Skip to content

[Snyk] Fix for 14 vulnerabilities - #705

Open
bashtage wants to merge 1 commit into
mainfrom
snyk-fix-d0ab7306334c9922136af74bb90c7079
Open

[Snyk] Fix for 14 vulnerabilities#705
bashtage wants to merge 1 commit into
mainfrom
snyk-fix-d0ab7306334c9922136af74bb90c7079

Conversation

@bashtage

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 14 vulnerabilities in the pip dependencies of this project.

Snyk changed the following file(s):

  • doc/requirements.txt
⚠️Warning
sphinx 5.3.0 has requirement docutils<0.20,>=0.14, but you have docutils 0.20.1.
notebook 6.5.7 requires pyzmq, which is not installed.
matplotlib 3.5.3 requires fonttools, which is not installed.
matplotlib 3.5.3 requires pillow, which is not installed.
jupyter 1.1.1 requires jupyterlab, which is not installed.
jupyter-server 1.24.0 requires pyzmq, which is not installed.
jupyter-console 6.6.3 requires pyzmq, which is not installed.
jupyter-client 7.4.9 requires pyzmq, which is not installed.
ipykernel 6.16.2 requires pyzmq, which is not installed.

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Some vulnerabilities couldn't be fully fixed and so Snyk will still find them when the project is tested again. This may be because the vulnerability existed within more than one direct dependency, but not all of the affected dependencies could be upgraded.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Directory Traversal
🦉 Regular Expression Denial of Service (ReDoS)
🦉 Out-of-bounds Write
🦉 More lessons are available in Snyk Learn

@bashtage

Copy link
Copy Markdown
OwnerAuthor

Merge Risk: High

This upgrade includes major version changes for Pillow and jupyter-server which introduce significant breaking changes, including dropped support for older Python versions and API removals that require code modifications. Other packages like nbconvert and soupsieve also have medium-risk environment changes.

Top 3 Most

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@codecov

codecovBot commented Jul 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.54%. Comparing base (7e1de2e) to head (d21ba39).
⚠️ Report is 6 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #705 +/- ##
=======================================
Coverage 99.54% 99.54% =======================================
Files 101 101 Lines 17426 17426 Branches 1430 1430 =======================================
Hits 17347 17347 Misses 29 29 Partials 50 50 
FlagCoverage Δ
adder99.52% <ø> (ø)
subtractor99.52% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@bashtage@snyk-bot