@@ -148,6 +163,14 @@ Full tech stack [here](/techstack.md)
|
+
+
+
+ NuGet
+
+
+ |
+
@@ -197,21 +220,21 @@ Full tech stack [here](/techstack.md)
|:------|:------|:------|:------|:------|:------|
|[GitPython](https://pypi.org/project/GitPython)|v3.1.3|06/12/20|Martin Chapman |BSD-3-Clause|[CVE-2023-40267](https://github.com/advisories/GHSA-pr76-5cm5-w9cj) (Critical) [CVE-2024-22190](https://github.com/advisories/GHSA-2mqj-m65w-jghx) (High) [CVE-2022-24439](https://github.com/advisories/GHSA-hcpj-qp55-gfph) (High) [CVE-2023-41040](https://github.com/advisories/GHSA-cwvm-v4w8-q58c) (Moderate)|
|[certifi](https://pypi.org/project/certifi)|v2020.4.5|06/11/20|Martin Chapman |MPL-2.0|[CVE-2023-37920](https://github.com/advisories/GHSA-xqr8-7jwr-rhp7) (High) [CVE-2022-23491](https://github.com/advisories/GHSA-43fp-rhv2-5gv8) (Moderate)|
+|[starlette](https://pypi.org/project/starlette)|v0.13.4|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2024-24762](https://github.com/advisories/GHSA-2jv5-9r88-3w3p) (High) [](https://github.com/advisories/GHSA-93gm-qmq6-w238) (High) [CVE-2023-30798](https://github.com/advisories/GHSA-3qj8-93xh-pwh2) (High) [](https://github.com/advisories/GHSA-74m5-2c7w-9w3x) (Moderate)|
+|[urllib3](https://pypi.org/project/urllib3)|v1.25.9|06/11/20|Martin Chapman |MIT|[CVE-2021-33503](https://github.com/advisories/GHSA-q2q7-5pp4-w6pg) (High) [CVE-2023-45803](https://github.com/advisories/GHSA-g4mx-q9vg-27p4) (Moderate) [CVE-2023-43804](https://github.com/advisories/GHSA-v845-jxx5-vc9f) (Moderate)|
+|[idna](https://pypi.org/project/idna)|v2.9|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2024-3651](https://github.com/advisories/GHSA-jjg7-2v4v-x38h) (Moderate)|
+|[requests](https://pypi.org/project/requests)|v2.23.0|06/11/20|Martin Chapman |Apache-2.0|[CVE-2024-35195](https://github.com/advisories/GHSA-9wx4-h78v-vm56) (Moderate) [CVE-2023-32681](https://github.com/advisories/GHSA-j8r2-6x86-q33q) (Moderate)|
+|[websockets](https://pypi.org/project/websockets)|v8.1|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2021-33880](https://github.com/advisories/GHSA-8ch4-58qp-g3mp) (Moderate)|
|[chardet](https://pypi.org/project/chardet)|v3.0.4|06/11/20|Martin Chapman |LGPL-2.1|N/A|
|[click](https://pypi.org/project/click)|v7.1.2|06/11/20|Martin Chapman |BSD-3-Clause|N/A|
|[gitdb](https://pypi.org/project/gitdb)|v4.0.5|06/12/20|Martin Chapman |BSD-3-Clause|N/A|
|[h11](https://pypi.org/project/h11)|v0.9.0|06/11/20|Martin Chapman |MIT|N/A|
|[httptools](https://pypi.org/project/httptools)|v0.1.1|06/11/20|Martin Chapman |MIT|N/A|
-|[idna](https://pypi.org/project/idna)|v2.9|06/11/20|Martin Chapman |BSD-3-Clause|N/A|
|[pika](https://pypi.org/project/pika)|v1.1.0|06/12/20|Martin Chapman |BSD-3-Clause|N/A|
|[pony](https://pypi.org/project/pony)|v0.7.14|01/28/21|Martin Chapman |Apache-2.0|N/A|
|[python-dotenv](https://pypi.org/project/python-dotenv)|v0.13.0|06/12/20|Martin Chapman |BSD-3-Clause|N/A|
-|[requests](https://pypi.org/project/requests)|v2.23.0|06/11/20|Martin Chapman |Apache-2.0|[CVE-2023-32681](https://github.com/advisories/GHSA-j8r2-6x86-q33q) (Moderate)|
-|[starlette](https://pypi.org/project/starlette)|v0.13.4|06/11/20|Martin Chapman |BSD-3-Clause|[](https://github.com/advisories/GHSA-93gm-qmq6-w238) (High) [CVE-2023-30798](https://github.com/advisories/GHSA-3qj8-93xh-pwh2) (High) [](https://github.com/advisories/GHSA-74m5-2c7w-9w3x) (Moderate)|
