Skip to content

Audit Snyk check/fix 2.8#12826

Merged
geo-ghci-int[bot] merged 1 commit into2.8from
ghci/audit/snyk/2.8
Apr 15, 2026
Merged

Audit Snyk check/fix 2.8#12826
geo-ghci-int[bot] merged 1 commit into2.8from
ghci/audit/snyk/2.8

Conversation

@geo-ghci-int
Copy link
Copy Markdown
Contributor

@geo-ghci-int geo-ghci-int bot commented Apr 14, 2026

⠋ Running snyk test for /tmp/tmp1t4f85jk/c2cgeoportal
► Running snyk test for /tmp/tmp1t4f85jk/c2cgeoportal

  • Looking for supported Python items
    ✔ Looking for supported Python items
  • Looking for supported Python items
    ✔ Looking for supported Python items
    ⠋ Processing 4 pyproject.toml items⠋ Processing 8 requirements.txt items✔ Processed 8 requirements.txt items
  • Checking poetry version
    ⚠️ Could not detect poetry version, proceeding anyway. Some operations may fail.
  • Fixing pyproject.toml 1/2
  • Fixing pyproject.toml 2/2
    ✔ Processed 4 pyproject.toml items
    ✔ Done
    Successful fixes:
    doc/pyproject.toml
    ✔ Upgraded pillow from 12.1.1 to 12.2.0
    Unresolved items:
    docker/config/pyproject.toml
    ✖ There is no actionable remediation to apply
    docker/qgisserver/pyproject.toml
    ✖ There is no actionable remediation to apply
    pyproject.toml
    x Failed to upgrade pillow from 10.3.0 to 12.2.0
    Reason: No fixes could be applied.
    Tip: Try running poetry add pillow==12.2.0 pyjwt==2.12.0 requests==2.33.0 ujson==5.12.0
    x Failed to pin pyjwt from 2.6.0 to 2.12.0
    Reason: No fixes could be applied.
    Tip: Try running poetry add pillow==12.2.0 pyjwt==2.12.0 requests==2.33.0 ujson==5.12.0
    x Failed to upgrade requests from 2.32.5 to 2.33.0
    Reason: No fixes could be applied.
    Tip: Try running poetry add pillow==12.2.0 pyjwt==2.12.0 requests==2.33.0 ujson==5.12.0
    x Failed to pin ujson from 5.7.0 to 5.12.0
    Reason: No fixes could be applied.
    Tip: Try running poetry add pillow==12.2.0 pyjwt==2.12.0 requests==2.33.0 ujson==5.12.0
    admin/package-lock.json
    ✖ npm is not supported.
    geoportal/package-lock.json
    ✖ npm is not supported.
    Summary:
    5 items were not fixed
    1 items were successfully fixed
    2 items were not vulnerable
    42 issues: 1 Critical | 22 High | 18 Medium | 1 Low
    22 issues are fixable
    1 issues were successfully fixed
    Tip: Re-run in debug mode to see more information: DEBUG=*snyk* . If the issue persists contact support@snyk.io

Output
Logs

@geo-ghci-int geo-ghci-int bot enabled auto-merge April 14, 2026 18:30
@sbrunner sbrunner force-pushed the ghci/audit/snyk/2.8 branch from 3bd8fbf to 41440fe Compare April 15, 2026 07:04
@geo-ghci-int geo-ghci-int bot merged commit 5f96500 into 2.8 Apr 15, 2026
23 checks passed
@geo-ghci-int geo-ghci-int bot deleted the ghci/audit/snyk/2.8 branch April 15, 2026 07:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant