#14543 Python's certifi package is ingested with the following version string: `2023.7.22`. The NVD dataset uses the following versioning: `2023.07.22`. This PR updates the nvdtools package. This is the fix in nvdtools that fixes this exact false positive: https://github.com/facebookincubator/nvdtools/commit/c0d18738cde5864576f073af99669edc92e87fb4 - [X] Changes file added for user-visible changes in `changes/` or `orbit/changes/`. See [Changes files](https://fleetdm.com/docs/contributing/committing-changes#changes-files) for more information. - ~[ ] Documented any API changes (docs/Using-Fleet/REST-API.md or docs/Contributing/API-for-contributors.md)~ - ~[ ] Documented any permissions changes (docs/Using Fleet/manage-access.md)~ - ~[ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements)~ - ~[ ] Added support on fleet's osquery simulator `cmd/osquery-perf` for new osquery data ingestion features.~ - ~[ ] Added/updated tests~ - [X] Manual QA for all new/changed functionality - For Orbit and Fleet Desktop changes: - ~[ ] Manual QA must be performed in the three main OSs, macOS, Windows and Linux.~ - ~[ ] Auto-update manual QA, from released version of component to new version (see [tools/tuf/test](../tools/tuf/test/README.md)).~
2 lines
76 B
Plaintext
2 lines
76 B
Plaintext
* Fixed false positive CVE-2023-37920 detected on `certifi` python package.
|