-|[urllib3](https://pypi.org/project/urllib3)|v1.25.9|06/11/20|Martin Chapman |MIT|[CVE-2021-33503](https://github.com/advisories/GHSA-q2q7-5pp4-w6pg) (High) [CVE-2023-45803](https://github.com/advisories/GHSA-g4mx-q9vg-27p4) (Moderate) [CVE-2023-43804](https://github.com/advisories/GHSA-v845-jxx5-vc9f) (Moderate)|
|[uvicorn](https://pypi.org/project/uvicorn)|v0.11.7|04/23/21|Martin Chapman |BSD-3-Clause|N/A|
|[uvloop](https://pypi.org/project/uvloop)|v0.14.0|06/11/20|Martin Chapman |Apache-2.0|N/A|
-|[websockets](https://pypi.org/project/websockets)|v8.1|06/11/20|Martin Chapman |BSD-3-Clause|[CVE-2021-33880](https://github.com/advisories/GHSA-8ch4-58qp-g3mp) (Moderate)|
## npm (2)
diff --git a/techstack.yml b/techstack.yml
index 10cf14a..40926ab 100644
--- a/techstack.yml
+++ b/techstack.yml
@@ -1,12 +1,12 @@
repo_name: kclhi/jupyter
-report_id: f853adab0c8ee44a7b7258d780f82ff9
+report_id: 835a9742551d6596e86a25721183bbd8
version: 0.1
repo_type: Public
-timestamp: '2024-02-11T18:36:08+00:00'
+timestamp: '2024-06-09T11:11:08+00:00'
requested_by: martinchapman
provider: github
branch: master
-detected_tools_count: 34
+detected_tools_count: 36
tools:
- name: Java
description: A concurrent, class-based, object-oriented, language specifically designed
@@ -54,6 +54,20 @@ tools:
image_url: https://img.stackshare.io/service/1612/bynNY5dJ.jpg
detection_source_url: https://github.com/kclhi/jupyter
detection_source: Repo Metadata
+- name: ".NET"
+ description: A free, cross-platform, open source developer platform for building
+ many different types of applications
+ website_url: http://www.microsoft.com/net/
+ license: MIT
+ open_source: true
+ hosted_saas: false
+ category: Languages & Frameworks
+ sub_category: Frameworks (Full Stack)
+ image_url: https://img.stackshare.io/service/1014/IoPy1dce_400x400.png
+ detection_source_url: https://github.com/kclhi/jupyter/blob/master/docker-compose.yml
+ detection_source: docker-compose.yml
+ last_updated_by: Martin Chapman
+ last_updated_on: 2020-05-18 15:37:06.000000000 Z
- name: MySQL
description: The world's most popular open source database
website_url: http://www.mysql.com
@@ -139,6 +153,18 @@ tools:
detection_source: proxy/nginx.conf
last_updated_by: Martin Chapman
last_updated_on: 2020-05-18 17:39:45.000000000 Z
+- name: NuGet
+ description: The package manager for .NET
+ website_url: https://www.nuget.org/
+ open_source: false
+ hosted_saas: false
+ category: Build, Test, Deploy
+ sub_category: Package Managers
+ image_url: https://img.stackshare.io/service/2637/6I3oEOP4_400x400.jpg
+ detection_source_url: https://github.com/kclhi/jupyter/blob/master/docker-compose.yml
+ detection_source: docker-compose.yml
+ last_updated_by: Martin Chapman
+ last_updated_on: 2020-05-18 15:37:06.000000000 Z
- name: PyPI
description: A repository of software for the Python programming language
website_url: https://pypi.org/
@@ -254,6 +280,152 @@ tools:
detected_date: Dec 8
severity: moderate
first_patched: 2022.12.07
+- name: starlette
+ description: The little ASGI library that shines
+ package_url: https://pypi.org/project/starlette
+ version: 0.13.4
+ license: BSD-3-Clause
+ open_source: true
+ hosted_saas: false
+ category: Libraries
+ sub_category: PyPI Packages
+ image_url: https://img.stackshare.io/package/20295/default_640b00772a7025571fa2ac02de971e76f9662aa9.png
+ detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
+ detection_source: provenance/requirements.txt
+ last_updated_by: Martin Chapman
+ last_updated_on: 2020-06-11 09:37:53.000000000 Z
+ vulnerabilities:
+ - name: python-multipart vulnerable to Content-Type Header ReDoS
+ cve_id: CVE-2024-24762
+ cve_url: https://github.com/advisories/GHSA-2jv5-9r88-3w3p
+ detected_date: Feb 17
+ severity: high
+ first_patched: 0.36.2
+ - name: 'Duplicate Advisory: Starlette Content-Type Header ReDoS'
+ cve_id:
+ cve_url: https://github.com/advisories/GHSA-93gm-qmq6-w238
+ detected_date: Feb 6
+ severity: high
+ first_patched: 0.36.2
+ - name: Starlette allows an unauthenticated and remote attacker to specify any number
+ of form fields or files
+ cve_id: CVE-2023-30798
+ cve_url: https://github.com/advisories/GHSA-3qj8-93xh-pwh2
+ detected_date: Apr 22
+ severity: high
+ first_patched: 0.25.0
+ - name: MultipartParser denial of service with too many fields or files
+ cve_id:
+ cve_url: https://github.com/advisories/GHSA-74m5-2c7w-9w3x
+ detected_date: Feb 15
+ severity: moderate
+ first_patched: 0.25.0
+- name: urllib3
+ description: HTTP library with thread-safe connection pooling
+ package_url: https://pypi.org/project/urllib3
+ version: 1.25.9
+ license: MIT
+ open_source: true
+ hosted_saas: false
+ category: Libraries
+ sub_category: PyPI Packages
+ image_url: https://img.stackshare.io/package/19842/default_4604ff5dcb7f4d9c7b3833591c2142493951b19c.png
+ detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
+ detection_source: provenance/requirements.txt
+ last_updated_by: Martin Chapman
+ last_updated_on: 2020-06-11 09:37:53.000000000 Z
+ vulnerabilities:
+ - name: Catastrophic backtracking in URL authority parser when passed URL containing
+ many @ characters
+ cve_id: CVE-2021-33503
+ cve_url: https://github.com/advisories/GHSA-q2q7-5pp4-w6pg
+ detected_date: Aug 22
+ severity: high
+ first_patched: 1.26.5
+ - name: urllib3's request body not stripped after redirect from 303 status changes
+ request method to GET
+ cve_id: CVE-2023-45803
+ cve_url: https://github.com/advisories/GHSA-g4mx-q9vg-27p4
+ detected_date: Oct 18
+ severity: moderate
+ first_patched: 1.26.18
+ - name: "`Cookie` HTTP header isn't stripped on cross-origin redirects"
+ cve_id: CVE-2023-43804
+ cve_url: https://github.com/advisories/GHSA-v845-jxx5-vc9f
+ detected_date: Oct 3
+ severity: moderate
+ first_patched: 1.26.17
+- name: idna
+ description: Internationalized Domain Names in Applications
+ package_url: https://pypi.org/project/idna
+ version: '2.9'
+ license: BSD-3-Clause
+ open_source: true
+ hosted_saas: false
+ category: Libraries
+ sub_category: PyPI Packages
+ image_url: https://img.stackshare.io/package/19863/default_f24e00e4cb7620e436f9d06e0305070e1335922a.png
+ detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
+ detection_source: provenance/requirements.txt
+ last_updated_by: Martin Chapman
+ last_updated_on: 2020-06-11 09:37:53.000000000 Z
+ vulnerabilities:
+ - name: Internationalized Domain Names in Applications (IDNA) vulnerable to denial
+ of service from specially crafted inputs to idna.encode
+ cve_id: CVE-2024-3651
+ cve_url: https://github.com/advisories/GHSA-jjg7-2v4v-x38h
+ detected_date: Apr 12
+ severity: moderate
+ first_patched: '3.7'
+- name: requests
+ description: Python HTTP for Humans
+ package_url: https://pypi.org/project/requests
+ version: 2.23.0
+ license: Apache-2.0
+ open_source: true
+ hosted_saas: false
+ category: Libraries
+ sub_category: PyPI Packages
+ image_url: https://img.stackshare.io/package/19826/default_d7c684bf2673f008a9f02ac93901229297a22d7e.png
+ detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
+ detection_source: provenance/requirements.txt
