Skip to content

pyats.log 26.6 pins python-engineio below patched CVE fix #290

Description

@pc3o

Summary

pyats[full]==26.6 pulls pyats.log>=26.6.0,<26.7.0, which requires:

python-engineio>=3.13.0,<4.10.0

That constraint prevents installation of the patched python-engineio versions for:

Both advisories affect python-engineio <=4.13.1 and are patched in 4.13.2.

Impact

Security-controlled package mirrors block the resolved version, currently python-engineio==4.9.1, so pyats[full]==26.6 cannot be installed.

Example failure:

Could not install requirement python-engineio<4.10.0,>=3.13.0
(from pyats.log<26.7.0,>=26.6.0->pyats==26.6->pyats[full]==26.6)
because of HTTP error 403 Client Error: Forbidden

Request

Please update the pyats.log dependency constraint to allow patched python-engineio versions, ideally >=4.13.2, and publish a patched pyATS release.

For example, if compatible:

python-engineio>=4.13.2,<5

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions