← All tasks
pythonzeromq/pyzmq #1815Not a task: already works

BUG: PyPy Dependency on `py` package triggers CVE-2022-42969

envgap__zeromq__pyzmq-1815

01 / FAILURE SIGNATURE

As reported upstream

When using `pyzmq`, `py` is installed as a dependency and this triggers a error when scanning with trivy: https://avd.aquasec.com/nvd/2022/cve-2022-42969/
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
5ff8104a07a4274ddca49c1707ffbee45d63b670
Manifest
setup.py
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

zeromq/pyzmq #1815 · read the original issue
### What pyzmq version?

24.0.1

### What libzmq version?

4.3.4

### Python version (and how it was installed)

Python 3.10.6, installed from repository

### OS

ubuntu 22.04

### What happened?

When using `pyzmq`, `py` is installed as a dependency and this triggers a error when scanning with trivy: https://avd.aquasec.com/nvd/2022/cve-2022-42969/



Seeing the projects readme `py` should no longer be used, but replaced by the other packages mentioned in the readme.



### Code to reproduce bug

_No response_

### Traceback, if applicable

_No response_

### More info

_No response_
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]