+ last_updated_by: Martin Chapman
+ last_updated_on: 2020-06-11 09:37:53.000000000 Z
+ vulnerabilities:
+ - name: Requests `Session` object does not verify requests after making first request
+ with verify=False
+ cve_id: CVE-2024-35195
+ cve_url: https://github.com/advisories/GHSA-9wx4-h78v-vm56
+ detected_date: May 21
+ severity: moderate
+ first_patched: 2.32.0
+ - name: Unintended leak of Proxy-Authorization header in requests
+ cve_id: CVE-2023-32681
+ cve_url: https://github.com/advisories/GHSA-j8r2-6x86-q33q
+ detected_date: May 23
+ severity: moderate
+ first_patched: 2.31.0
+- name: websockets
+ description: An implementation of the WebSocket Protocol
+ package_url: https://pypi.org/project/websockets
+ version: '8.1'
+ license: BSD-3-Clause
+ open_source: true
+ hosted_saas: false
+ category: Libraries
+ sub_category: PyPI Packages
+ image_url: https://img.stackshare.io/package/19951/default_fbe690a687f1af7dc36ac3d526708be3294c4cc9.png
+ detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
+ detection_source: provenance/requirements.txt
+ last_updated_by: Martin Chapman
+ last_updated_on: 2020-06-11 09:37:53.000000000 Z
+ vulnerabilities:
+ - name: Observable Timing Discrepancy in aaugustin websockets library
+ cve_id: CVE-2021-33880
+ cve_url: https://github.com/advisories/GHSA-8ch4-58qp-g3mp
+ detected_date: Aug 22
+ severity: moderate
+ first_patched: '9.1'
- name: chardet
description: Universal encoding detector for Python 2 and 3
package_url: https://pypi.org/project/chardet
@@ -324,20 +496,6 @@ tools:
detection_source: provenance/requirements.txt
last_updated_by: Martin Chapman
last_updated_on: 2020-06-11 09:37:53.000000000 Z
-- name: idna
- description: Internationalized Domain Names in Applications
- package_url: https://pypi.org/project/idna
- version: '2.9'
- license: BSD-3-Clause
- open_source: true
- hosted_saas: false
- category: Libraries
- sub_category: PyPI Packages
- image_url: https://img.stackshare.io/package/19863/default_f24e00e4cb7620e436f9d06e0305070e1335922a.png
- detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
- detection_source: provenance/requirements.txt
- last_updated_by: Martin Chapman
- last_updated_on: 2020-06-11 09:37:53.000000000 Z
- name: pika
description: Pika Python AMQP Client Library
package_url: https://pypi.org/project/pika
@@ -380,96 +538,6 @@ tools:
detection_source: provenance/requirements.txt
last_updated_by: Martin Chapman
last_updated_on: 2020-06-12 16:40:07.000000000 Z
-- name: requests
- description: Python HTTP for Humans
- package_url: https://pypi.org/project/requests
- version: 2.23.0
- license: Apache-2.0
- open_source: true
- hosted_saas: false
- category: Libraries
- sub_category: PyPI Packages
- image_url: https://img.stackshare.io/package/19826/default_d7c684bf2673f008a9f02ac93901229297a22d7e.png
- detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
- detection_source: provenance/requirements.txt
- last_updated_by: Martin Chapman
- last_updated_on: 2020-06-11 09:37:53.000000000 Z
- vulnerabilities:
- - name: Unintended leak of Proxy-Authorization header in requests
- cve_id: CVE-2023-32681
- cve_url: https://github.com/advisories/GHSA-j8r2-6x86-q33q
- detected_date: May 23
- severity: moderate
- first_patched: 2.31.0
-- name: starlette
- description: The little ASGI library that shines
- package_url: https://pypi.org/project/starlette
- version: 0.13.4
- license: BSD-3-Clause
- open_source: true
- hosted_saas: false
- category: Libraries
- sub_category: PyPI Packages
