BUG: PyPy Dependency on `py` package triggers CVE-2022-42969
envgap__zeromq__pyzmq-1815
01 / FAILURE SIGNATURE
As reported upstream
When using `pyzmq`, `py` is installed as a dependency and this triggers a error when scanning with trivy: https://avd.aquasec.com/nvd/2022/cve-2022-42969/
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
5ff8104a07a4274ddca49c1707ffbee45d63b670- Manifest
setup.py- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
zeromq/pyzmq #1815 · read the original issue
### What pyzmq version? 24.0.1 ### What libzmq version? 4.3.4 ### Python version (and how it was installed) Python 3.10.6, installed from repository ### OS ubuntu 22.04 ### What happened? When using `pyzmq`, `py` is installed as a dependency and this triggers a error when scanning with trivy: https://avd.aquasec.com/nvd/2022/cve-2022-42969/ Seeing the projects readme `py` should no longer be used, but replaced by the other packages mentioned in the readme. ### Code to reproduce bug _No response_ ### Traceback, if applicable _No response_ ### More info _No response_
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]