Vendor ply as it is no longer maintained, resolve CVE in the package by removing pickle functionality - #208
Conversation
Resolve GHSA/CVE for reading untrusted pickle files. * GHSA-qc6m-pwr3-g72p * https://nvd.nist.gov/vuln/detail/CVE-2025-56005
|
i beg 🙏🏻🙏🏻🙏🏻🙏🏻 |
|
Thank you for working on this! |
|
Thanks @jmahlik! |
|
Will there be a new release with this fix? |
|
Can we have a new release with this fix? |
But it wasn't removed here, so it's being detected as a dependency by vulnerability scanning tools.
|
@jmahlik when can we expect a release on this? |
|
I'm not a core maintainer on this project, just did the PR to vendor it. Keep in mind the maintainers are doing this on their free time. I would suggest upvoting #206 with a thumbs up and hopefully they'll release a new version soon. They are paying attention to the issue tracker. It can be difficult to wait if a dependency scanner is causing all kinds of issues for you but this "vulnerability" is questionable at best and jsonpath-ng wasn't event using the functionality in question so at least you've got that to stand on. Thus is the dysfunctional CVE system we're meant to deal with. |
Vendor ply as it is no longer maintained
related #206