- image_url: https://img.stackshare.io/package/20295/default_640b00772a7025571fa2ac02de971e76f9662aa9.png
- detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
- detection_source: provenance/requirements.txt
- last_updated_by: Martin Chapman
- last_updated_on: 2020-06-11 09:37:53.000000000 Z
- vulnerabilities:
- - name: Starlette Content-Type Header ReDoS
- cve_id:
- cve_url: https://github.com/advisories/GHSA-93gm-qmq6-w238
- detected_date: Feb 6
- severity: high
- first_patched: 0.36.2
- - name: Starlette allows an unauthenticated and remote attacker to specify any number
- of form fields or files
- cve_id: CVE-2023-30798
- cve_url: https://github.com/advisories/GHSA-3qj8-93xh-pwh2
- detected_date: Apr 22
- severity: high
- first_patched: 0.25.0
- - name: MultipartParser denial of service with too many fields or files
- cve_id:
- cve_url: https://github.com/advisories/GHSA-74m5-2c7w-9w3x
- detected_date: Feb 15
- severity: moderate
- first_patched: 0.25.0
-- name: urllib3
- description: HTTP library with thread-safe connection pooling
- package_url: https://pypi.org/project/urllib3
- version: 1.25.9
- license: MIT
- open_source: true
- hosted_saas: false
- category: Libraries
- sub_category: PyPI Packages
- image_url: https://img.stackshare.io/package/19842/default_4604ff5dcb7f4d9c7b3833591c2142493951b19c.png
- detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
- detection_source: provenance/requirements.txt
- last_updated_by: Martin Chapman
- last_updated_on: 2020-06-11 09:37:53.000000000 Z
- vulnerabilities:
- - name: Catastrophic backtracking in URL authority parser when passed URL containing
- many @ characters
- cve_id: CVE-2021-33503
- cve_url: https://github.com/advisories/GHSA-q2q7-5pp4-w6pg
- detected_date: Aug 22
- severity: high
- first_patched: 1.26.5
- - name: urllib3's request body not stripped after redirect from 303 status changes
- request method to GET
- cve_id: CVE-2023-45803
- cve_url: https://github.com/advisories/GHSA-g4mx-q9vg-27p4
- detected_date: Oct 18
- severity: moderate
- first_patched: 1.26.18
- - name: "`Cookie` HTTP header isn't stripped on cross-origin redirects"
- cve_id: CVE-2023-43804
- cve_url: https://github.com/advisories/GHSA-v845-jxx5-vc9f
- detected_date: Oct 3
- severity: moderate
- first_patched: 1.26.17
- name: uvicorn
description: The lightning-fast ASGI server
package_url: https://pypi.org/project/uvicorn
@@ -498,27 +566,6 @@ tools:
detection_source: provenance/requirements.txt
last_updated_by: Martin Chapman
last_updated_on: 2020-06-11 09:37:53.000000000 Z
-- name: websockets
- description: An implementation of the WebSocket Protocol
- package_url: https://pypi.org/project/websockets
- version: '8.1'
- license: BSD-3-Clause
- open_source: true
- hosted_saas: false
- category: Libraries
- sub_category: PyPI Packages
- image_url: https://img.stackshare.io/package/19951/default_fbe690a687f1af7dc36ac3d526708be3294c4cc9.png
- detection_source_url: https://github.com/kclhi/jupyter/blob/master/provenance/requirements.txt
- detection_source: provenance/requirements.txt
- last_updated_by: Martin Chapman
- last_updated_on: 2020-06-11 09:37:53.000000000 Z
- vulnerabilities:
- - name: Observable Timing Discrepancy in aaugustin websockets library
- cve_id: CVE-2021-33880
- cve_url: https://github.com/advisories/GHSA-8ch4-58qp-g3mp
- detected_date: Aug 22
- severity: moderate
- first_patched: '9.1'
- name: "@jupyterlab/application"
description: JupyterLab - Application
package_url: https://www.npmjs.com/@jupyterlab/application
|