You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The copies of zlib included in tkcop.dll and tkezlib.dll rely on the 1.2.13 versions of the package, where the current version is 1.3.1:
Because SWAT and TK don't directly expose the tool which has a critical vulnerability, the high priority CVE isn't directly relevant, but it would still be great to resync so that security scanners and other consumers don't flag the package.
The text was updated successfully, but these errors were encountered:
Working with SAS support, they closed the internal issue and said this public facing one was the right place to get this issue addressed. Can a contributor to the python-swat package please triage this issue? It is still present in the latest 1.15.0 wheels:
The copies of![image](https://private-user-images.githubusercontent.com/1314/313746363-a87cdf88-7bee-4b30-9818-da1dc457c074.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkzNjYzNzgsIm5iZiI6MTczOTM2NjA3OCwicGF0aCI6Ii8xMzE0LzMxMzc0NjM2My1hODdjZGY4OC03YmVlLTRiMzAtOTgxOC1kYTFkYzQ1N2MwNzQucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI1MDIxMiUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNTAyMTJUMTMxNDM4WiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9Zjc2YmNiNTNhN2EzM2FlYzNlOWMxZmRkZjc2NjY5N2Y2MDU3NjM5ZmFlZGVjNjc1NzljYjJhZGMxOTQzYTg3MCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.ZpOc5RMBkW-dSs9W77l9pMpQFHhdZjPnaet6cqdQNmY)
zlib
included intkcop.dll
andtkezlib.dll
rely on the 1.2.13 versions of the package, where the current version is 1.3.1:Because SWAT and TK don't directly expose the tool which has a critical vulnerability, the high priority CVE isn't directly relevant, but it would still be great to resync so that security scanners and other consumers don't flag the package.
The text was updated successfully, but these errors were encountered: