Skip to content

[Harness SCS] Security upgrade docx2pdf to version 0.1.8#1

Open
Sayanta66 wants to merge 1 commit intomainfrom
harness-scs/fix-812148f4
Open

[Harness SCS] Security upgrade docx2pdf to version 0.1.8#1
Sayanta66 wants to merge 1 commit intomainfrom
harness-scs/fix-812148f4

Conversation

@Sayanta66
Copy link
Copy Markdown
Owner

Harness has created this PR to fix risky or vulnerable packages.

📁 Changes included in this PR

Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

  • requirements.txt

📝 Description

Upgrade Version: 0.1.8

Summary:
The current version of docx2pdf is 0.1.7, which is unmaintained and outdated, with known vulnerabilities. Upgrading to version 0.1.8 is crucial as it addresses these vulnerabilities, enhancing security and stability. This upgrade will mitigate existing security risks, although the specific number of vulnerabilities and their severity levels have not been disclosed. Before proceeding with the upgrade, it is advisable to review potential breaking changes to ensure compatibility. Additionally, version 0.1.8 may include updates to dependencies and improvements in functionality that enhance overall performance.


🛡️ Security Impact

Current version vulnerabilities: 0 (Critical: 0, High: 0, Medium: 0, Low: 0)

Upgrade version vulnerabilities: 0 (Critical: 0, High: 0, Medium: 0, Low: 0)

Status: 🎉 0 vulnerabilities have been reduced/resolved.


📦 Dependencies affected

✅ Upgrading this dependency does not introduce any changes to its transitive dependencies.


👤 Created By

Sayanta Banerjee (sayanta.banerjee@harness.io)


Note

This PR is generated by Harness Supply Chain Security and contains changes based on AI recommendations. It is recommended to review the changes before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant