diff --git a/techstack.md b/techstack.md new file mode 100644 index 000000000..d38c3d735 --- /dev/null +++ b/techstack.md @@ -0,0 +1,278 @@ + +
+ +# Tech Stack File +![](https://img.stackshare.io/repo.svg "repo") [yourkin/setup-python](https://github.com/yourkin/setup-python)![](https://img.stackshare.io/public_badge.svg "public") +

+|44
Tools used|02/29/24
Report generated| +|------|------| +
+ +## Languages (4) + + + + + + + + + + +
+ JavaScript +
+ JavaScript +
+ +
+ Python +
+ Python +
+ +
+ Ruby +
+ Ruby +
+ +
+ TypeScript +
+ TypeScript +
+ +
+ +## Frameworks (2) + + + + + + +
+ .NET +
+ .NET +
+ +
+ Node.js +
+ Node.js +
+ +
+ +## DevOps (10) + + + + + + + + + + + + + + + + + + + + + + + + +
+ ESLint +
+ ESLint +
+ +
+ Git +
+ Git +
+ +
+ GitHub Actions +
+ GitHub Actions +
+ +
+ Jest +
+ Jest +
+ v27.2.5 +
+ NuGet +
+ NuGet +
+ +
+ Prettier +
+ Prettier +
+ v2.8.4 +
+ PyPI +
+ PyPI +
+ +
+ RubyGems +
+ RubyGems +
+ +
+ flake8 +
+ flake8 +
+ +
+ npm +
+ npm +
+ +
+ +## Other (4) + + + + + + + + + + +
+ NumPy +
+ NumPy +
+ v1.25.1 +
+ Shell +
+ Shell +
+ +
+ docutils +
+ docutils +
+ +
+ husky +
+ husky +
+ +
+ + +## Open source packages (24) + +## PyPI (14) + +|NAME|VERSION|LAST UPDATED|LAST UPDATED BY|LICENSE|VULNERABILITIES| +|:------|:------|:------|:------|:------|:------| +|[Kivy](https://pypi.org/project/Kivy)|N/A|11/17/21|Dmitry Shibanov |MIT|N/A| +|[Pygments](https://pypi.org/project/Pygments)|v2.6.1|11/17/21|Dmitry Shibanov |BSD-3-Clause|[CVE-2021-27291](https://github.com/advisories/GHSA-pq64-v7f5-gqh8) (High)
[CVE-2021-20270](https://github.com/advisories/GHSA-9w8r-397f-prfh) (High)
[CVE-2022-40896](https://github.com/advisories/GHSA-mrwq-x4v8-fh7p) (Moderate)| +|[certifi](https://pypi.org/project/certifi)|v2020.6.20|11/17/21|Dmitry Shibanov |MPL-2.0|[CVE-2023-37920](https://github.com/advisories/GHSA-xqr8-7jwr-rhp7) (High)
[CVE-2022-23491](https://github.com/advisories/GHSA-43fp-rhv2-5gv8) (Moderate)| +|[chardet](https://pypi.org/project/chardet)|v3.0.4|11/17/21|Dmitry Shibanov |LGPL-2.1|N/A| +|[docutils](https://pypi.org/project/docutils)|v0.16|11/17/21|Dmitry Shibanov |Unlicense,Python-2.0,BSD-2-Clause,CNRI-Python-GPL-Compatible|N/A| +|[future](https://pypi.org/project/future)|v0.18.2|11/17/21|Dmitry Shibanov |MIT|[CVE-2022-40899](https://github.com/advisories/GHSA-v3c5-jqr6-7qm8) (High)| +|[idna](https://pypi.org/project/idna)|v2.9|11/17/21|Dmitry Shibanov |BSD-3-Clause|N/A| +|[itsdangerous](https://pypi.org/project/itsdangerous)|v1.1.0|11/17/21|Dmitry Shibanov |BSD-3-Clause|N/A| +|[packaging](https://pypi.org/project/packaging)|v21.0|11/17/21|Dmitry Shibanov |BSD-3-Clause,Apache-2.0|N/A| +|[pefile](https://pypi.org/project/pefile)|v2021.9.3|11/17/21|Dmitry Shibanov |MIT|N/A| +|[pyparsing](https://pypi.org/project/pyparsing)|v2.4.7|11/17/21|Dmitry Shibanov |MIT|N/A| +|[requests](https://pypi.org/project/requests)|v2.24.0|11/17/21|Dmitry Shibanov |Apache-2.0|[CVE-2023-32681](https://github.com/advisories/GHSA-j8r2-6x86-q33q) (Moderate)| +|[urllib3](https://pypi.org/project/urllib3)|v1.25.9|11/17/21|Dmitry Shibanov |MIT|[CVE-2021-33503](https://github.com/advisories/GHSA-q2q7-5pp4-w6pg) (High)
[CVE-2023-45803](https://github.com/advisories/GHSA-g4mx-q9vg-27p4) (Moderate)
[CVE-2023-43804](https://github.com/advisories/GHSA-v845-jxx5-vc9f) (Moderate)| +|[xlrd](https://pypi.org/project/xlrd)|v1.2.0|11/17/21|Dmitry Shibanov |BSD-3-Clause|N/A| + + +## npm (10) + +|NAME|VERSION|LAST UPDATED|LAST UPDATED BY|LICENSE|VULNERABILITIES| +|:------|:------|:------|:------|:------|:------| +|[@types/jest](https://www.npmjs.com/@types/jest)|v27.0.2|03/09/23|Ivan |MIT|N/A| +|[@types/node](https://www.npmjs.com/@types/node)|v16.11.25|05/22/23|Nikolai Laevskii |MIT|N/A| +|[@types/semver](https://www.npmjs.com/@types/semver)|v7.3.13|07/13/23|dependabot[bot] |MIT|N/A| +|[@typescript-eslint/eslint-plugin](https://www.npmjs.com/@typescript-eslint/eslint-plugin)|v5.54.0|05/22/23|Nikolai Laevskii |MIT|N/A| +|[@typescript-eslint/parser](https://www.npmjs.com/@typescript-eslint/parser)|v5.54.0|05/22/23|Nikolai Laevskii |BSD-2-Clause|N/A| +|[eslint-config-prettier](https://www.npmjs.com/eslint-config-prettier)|v8.6.0|05/22/23|Nikolai Laevskii |MIT|N/A| +|[eslint-plugin-jest](https://www.npmjs.com/eslint-plugin-jest)|v27.2.1|05/22/23|Nikolai Laevskii |MIT|N/A| +|[eslint-plugin-node](https://www.npmjs.com/eslint-plugin-node)|v11.1.0|05/22/23|Nikolai Laevskii |MIT|N/A| +|[husky](https://www.npmjs.com/husky)|v7.0.2|10/13/21|Dmitry Shibanov |MIT|N/A| +|[ts-jest](https://www.npmjs.com/ts-jest)|v27.0.5|03/09/23|Ivan |MIT|N/A| + +
+
+ +Generated via [Stack File](https://github.com/marketplace/stack-file) diff --git a/techstack.yml b/techstack.yml new file mode 100644 index 000000000..801661e91 --- /dev/null +++ b/techstack.yml @@ -0,0 +1,655 @@ +repo_name: yourkin/setup-python +report_id: e83026df00eb1b438cef32e3c4326537 +version: 0.1 +repo_type: Public +timestamp: '2024-02-29T18:17:20+00:00' +requested_by: dmitry-shibanov +provider: github +branch: main +detected_tools_count: 44 +tools: +- name: JavaScript + description: Lightweight, interpreted, object-oriented language with first-class + functions + website_url: https://developer.mozilla.org/en-US/docs/Web/JavaScript + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/1209/javascript.jpeg + detection_source_url: https://github.com/yourkin/setup-python + detection_source: Repo Metadata +- name: Python + description: A clear and powerful object-oriented programming language, comparable + to Perl, Ruby, Scheme, or Java. + website_url: https://www.python.org + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/993/pUBY5pVj.png + detection_source_url: https://github.com/yourkin/setup-python + detection_source: Repo Metadata +- name: Ruby + description: A dynamic, interpreted, open source programming language with a focus + on simplicity and productivity + website_url: https://www.ruby-lang.org + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/989/ruby.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/requirements-linux.txt + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: TypeScript + description: A superset of JavaScript that compiles to clean JavaScript output + website_url: http://www.typescriptlang.org + license: Apache-2.0 + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/1612/bynNY5dJ.jpg + detection_source_url: https://github.com/yourkin/setup-python + detection_source: Repo Metadata +- name: ".NET" + description: A free, cross-platform, open source developer platform for building + many different types of applications + website_url: http://www.microsoft.com/net/ + license: MIT + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Frameworks (Full Stack) + image_url: https://img.stackshare.io/service/1014/IoPy1dce_400x400.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package.json + detection_source: package.json + last_updated_by: Danny McCormick + last_updated_on: 2019-08-20 14:27:52.000000000 Z +- name: Node.js + description: A platform built on Chrome's JavaScript runtime for easily building + fast, scalable network applications + website_url: http://nodejs.org/ + open_source: true + hosted_saas: false + category: Languages & Frameworks + sub_category: Frameworks (Full Stack) + image_url: https://img.stackshare.io/service/1011/n1JRsFeB_400x400.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package.json + detection_source: package.json + last_updated_by: Danny McCormick + last_updated_on: 2019-08-20 14:27:52.000000000 Z +- name: ESLint + description: The fully pluggable JavaScript code quality tool + website_url: http://eslint.org/ + license: MIT + open_source: true + hosted_saas: false + category: Build, Test, Deploy + sub_category: Code Review + image_url: https://img.stackshare.io/service/3337/Q4L7Jncy.jpg + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package.json + detection_source: package.json + last_updated_by: Danny McCormick + last_updated_on: 2019-08-20 14:27:52.000000000 Z +- name: Git + description: Fast, scalable, distributed revision control system + website_url: http://git-scm.com/ + open_source: true + hosted_saas: false + category: Build, Test, Deploy + sub_category: Version Control System + image_url: https://img.stackshare.io/service/1046/git.png + detection_source_url: https://github.com/yourkin/setup-python + detection_source: Repo Metadata +- name: GitHub Actions + description: Automate your workflow from idea to production + website_url: https://github.com/features/actions + open_source: false + hosted_saas: true + category: Build, Test, Deploy + sub_category: Continuous Integration + image_url: https://img.stackshare.io/service/11563/actions.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/.github/workflows/basic-validation.yml + detection_source: ".github/workflows/basic-validation.yml" + last_updated_by: Ivan + last_updated_on: 2023-03-09 10:44:56.000000000 Z +- name: Jest + description: Painless JavaScript Unit Testing + website_url: http://facebook.github.io/jest/ + version: 27.2.5 + license: MIT + open_source: true + hosted_saas: false + category: Build, Test, Deploy + sub_category: Javascript Testing Framework + image_url: https://img.stackshare.io/service/830/jest.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Danny McCormick + last_updated_on: 2019-08-20 14:27:52.000000000 Z +- name: NuGet + description: The package manager for .NET + website_url: https://www.nuget.org/ + open_source: false + hosted_saas: false + category: Build, Test, Deploy + sub_category: Package Managers + image_url: https://img.stackshare.io/service/2637/6I3oEOP4_400x400.jpg + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package.json + detection_source: package.json + last_updated_by: Danny McCormick + last_updated_on: 2019-08-20 14:27:52.000000000 Z +- name: Prettier + description: Prettier is an opinionated code formatter. + website_url: https://prettier.io/ + version: 2.8.4 + license: MIT + open_source: true + hosted_saas: false + category: Build, Test, Deploy + sub_category: Code Review + image_url: https://img.stackshare.io/service/7035/default_66f265943abed56bcdbfca1c866a4261b1fbb063.jpg + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Ivan + last_updated_on: 2023-04-03 10:46:57.000000000 Z +- name: PyPI + description: A repository of software for the Python programming language + website_url: https://pypi.org/ + open_source: false + hosted_saas: false + category: Build, Test, Deploy + sub_category: Hosted Package Repository + image_url: https://img.stackshare.io/service/12572/-RIWgodF_400x400.jpg + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/requirements.txt + detection_source: __tests__/data/requirements.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: RubyGems + description: Easily download, install, and use ruby software packages on your system + website_url: https://rubygems.org/ + open_source: false + hosted_saas: false + category: Build, Test, Deploy + sub_category: Package Managers + image_url: https://img.stackshare.io/service/12795/5jL6-BA5_400x400.jpeg + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/requirements-linux.txt + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: flake8 + description: Tool for style guide enforcement + website_url: https://github.com/PyCQA/flake8 + open_source: true + hosted_saas: false + category: Build, Test, Deploy + sub_category: Code Review + image_url: https://img.stackshare.io/service/4838/default_c37162891c64eca7fafe782d9c191e409aae1e93.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/pipenv-requirements.txt + detection_source: __tests__/data/pipenv-requirements.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2023-07-13 12:11:40.000000000 Z +- name: npm + description: The package manager for JavaScript. + website_url: https://www.npmjs.com/ + open_source: false + hosted_saas: false + category: Build, Test, Deploy + sub_category: Front End Package Manager + image_url: https://img.stackshare.io/service/1120/lejvzrnlpb308aftn31u.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package.json + detection_source: package.json + last_updated_by: Danny McCormick + last_updated_on: 2019-08-20 14:27:52.000000000 Z +- name: NumPy + description: Fundamental package for scientific computing with Python + website_url: http://www.numpy.org/ + version: 1.25.1 + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: Data Science Tools + image_url: https://img.stackshare.io/service/2179/default_332f874a2edb2686f578aa6389313efcea1eec41.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/Pipfile.lock + detection_source: __tests__/data/Pipfile + last_updated_by: Vladimir Safonkin + last_updated_on: 2022-04-04 13:12:24.000000000 Z +- name: Shell + description: A shell is a text-based terminal, used for manipulating programs and + files. Shell scripts typically manage program execution. + website_url: https://en.wikipedia.org/wiki/Shell_script + open_source: false + hosted_saas: false + category: Languages & Frameworks + sub_category: Languages + image_url: https://img.stackshare.io/service/4631/default_c2062d40130562bdc836c13dbca02d318205a962.png + detection_source_url: https://github.com/yourkin/setup-python + detection_source: Repo Metadata +- name: docutils + description: "http://t.co/lH6rcPxBja Service Outage and other informational alerts.\r\n\r\nFor + support, see ticket/IRC/email information on http://t.co/nE5akSwLqM" + website_url: http://docutils.sourceforge.net/ + open_source: false + hosted_saas: false + image_url: https://img.stackshare.io/service/8480/LI68uG-2_normal.jpg + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/requirements-linux.txt + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: husky + website_url: https://github.com/typicode/husky + open_source: false + hosted_saas: false + image_url: https://img.stackshare.io/service/9527/5502029.jpeg + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package.json + detection_source: package.json + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-10-13 12:18:42.000000000 Z +- name: Kivy + description: A software library for rapid development of hardware-accelerated multitouch + applications + package_url: https://pypi.org/project/Kivy + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/20652/default_a2b194ec3319028e4cccf6121f9dc81fa9e44c37.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/requirements-linux.txt + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: Pygments + description: Pygments is a syntax highlighting package written in Python + package_url: https://pypi.org/project/Pygments + version: 2.6.1 + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19858/default_4d761b2257a1435539d6dc92346974d9f1d55c70.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/requirements-linux.txt + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z + vulnerabilities: + - name: Pygments vulnerable to Regular Expression Denial of Service (ReDoS) + cve_id: CVE-2021-27291 + cve_url: https://github.com/advisories/GHSA-pq64-v7f5-gqh8 + detected_date: Aug 22 + severity: high + first_patched: 2.7.4 + - name: Infinite Loop in Pygments + cve_id: CVE-2021-20270 + cve_url: https://github.com/advisories/GHSA-9w8r-397f-prfh + detected_date: Aug 22 + severity: high + first_patched: 2.7.4 + - name: Pygments vulnerable to ReDoS + cve_id: CVE-2022-40896 + cve_url: https://github.com/advisories/GHSA-mrwq-x4v8-fh7p + detected_date: Jul 21 + severity: moderate + first_patched: 2.15.0 +- name: certifi + description: Python package for providing Mozilla's CA Bundle + package_url: https://pypi.org/project/certifi + version: 2020.6.20 + license: MPL-2.0 + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19849/default_75c38a39b9f0062814489e2ec2cbfca0ca15d9ba.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z + vulnerabilities: + - name: Removal of e-Tugra root certificate + cve_id: CVE-2023-37920 + cve_url: https://github.com/advisories/GHSA-xqr8-7jwr-rhp7 + detected_date: Jul 26 + severity: high + first_patched: 2023.7.22 + - name: Certifi removing TrustCor root certificate + cve_id: CVE-2022-23491 + cve_url: https://github.com/advisories/GHSA-43fp-rhv2-5gv8 + detected_date: Dec 8 + severity: moderate + first_patched: 2022.12.07 +- name: chardet + description: Universal encoding detector for Python 2 and 3 + package_url: https://pypi.org/project/chardet + version: 3.0.4 + license: LGPL-2.1 + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19856/default_4a8a8fdc10130068bf295812b98e9b72fb42fe70.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: docutils + description: Docutils -- Python Documentation Utilities + package_url: https://pypi.org/project/docutils + version: '0.16' + license: Unlicense,Python-2.0,BSD-2-Clause,CNRI-Python-GPL-Compatible + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19874/default_7ed3c4ccf2a3218ae3655165b980bd4a90a445dc.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: future + description: Clean single-source support for Python 3 and 2 + package_url: https://pypi.org/project/future + version: 0.18.2 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19839/default_85689b353a3a9409328e253ea28d859d29151e0c.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z + vulnerabilities: + - name: Python Charmers Future denial of service vulnerability + cve_id: CVE-2022-40899 + cve_url: https://github.com/advisories/GHSA-v3c5-jqr6-7qm8 + detected_date: Jan 5 + severity: high + first_patched: 0.18.3 +- name: idna + description: Internationalized Domain Names in Applications + package_url: https://pypi.org/project/idna + version: '2.9' + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19863/default_f24e00e4cb7620e436f9d06e0305070e1335922a.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: itsdangerous + description: Various helpers to pass data to untrusted environments and back + package_url: https://pypi.org/project/itsdangerous + version: 1.1.0 + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19989/default_b1f1fc9c4c59a78443018e01395203ba8c61dcde.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: packaging + description: Core utilities for Python packages + package_url: https://pypi.org/project/packaging + version: '21.0' + license: BSD-3-Clause,Apache-2.0 + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19894/default_f716e4bc541a9eb6e3f5b7a20d7c35355075b0b4.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: pefile + description: Python PE parsing module + package_url: https://pypi.org/project/pefile + version: 2021.9.3 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/20601/default_705055e61b43e314c99bd16582ed1fac9638127e.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: pyparsing + description: Python parsing module + package_url: https://pypi.org/project/pyparsing + version: 2.4.7 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19881/default_2270bfab784e3d2c2d999d26b11ee478a9dad238.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: requests + description: Python HTTP for Humans + package_url: https://pypi.org/project/requests + version: 2.24.0 + license: Apache-2.0 + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19826/default_d7c684bf2673f008a9f02ac93901229297a22d7e.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z + vulnerabilities: + - name: Unintended leak of Proxy-Authorization header in requests + cve_id: CVE-2023-32681 + cve_url: https://github.com/advisories/GHSA-j8r2-6x86-q33q + detected_date: May 23 + severity: moderate + first_patched: 2.31.0 +- name: urllib3 + description: HTTP library with thread-safe connection pooling + package_url: https://pypi.org/project/urllib3 + version: 1.25.9 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/19842/default_4604ff5dcb7f4d9c7b3833591c2142493951b19c.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z + vulnerabilities: + - name: Catastrophic backtracking in URL authority parser when passed URL containing + many @ characters + cve_id: CVE-2021-33503 + cve_url: https://github.com/advisories/GHSA-q2q7-5pp4-w6pg + detected_date: Aug 22 + severity: high + first_patched: 1.26.5 + - name: urllib3's request body not stripped after redirect from 303 status changes + request method to GET + cve_id: CVE-2023-45803 + cve_url: https://github.com/advisories/GHSA-g4mx-q9vg-27p4 + detected_date: Oct 18 + severity: moderate + first_patched: 1.26.18 + - name: "`Cookie` HTTP header isn't stripped on cross-origin redirects" + cve_id: CVE-2023-43804 + cve_url: https://github.com/advisories/GHSA-v845-jxx5-vc9f + detected_date: Oct 3 + severity: moderate + first_patched: 1.26.17 +- name: xlrd + description: Library for developers to extract data from Microsoft Excel + package_url: https://pypi.org/project/xlrd + version: 1.2.0 + license: BSD-3-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: PyPI Packages + image_url: https://img.stackshare.io/package/20182/default_3d320a0aa731f16ceb0e7b6999ca7f7cd784aee2.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/__tests__/data/inner/poetry.lock + detection_source: __tests__/data/requirements-linux.txt + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-11-17 10:31:22.000000000 Z +- name: "@types/jest" + description: TypeScript definitions for Jest + package_url: https://www.npmjs.com/@types/jest + version: 27.0.2 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15840/default_004658cda9b38934f2871435e9dc15608c86e8be.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Ivan + last_updated_on: 2023-03-09 10:44:56.000000000 Z +- name: "@types/node" + description: TypeScript definitions for Node.js + package_url: https://www.npmjs.com/@types/node + version: 16.11.25 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15809/default_5e5e8ac63beda29f31f1844df64d4b8247570a66.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Nikolai Laevskii + last_updated_on: 2023-05-22 08:41:59.000000000 Z +- name: "@types/semver" + description: TypeScript definitions for semver + package_url: https://www.npmjs.com/@types/semver + version: 7.3.13 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/16694/default_4b738bf1758d38dddd276589bbea47fca5a990df.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: dependabot[bot] + last_updated_on: 2023-07-13 13:25:58.000000000 Z +- name: "@typescript-eslint/eslint-plugin" + description: TypeScript plugin for ESLint + package_url: https://www.npmjs.com/@typescript-eslint/eslint-plugin + version: 5.54.0 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15982/default_8b5680d4e916298d08363c291a0d6e34c07ceb15.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Nikolai Laevskii + last_updated_on: 2023-05-22 08:41:59.000000000 Z +- name: "@typescript-eslint/parser" + description: An ESLint custom parser which leverages TypeScript ESTree + package_url: https://www.npmjs.com/@typescript-eslint/parser + version: 5.54.0 + license: BSD-2-Clause + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15980/default_732016a20524708efe7a4c77497fe9bfeea19ba6.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Nikolai Laevskii + last_updated_on: 2023-05-22 08:41:59.000000000 Z +- name: eslint-config-prettier + description: Turns off all rules that are unnecessary or might conflict with Prettier + package_url: https://www.npmjs.com/eslint-config-prettier + version: 8.6.0 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15879/default_0b10af8ca19c215f781dc07442e75bdc831089d0.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Nikolai Laevskii + last_updated_on: 2023-05-22 08:41:59.000000000 Z +- name: eslint-plugin-jest + description: Eslint rules for Jest + package_url: https://www.npmjs.com/eslint-plugin-jest + version: 27.2.1 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15996/default_7a88bebb451873cc63bd99007de5bd3bb8ef85de.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Nikolai Laevskii + last_updated_on: 2023-05-22 08:41:59.000000000 Z +- name: eslint-plugin-node + description: Additional ESLint's rules for Node.js + package_url: https://www.npmjs.com/eslint-plugin-node + version: 11.1.0 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15874/default_6743ba96cf149a3c3c68a185199f9705d6eff80e.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Nikolai Laevskii + last_updated_on: 2023-05-22 08:41:59.000000000 Z +- name: husky + description: Prevents bad commit or push + package_url: https://www.npmjs.com/husky + version: 7.0.2 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15831/default_14fd11531839d935f920b6d55bd6f3528c890ad7.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Dmitry Shibanov + last_updated_on: 2021-10-13 12:18:42.000000000 Z +- name: ts-jest + description: A preprocessor with source maps support to help use TypeScript with + Jest + package_url: https://www.npmjs.com/ts-jest + version: 27.0.5 + license: MIT + open_source: true + hosted_saas: false + category: Libraries + sub_category: npm Packages + image_url: https://img.stackshare.io/package/15864/default_6743ba96cf149a3c3c68a185199f9705d6eff80e.png + detection_source_url: https://github.com/yourkin/setup-python/blob/main/package-lock.json + detection_source: package.json + last_updated_by: Ivan + last_updated_on: 2023-03-09 10:44:56.000000000 Z