Skip to content

Allow networkx<3.0 to allow security fixes#140

Open
jdimatteo wants to merge 1 commit intoetsy:masterfrom
jdimatteo:networkx-upgrade
Open

Allow networkx<3.0 to allow security fixes#140
jdimatteo wants to merge 1 commit intoetsy:masterfrom
jdimatteo:networkx-upgrade

Conversation

@jdimatteo
Copy link

Description

Allow networkx<3.0 to allow security fixes

Context / Why are we making this change?

networkx before 2.6 is flagged for security vulnerabilities as described at https://security.snyk.io/vuln/SNYK-PYTHON-NETWORKX-1062709

Testing and QA Plan

How has this work been tested or QA'd?

Trusting automated test coverage.

Impact

What are the implications of these changes? Are there any cross-cutting concerns to keep in mind?

networkx<3.0 was allowed with #107 , however was reverted with #108 , and no context was provided why it was reverted, but hopefully this change is fine now given the passage of time.

networkx before 2.6 is flagged for security vulnerabilities as described at https://security.snyk.io/vuln/SNYK-PYTHON-NETWORKX-1062709

Note that networkx<3.0 was allowed with etsy#107 , however was reverted with etsy#108 , and no context was provided why it was reverted, but hopefully this change is fine now given the passage of time.
@jdimatteo
Copy link
Author

Hi can someone please review / merge this or let me know what changes are needed before merging this security fix?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments