Fix vulnerable musicround dependencies
This commit is contained in:
+2
-1
@@ -5,7 +5,8 @@ flask_migrate
|
|||||||
requests
|
requests
|
||||||
pydub
|
pydub
|
||||||
reportlab
|
reportlab
|
||||||
PyJWT
|
PyJWT>=2.10.1
|
||||||
|
idna>=3.11
|
||||||
python-dotenv
|
python-dotenv
|
||||||
deezer-python
|
deezer-python
|
||||||
Flask-Assets
|
Flask-Assets
|
||||||
|
|||||||
@@ -124,6 +124,30 @@ class TestDependencySecurity:
|
|||||||
assert 'authlib>=1.6.5' in content, \
|
assert 'authlib>=1.6.5' in content, \
|
||||||
"authlib should be pinned to >= 1.6.5 to fix known vulnerabilities"
|
"authlib should be pinned to >= 1.6.5 to fix known vulnerabilities"
|
||||||
|
|
||||||
|
def test_pyjwt_version(self):
|
||||||
|
"""Test that PyJWT is at least version 2.10.1."""
|
||||||
|
requirements_path = os.path.join(
|
||||||
|
os.path.dirname(__file__), '..', 'requirements.txt'
|
||||||
|
)
|
||||||
|
|
||||||
|
with open(requirements_path, 'r') as f:
|
||||||
|
content = f.read()
|
||||||
|
|
||||||
|
assert 'PyJWT>=2.10.1' in content, \
|
||||||
|
"PyJWT should be pinned to >= 2.10.1 to fix known vulnerabilities"
|
||||||
|
|
||||||
|
def test_idna_version(self):
|
||||||
|
"""Test that idna is at least version 3.11."""
|
||||||
|
requirements_path = os.path.join(
|
||||||
|
os.path.dirname(__file__), '..', 'requirements.txt'
|
||||||
|
)
|
||||||
|
|
||||||
|
with open(requirements_path, 'r') as f:
|
||||||
|
content = f.read()
|
||||||
|
|
||||||
|
assert 'idna>=3.11' in content, \
|
||||||
|
"idna should be pinned to >= 3.11 to fix known vulnerabilities"
|
||||||
|
|
||||||
|
|
||||||
class TestInputValidation:
|
class TestInputValidation:
|
||||||
"""Test that user input is properly validated."""
|
"""Test that user input is properly validated."""
|
||||||
|
|||||||
Reference in New Issue
Block a user