httptools](https://pypi.org/project/httptools)|v0.1.1|06/11/20|Martin Chapman |MIT|N/A| -|[idna](https://pypi.org/project/idna)|v2.9|06/11/20|Martin Chapman |BSD-3-Clause|N/A| |[pika](https://pypi.org/project/pika)|v1.1.0|06/12/20|Martin Chapman |BSD-3-Clause|N/A| |[pony](https://pypi.org/project/pony)|v0.7.14|01/28/21|Martin Chapman |Apache-2.0|N/A| |[python-dotenv](https://pypi.org/project/python-dotenv)|v0.13.0|06/12/20|Martin Chapman |BSD-3-Clause|N/A| -|[requests](https://pypi.org/project/requests)|v2.23.0|06/11/20|Martin Chapman |Apache-2.0|[CVE-2023-32681](https://github.com/advisories/GHSA-j8r2-6x86-q33q) (Moderate)| -|[starlette](https://pypi.org/project/starlette)|v0.13.4|06/11/20|Martin Chapman |BSD-3-Clause|[](https://github.com/advisories/GHSA-93gm-qmq6-w238) (High)
[CVE-2023-30798](https://github.com/advisories/GHSA-3qj8-93xh-pwh2) (High)
[](https://github.com/advisories/GHSA-74m5-2c7w-9w3x) (Moderate)| -|[urllib3](https://pypi.org/project/urllib3)|v1.25.9|06/11/20|Martin Chapman |MIT|[CVE-2021-33503](https://github.com/advisories/GHSA-q2q7-5pp4-w6pg) (High)
[CVE-2023-45803](https://github.com/advisories/GHSA-g4mx-q9vg-27p4) (Moderate)
[CVE-2023-43804](https://github.com/advisories/GHSA-v845-jxx5-vc9f) (Moderate)| |[uvicorn](https://pypi.org/project/uvicorn)|v0.11.7|04/23/21|Martin Chapman |BSD-3-Clause|N/A| |[uvloop](https://pypi.org/project/uvloop)|v0.14.0|06/11/20|Martin Chapman |Apache-2.0|N/A| -|[websockets](https://pypi.org/project/websockets)|v8.1|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2021-33880](https://github.com/advisories/GHSA-8ch4-58qp-g3mp) (Moderate)| ## npm (2) diff --git a/techstack.yml b/techstack.yml index 10cf14a..40926ab 100644 --- a/techstack.yml +++ b/techstack.yml @@ -1,12 +1,12 @@ repo_name: kclhi/jupyter -report_id: f853adab0c8ee44a7b7258d780f82ff9 +report_id: 835a9742551d6596e86a25721183bbd8 version: 0.1 repo_type: Public -timestamp: '2024-02-11T18:36:08+00:00' +timestamp: '2024-06-09T11:11:08+00:00' requested_by: martinchapman provider: github branch: master -detected_tools_count: 34 +detected_tools_count: 36 tools: - name: Java description: A concurrent, class-based, object-oriented, language specifically designed @@ -54,6 +54,20 @@ tools: image_url: https://img.stackshare.io/service/1612/bynNY5dJ.jpg detection_source_url: https://github.com/kclhi/jupyter detection_source: Repo Metadata +- name: ".NET" + description: A free, cross-platform, open source developer platform for building + many different types of applications + website_url: http://www.microsoft.com/net/ + license: MIT + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Frameworks (Full Stack) + image_url: https://img.stackshare.io/service/1014/IoPy1dce_400x400.png + detection_source_url: https://github.com/kclhi/jupyter/blob/master/docker-compose.yml + detection_source: docker-compose.yml + last_updated_by: Martin Chapman + last_updated_on: 2020-05-18 15:37:06.000000000 Z - name: MySQL description: The world's most popular open source database website_url: http://www.mysql.com @@ -139,6 +153,18 @@ tools: detection_source: proxy/nginx.conf last_updated_by: Martin Chapman last_updated_on: 2020-05-18 17:39:45.000000000 Z +- name: NuGet + description: The package manager for .NET + website_url: https://www.nuget.org/ + open_source: false + hosted_saas: false + category: Build, Test, Deploy + sub_category: Package Managers + image_url: https://img.stackshare.io/service/2637/6I3oEOP4_400x400.jpg + detection_source_url: https://github.com/kclhi/jupyter/blob/master/docker-compose.yml + detection_source: docker-compose.yml + last_updated_by: Martin Chapman + last_updated_on: 2020-05-18 15:37:06.000000000 Z - name: PyPI description: A repository of software for the Python programming language website_url: https://pypi.org/ @@ -254,6 +280,152 @@ tools: detected_date: Dec 8 severity: moderate first_patched: 2022.12.07 +- name: starlette + description: The little ASGI library that shines + package_url: https://pypi.org/project/starlette + version: 0.13.4 + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/20295/default_640b00772a7025571fa2ac02de971e76f9662aa9.png + detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt + detection_source: provenance/requirements.txt + last_updated_by: Martin Chapman + last_updated_on: 2020-06-11 09:37:53.000000000 Z + vulnerabilities: + - name: python-multipart vulnerable to Content-Type Header ReDoS + cve_id: CVE-2024-24762 + cve_url: https://github.com/advisories/GHSA-2jv5-9r88-3w3p + detected_date: Feb 17 + severity: high + first_patched: 0.36.2 + - name: 'Duplicate Advisory: Starlette Content-Type Header ReDoS' + cve_id: + cve_url: https://github.com/advisories/GHSA-93gm-qmq6-w238 + detected_date: Feb 6 + severity: high + first_patched: 0.36.2 + - name: Starlette allows an unauthenticated and remote attacker to specify any number + of form fields or files + cve_id: CVE-2023-30798 + cve_url: https://github.com/advisories/GHSA-3qj8-93xh-pwh2 + detected_date: Apr 22 + severity: high + first_patched: 0.25.0 + - name: MultipartParser denial of service with too many fields or files + cve_id: + cve_url: https://github.com/advisories/GHSA-74m5-2c7w-9w3x + detected_date: Feb 15 + severity: moderate + first_patched: 0.25.0 +- name: urllib3 + description: HTTP library with thread-safe connection pooling + package_url: https://pypi.org/project/urllib3 + version: 1.25.9 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19842/default_4604ff5dcb7f4d9c7b3833591c2142493951b19c.png + detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt + detection_source: provenance/requirements.txt + last_updated_by: Martin Chapman + last_updated_on: 2020-06-11 09:37:53.000000000 Z + vulnerabilities: + - name: Catastrophic backtracking in URL authority parser when passed URL containing + many @ characters + cve_id: CVE-2021-33503 + cve_url: https://github.com/advisories/GHSA-q2q7-5pp4-w6pg + detected_date: Aug 22 + severity: high + first_patched: 1.26.5 + - name: urllib3's request body not stripped after redirect from 303 status changes + request method to GET + cve_id: CVE-2023-45803 + cve_url: https://github.com/advisories/GHSA-g4mx-q9vg-27p4 + detected_date: Oct 18 + severity: moderate + first_patched: 1.26.18 + - name: "`Cookie` HTTP header isn't stripped on cross-origin redirects" + cve_id: CVE-2023-43804 + cve_url: https://github.com/advisories/GHSA-v845-jxx5-vc9f + detected_date: Oct 3 + severity: moderate + first_patched: 1.26.17 +- name: idna + description: Internationalized Domain Names in Applications + package_url: https://pypi.org/project/idna + version: '2.9' + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19863/default_f24e00e4cb7620e436f9d06e0305070e1335922a.png + detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt + detection_source: provenance/requirements.txt + last_updated_by: Martin Chapman + last_updated_on: 2020-06-11 09:37:53.000000000 Z + vulnerabilities: + - name: Internationalized Domain Names in Applications (IDNA) vulnerable to denial + of service from specially crafted inputs to idna.encode + cve_id: CVE-2024-3651 + cve_url: https://github.com/advisories/GHSA-jjg7-2v4v-x38h + detected_date: Apr 12 + severity: moderate + first_patched: '3.7' +- name: requests + description: Python HTTP for Humans + package_url: https://pypi.org/project/requests + version: 2.23.0 + license: Apache-2.0 + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19826/default_d7c684bf2673f008a9f02ac93901229297a22d7e.png + detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt + detection_source: provenance/requirements.txt + last_updated_by: Martin Chapman + last_updated_on: 2020-06-11 09:37:53.000000000 Z + vulnerabilities: + - name: Requests `Session` object does not verify requests after making first request + with verify=False + cve_id: CVE-2024-35195 + cve_url: https://github.com/advisories/GHSA-9wx4-h78v-vm56 + detected_date: May 21 + severity: moderate + first_patched: 2.32.0 + - name: Unintended leak of Proxy-Authorization header in requests + cve_id: CVE-2023-32681 + cve_url: https://github.com/advisories/GHSA-j8r2-6x86-q33q + detected_date: May 23 + severity: moderate + first_patched: 2.31.0 +- name: websockets + description: An implementation of the WebSocket Protocol + package_url: https://pypi.org/project/websockets + version: '8.1' + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19951/default_fbe690a687f1af7dc36ac3d526708be3294c4cc9.png + detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt + detection_source: provenance/requirements.txt + last_updated_by: Martin Chapman + last_updated_on: 2020-06-11 09:37:53.000000000 Z + vulnerabilities: + - name: Observable Timing Discrepancy in aaugustin websockets library + cve_id: CVE-2021-33880 + cve_url: https://github.com/advisories/GHSA-8ch4-58qp-g3mp + detected_date: Aug 22 + severity: moderate + first_patched: '9.1' - name: chardet description: Universal encoding detector for Python 2 and 3 package_url: https://pypi.org/project/chardet @@ -324,20 +496,6 @@ tools: detection_source: provenance/requirements.txt last_updated_by: Martin Chapman last_updated_on: 2020-06-11 09:37:53.000000000 Z -- name: idna - description: Internationalized Domain Names in Applications - package_url: https://pypi.org/project/idna - version: '2.9' - license: BSD-3-Clause - open_source: true - hosted_saas: false - category: Libraries - sub_category: PyPI Packages - image_url: https://img.stackshare.io/package/19863/default_f24e00e4cb7620e436f9d06e0305070e1335922a.png - detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt - detection_source: provenance/requirements.txt - last_updated_by: Martin Chapman - last_updated_on: 2020-06-11 09:37:53.000000000 Z - name: pika description: Pika Python AMQP Client Library package_url: https://pypi.org/project/pika @@ -380,96 +538,6 @@ tools: detection_source: provenance/requirements.txt last_updated_by: Martin Chapman last_updated_on: 2020-06-12 16:40:07.000000000 Z -- name: requests - description: Python HTTP for Humans - package_url: https://pypi.org/project/requests - version: 2.23.0 - license: Apache-2.0 - open_source: true - hosted_saas: false - category: Libraries - sub_category: PyPI Packages - image_url: https://img.stackshare.io/package/19826/default_d7c684bf2673f008a9f02ac93901229297a22d7e.png - detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt - detection_source: provenance/requirements.txt - last_updated_by: Martin Chapman - last_updated_on: 2020-06-11 09:37:53.000000000 Z - vulnerabilities: - - name: Unintended leak of Proxy-Authorization header in requests - cve_id: CVE-2023-32681 - cve_url: https://github.com/advisories/GHSA-j8r2-6x86-q33q - detected_date: May 23 - severity: moderate - first_patched: 2.31.0 -- name: starlette - description: The little ASGI library that shines - package_url: https://pypi.org/project/starlette - version: 0.13.4 - license: BSD-3-Clause - open_source: true - hosted_saas: false - category: Libraries - sub_category: PyPI Packages - image_url: https://img.stackshare.io/package/20295/default_640b00772a7025571fa2ac02de971e76f9662aa9.png - detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt - detection_source: provenance/requirements.txt - last_updated_by: Martin Chapman - last_updated_on: 2020-06-11 09:37:53.000000000 Z - vulnerabilities: - - name: Starlette Content-Type Header ReDoS - cve_id: - cve_url: https://github.com/advisories/GHSA-93gm-qmq6-w238 - detected_date: Feb 6 - severity: high - first_patched: 0.36.2 - - name: Starlette allows an unauthenticated and remote attacker to specify any number - of form fields or files - cve_id: CVE-2023-30798 - cve_url: https://github.com/advisories/GHSA-3qj8-93xh-pwh2 - detected_date: Apr 22 - severity: high - first_patched: 0.25.0 - - name: MultipartParser denial of service with too many fields or files - cve_id: - cve_url: https://github.com/advisories/GHSA-74m5-2c7w-9w3x - detected_date: Feb 15 - severity: moderate - first_patched: 0.25.0 -- name: urllib3 - description: HTTP library with thread-safe connection pooling - package_url: https://pypi.org/project/urllib3 - version: 1.25.9 - license: MIT - open_source: true - hosted_saas: false - category: Libraries - sub_category: PyPI Packages - image_url: https://img.stackshare.io/package/19842/default_4604ff5dcb7f4d9c7b3833591c2142493951b19c.png - detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt - detection_source: provenance/requirements.txt - last_updated_by: Martin Chapman - last_updated_on: 2020-06-11 09:37:53.000000000 Z - vulnerabilities: - - name: Catastrophic backtracking in URL authority parser when passed URL containing - many @ characters - cve_id: CVE-2021-33503 - cve_url: https://github.com/advisories/GHSA-q2q7-5pp4-w6pg - detected_date: Aug 22 - severity: high - first_patched: 1.26.5 - - name: urllib3's request body not stripped after redirect from 303 status changes - request method to GET - cve_id: CVE-2023-45803 - cve_url: https://github.com/advisories/GHSA-g4mx-q9vg-27p4 - detected_date: Oct 18 - severity: moderate - first_patched: 1.26.18 - - name: "`Cookie` HTTP header isn't stripped on cross-origin redirects" - cve_id: CVE-2023-43804 - cve_url: https://github.com/advisories/GHSA-v845-jxx5-vc9f - detected_date: Oct 3 - severity: moderate - first_patched: 1.26.17 - name: uvicorn description: The lightning-fast ASGI server package_url: https://pypi.org/project/uvicorn @@ -498,27 +566,6 @@ tools: detection_source: provenance/requirements.txt last_updated_by: Martin Chapman last_updated_on: 2020-06-11 09:37:53.000000000 Z -- name: websockets - description: An implementation of the WebSocket Protocol - package_url: https://pypi.org/project/websockets - version: '8.1' - license: BSD-3-Clause - open_source: true - hosted_saas: false - category: Libraries - sub_category: PyPI Packages - image_url: https://img.stackshare.io/package/19951/default_fbe690a687f1af7dc36ac3d526708be3294c4cc9.png - detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt - detection_source: provenance/requirements.txt - last_updated_by: Martin Chapman - last_updated_on: 2020-06-11 09:37:53.000000000 Z - vulnerabilities: - - name: Observable Timing Discrepancy in aaugustin websockets library - cve_id: CVE-2021-33880 - cve_url: https://github.com/advisories/GHSA-8ch4-58qp-g3mp - detected_date: Aug 22 - severity: moderate - first_patched: '9.1' - name: "@jupyterlab/application" description: JupyterLab - Application package_url: https://www.npmjs.com/@jupyterlab/application