[FAIL] Supply chaincriticalDP-01@ pyproject.toml, requirements.txt, uv.lock
anyio@4.11.0 has a known vulnerability: AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing.
GHSA-82r6-8w77-94w6 · PyPI:anyio@4.11.0highDP-03@ pyproject.toml
`GitPython` is one or two edits away from the popular `ipython`.
GitPythonhighDP-01@ pyproject.toml, requirements.txt, uv.lock
click@8.3.0 has a known vulnerability.
PYSEC-2026-2132 · PyPI:click@8.3.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
idna@3.11 has a known vulnerability.
PYSEC-2026-215 · PyPI:idna@3.11highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pygments@2.19.2 has a known vulnerability: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching.
PYSEC-2026-2987 · PyPI:Pygments@2.19.2highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability: Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading.
GHSA-45hq-cxwh-f6vc · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability: Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`.
GHSA-5x94-69rx-g8h2 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-62p4-gmf7-7g93 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-6r8x-57c9-28j4 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-8v84-f9pq-wr9x · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-9hw9-ch79-4vh6 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-cfh3-3jmp-rvhc · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-fj7v-r99m-22gq · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-jjj6-mw9f-p565 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-phj9-mv4w-65pm · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-pwv6-vv43-88gr · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-r73j-pqj5-w3x7 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-vjc4-5qp5-m44j · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-whj4-6x5x-4v2j · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-wjx4-4jcj-g98j · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
GHSA-xj96-63gp-2gmr · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-165 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2249 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2250 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2252 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2253 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2254 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2255 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2256 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2257 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-2874 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-3451 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-3453 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-3454 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-3493 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-3494 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-3495 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability.
PYSEC-2026-3496 · PyPI:Pillow@11.0.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
pytest@8.4.2 has a known vulnerability.
GHSA-6w46-j5rx-g56g · PyPI:pytest@8.4.2highDP-01@ pyproject.toml, requirements.txt, uv.lock
pytest@8.4.2 has a known vulnerability.
PYSEC-2026-1845 · PyPI:pytest@8.4.2highDP-01@ pyproject.toml, requirements.txt, uv.lock
python-dotenv@1.1.1 has a known vulnerability.
GHSA-mf9w-mj56-hr94 · PyPI:python-dotenv@1.1.1highDP-01@ pyproject.toml, requirements.txt, uv.lock
python-dotenv@1.1.1 has a known vulnerability.
PYSEC-2026-2270 · PyPI:python-dotenv@1.1.1highDP-01@ pyproject.toml, requirements.txt, uv.lock
requests@2.32.5 has a known vulnerability.
GHSA-gc5v-m9x4-r6x2 · PyPI:requests@2.32.5highDP-01@ pyproject.toml, requirements.txt, uv.lock
requests@2.32.5 has a known vulnerability.
PYSEC-2026-2275 · PyPI:requests@2.32.5highDP-01@ pyproject.toml, requirements.txt, uv.lock
soupsieve@2.8 has a known vulnerability.
GHSA-2wc2-fm75-p42x · PyPI:soupsieve@2.8highDP-01@ pyproject.toml, requirements.txt, uv.lock
soupsieve@2.8 has a known vulnerability.
GHSA-836r-79rf-4m37 · PyPI:soupsieve@2.8highDP-01@ pyproject.toml, requirements.txt, uv.lock
soupsieve@2.8 has a known vulnerability.
GHSA-gjv8-xp57-g29c · PyPI:soupsieve@2.8highDP-01@ pyproject.toml, requirements.txt, uv.lock
soupsieve@2.8 has a known vulnerability.
GHSA-j934-xhv5-fg8f · PyPI:soupsieve@2.8highDP-01@ pyproject.toml, requirements.txt, uv.lock
soupsieve@2.8 has a known vulnerability.
PYSEC-2026-3071 · PyPI:soupsieve@2.8highDP-01@ pyproject.toml, requirements.txt, uv.lock
soupsieve@2.8 has a known vulnerability.
PYSEC-2026-3072 · PyPI:soupsieve@2.8highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
GHSA-2xpw-w6gg-jr37 · PyPI:urllib3@2.5.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
GHSA-38jv-5279-wg99 · PyPI:urllib3@2.5.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
GHSA-gm62-xv2j-4w53 · PyPI:urllib3@2.5.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
GHSA-qccp-gfcp-xxvc · PyPI:urllib3@2.5.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
PYSEC-2026-141 · PyPI:urllib3@2.5.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
PYSEC-2026-1994 · PyPI:urllib3@2.5.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
PYSEC-2026-1996 · PyPI:urllib3@2.5.0highDP-01@ pyproject.toml, requirements.txt, uv.lock
urllib3@2.5.0 has a known vulnerability.
PYSEC-2026-1998 · PyPI:urllib3@2.5.0mediumDP-01@ pyproject.toml, requirements.txt, uv.lock
anyio@4.11.0 has a known vulnerability: AnyIO process-pool workers can block indefinitely on undrained stderr.
GHSA-5p39-cfhj-2xmp · PyPI:anyio@4.11.0mediumDP-01@ pyproject.toml, requirements.txt, uv.lock
idna@3.11 has a known vulnerability: Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix.
GHSA-65pc-fj4g-8rjx · PyPI:idna@3.11mediumDP-01@ pyproject.toml, requirements.txt, uv.lock
Pillow@11.0.0 has a known vulnerability: Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path.
GHSA-4x4j-2g7c-83w6 · PyPI:Pillow@11.0.0lowDP-01@ pyproject.toml, requirements.txt, uv.lock
Pygments@2.19.2 has a known vulnerability: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching.
GHSA-5239-wwwm-4pmq · PyPI:Pygments@2.19.2